mediumMultiple Select
350-401 Practice Question: Which three statements about Cisco QoS policing…
Which three statements about Cisco QoS policing and shaping are true? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policing can re-mark traffic that exceeds the configured rate to a lower priority.
Policing drops or re-marks traffic exceeding a rate, while shaping buffers excess traffic. Policing is typically applied inbound, shaping outbound. Option A is correct because policing can mark down traffic (e.g., set DSCP to 0) when the rate is exceeded. Option B is correct because shaping buffers traffic to smooth bursts, reducing drops. Option C is correct because both use a token bucket model to measure conformance. Option D is incorrect because policing does not buffer; it drops or re-marks. Option E is incorrect because shaping is applied on egress, not ingress.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Policing can re-mark traffic that exceeds the configured rate to a lower priority.
Why this is correct
Policing meters traffic against the token bucket and, instead of dropping, can mark conforming or exceeding packets with a new DSCP or IP precedence value, lowering their priority downstream. This satisfies the requirement to re-mark excess traffic.
- ✓
Shaping buffers excess traffic and transmits it later to avoid drops.
Why this is correct
Shaping applies a token bucket plus a queue: packets exceeding the committed rate are delayed in the buffer and released when tokens refill, smoothing bursts rather than discarding them. This satisfies the requirement to avoid drops on excess traffic.
- ✓
Both policing and shaping use a token bucket algorithm to measure traffic rates.
Why this is correct
Both mechanisms rely on the token bucket algorithm: tokens accumulate at the committed rate, and each packet consumes tokens. Policing drops or re-marks when tokens are exhausted, while shaping queues, so both measure rate against the same bucket model.
- ✗
Policing buffers traffic that exceeds the rate to reduce packet loss.
Why it's wrong here
Policing drops or remarks excess traffic rather than buffering it; buffering is shaping's mechanism, which queues over-rate packets to smooth bursts. Policing is tempting because it does limit rates, and would be correct where immediate discard of out-of-profile traffic is acceptable and no queuing delay is wanted.
- ✗
Shaping is typically applied on the ingress interface to control incoming traffic.
Why it's wrong here
Shaping buffers and delays egress traffic to smooth rates, so it is applied on the egress interface, not ingress. It is tempting because policing does act on ingress, and in a scenario limiting inbound traffic, ingress policing would be the correct mechanism.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 350-401
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which two statements about policing and shaping in a QoS architecture are true? (Choose two.)
medium- ✓ A.Policing can be configured on both ingress and egress interfaces, while shaping is only supported on egress interfaces.
- B.Shaping uses a token bucket algorithm to meter traffic and drops packets that exceed the configured rate.
- C.Policing introduces variable delay because it buffers excess traffic before forwarding.
- D.Both policing and shaping can re-mark packets that conform to the configured rate.
- ✓ E.The 'shape average' command configures shaping to use the average rate over time, while 'shape peak' allows bursts above the average.
Why A: Policing drops or re-marks traffic exceeding a rate, while shaping buffers excess traffic to smooth bursts. Policing is applied inbound or outbound, shaping is typically outbound. Policing does not introduce delay, shaping does. Both can use token bucket algorithms.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.