Courseiva

CCNA Qos Questions

68 questions · Qos topic · All types, answers revealed

1
MCQhard

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against excessive ARP traffic. The engineer applies the following policy: policy-map COPP-POLICY class ARP-CLASS police 8000 conform-action transmit exceed-action drop After applying the service-policy to the control-plane, the engineer notices that legitimate ARP requests are being dropped during peak hours. Which action should the engineer take to resolve this issue while maintaining protection?

A.Add a class-map that matches ARP replies and apply a separate police rate to that class.
B.Increase the police rate to a higher value that accommodates peak ARP traffic while still limiting excessive bursts.
C.Remove the service-policy from the control-plane and apply it to the data plane instead.
D.Change the exceed-action to transmit so that all ARP packets are allowed through.
AnswerB

The police rate of 8000 bps is too low for peak ARP traffic, causing legitimate ARP requests to be dropped. Increasing the rate to a value that matches normal peak traffic while still providing an upper bound protects the control plane without dropping legitimate traffic. This is the correct tuning approach for CoPP.

Why this answer

CoPP police rates must be tuned to allow legitimate control-plane traffic while blocking excess. A rate of 8000 bps is insufficient for ARP during peak hours, so increasing the rate to a realistic peak value resolves drops while preserving protection. Changing exceed-action to transmit removes protection, moving the policy to the data plane is ineffective, and splitting classes without raising the rate does not fix the underlying issue.

Exam trap

The trap here is thinking that any drop means the policy is too strict and should be disabled, rather than tuning the rate to match legitimate traffic patterns.

2
MCQmedium

A network engineer is configuring QoS on a Cisco IOS switch. The engineer needs to mark packets coming from a specific server with DSCP EF (46) and ensure that this marking is trusted throughout the network. Which command should be used to trust the DSCP markings on the interface connected to the server?

A.mls qos trust dscp
B.mls qos trust cos
C.mls qos trust ip-precedence
D.mls qos map cos-dscp 0 8 16 24 32 40 48 56
AnswerA

The 'mls qos trust dscp' command configures the interface to trust the DSCP value in incoming packets. This means the switch will use the existing DSCP marking for classification and queuing, rather than overwriting it. This is appropriate when the server is already marking its traffic with DSCP EF, as it preserves the marking and ensures proper treatment across the network.

Why this answer

To trust DSCP markings on an interface, the correct command is 'mls qos trust dscp'. This tells the switch to accept the DSCP value in incoming packets and use it for QoS processing. Since the server is already marking its traffic with DSCP EF, this command ensures that the marking is preserved and honored throughout the network, preventing the switch from re-marking the packets.

Exam trap

The trap here is confusing trust boundaries and assuming that trusting CoS is equivalent to trusting DSCP, even when the server sends untagged frames.

3
MCQhard

A network engineer is configuring CoPP on a Cisco Nexus 9000 switch to protect the control plane from a potential DoS attack. The engineer creates a class-map that matches traffic with a specific DSCP value (AF41) and applies a police rate of 10 Mbps. After applying the policy, the engineer notices that legitimate traffic with DSCP AF41 is being dropped even though the traffic rate is only 5 Mbps. What is the most likely cause?

A.The CoPP policy has a conform-action of drop, which drops all traffic matching the class.
B.The police rate is too low, and the traffic is being dropped due to exceeding the rate.
C.The DSCP value AF41 is not supported on Nexus switches.
D.The CoPP policy is applied to the wrong queue, causing all traffic to be dropped.
AnswerA

In Control-Plane Policing (CoPP) on Nexus switches, the police command defines separate actions for packets that conform to, exceed, or violate the configured rate. If the conform-action is set to 'drop', the policer drops every packet matching that class map, regardless of its instantaneous rate or whether it falls within the committed burst. Since the observed 5 Mbps is below the 10 Mbps police rate, the traffic is conforming; yet it is still dropped, which precisely matches a conform-action of drop rather than the common 'transmit' conform-action. This effectively turns the class into an unconditional drop filter for control-plane traffic.

Why this answer

The CoPP policy's conform-action of drop explicitly instructs the switch to discard all packets that match the class-map, regardless of the traffic rate. Even though the traffic rate is only 5 Mbps (below the 10 Mbps police rate), the drop action overrides the policing logic, causing legitimate AF41 traffic to be dropped. This is a common misconfiguration where the engineer sets the action to 'drop' instead of 'transmit' for conforming traffic.

Exam trap

Cisco often tests the distinction between the police rate and the police action, trapping candidates who assume that a rate below the configured limit automatically allows traffic, without checking the conform-action parameter.

How to eliminate wrong answers

Option B is wrong because the traffic rate of 5 Mbps is below the configured police rate of 10 Mbps, so traffic should not be dropped due to exceeding the rate; the issue is the action, not the rate. Option C is wrong because DSCP AF41 (decimal value 34) is fully supported on Nexus 9000 switches as part of the standard DiffServ code point set defined in RFC 2474. Option D is wrong because CoPP policies are applied to the control-plane interface globally, not to a specific queue; queue-based dropping would involve QoS policies, not CoPP.

4
MCQmedium

An enterprise network uses a Cisco Catalyst 9300 switch as a distribution layer device. The network team notices that ICMP echo requests from a monitoring server (192.168.1.100) to the switch's management IP are being dropped intermittently. The switch has a CoPP policy that includes a class-map matching ICMP traffic. The engineer checks the CoPP statistics and sees that ICMP packets from the monitoring server are being dropped by the policy. What is the most likely cause of this issue?

A.The CoPP policy is policing ICMP traffic to a rate that is too low for the monitoring server's traffic.
B.An ACL applied to the management interface is blocking ICMP from the monitoring server.
C.The monitoring server is sending ICMP packets with a TTL of 1, causing them to be dropped.
D.The switch's CPU is overloaded, causing CoPP to drop all packets.
AnswerA

CoPP (Control Plane Policing) uses an MQC policy with policers to rate-limit traffic destined to the switch CPU. A monitoring server’s ICMP packets (e.g., ping to the management IP) are classified into a class that matches ICMP; if the configured police rate (e.g., committed information rate) is too low, packets exceeding the burst are immediately dropped. The drop counters in 'show policy-map control-plane' confirm that the traffic was admitted to the control plane but then policed, not blocked earlier.

Why this answer

The CoPP policy is policing ICMP traffic to a rate that is too low for the monitoring server's traffic. CoPP (Control Plane Policing) protects the switch's CPU by rate-limiting control plane traffic, including ICMP. When the policer rate is set too low, even legitimate ICMP echo requests from the monitoring server are dropped, causing intermittent reachability issues.

Exam trap

The trap here is that candidates may assume CoPP drops are always due to CPU overload or a misconfigured ACL, but the key clue is the intermittent nature and the specific class-map match, pointing directly to an overly restrictive policer rate.

How to eliminate wrong answers

Option B is wrong because an ACL applied to the management interface would block ICMP consistently, not intermittently, and the CoPP statistics explicitly show drops from the policy, not ACL hits. Option C is wrong because ICMP packets with a TTL of 1 would be dropped by routers along the path, not by the destination switch's CoPP policy; the monitoring server typically sends TTL values of 64 or 128. Option D is wrong because an overloaded CPU would cause CoPP to drop all packets indiscriminately, but the scenario states only ICMP packets from the monitoring server are being dropped, indicating a specific rate-limit issue rather than general CPU exhaustion.

5
MCQhard

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and SNMP. The engineer wants to ensure that BGP keepalives are not dropped during a control plane overload, while still rate-limiting SSH and SNMP. The engineer creates a class-map matching BGP, SSH, and SNMP traffic, then applies a policy-map with a single policer of 1000 pps to that class. After applying the service-policy to the control plane, BGP sessions flap during high CPU utilization. What is the most likely cause?

A.CoPP cannot be applied to BGP traffic; it only supports management protocols like SSH and SNMP.
B.The service-policy must be applied to the data plane instead of the control plane for BGP to be protected.
C.The policer rate is too low for BGP keepalives, and all matched traffic is treated equally.
D.The policer should be configured with 'police cir' instead of 'police pps' to properly rate-limit BGP.
AnswerC

A single policer applied to a class that matches BGP, SSH, and SNMP treats all three protocols identically. During high CPU, BGP keepalives may exceed the 1000 pps rate along with other traffic, causing drops. BGP requires a separate class with a higher rate or priority to ensure keepalives are not dropped. The design flaw is the lack of granularity.

Why this answer

CoPP requires granular classification to protect critical protocols. When BGP, SSH, and SNMP are matched in the same class and policed together, BGP keepalives compete with other traffic and may be dropped during high CPU. BGP should be placed in its own class with a higher rate or priority to prevent flapping.

The single policer approach lacks the necessary differentiation.

Exam trap

The trap here is assuming that a single policer can adequately protect all control plane protocols, when in fact BGP requires separate treatment to avoid keepalive drops during congestion.

6
MCQhard

A network engineer runs the following command on Router R9: R9# show policy-map interface GigabitEthernet0/0.900 GigabitEthernet0/0.900 Service-policy input: QOS_POLICY_VRF_G Class-map: CLASS_VOICE (match-all) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp ef (46) police: cir 1000000 bps, bc 31250 bytes, be 31250 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: CLASS_DATA (match-all) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp af31 (26) police: cir 2000000 bps, bc 62500 bytes, be 62500 bytes conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: class-default (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any Based on this output, what can be concluded?

A.No QoS policy is applied to this interface
B.The policy only polices voice traffic
C.A QoS policy is applied inbound on GigabitEthernet0/0.900, policing voice and data traffic
D.The policy is applied outbound
AnswerC

The configuration shows 'service-policy input' on GigabitEthernet0/0.900, which places the QoS policy in the inbound direction for that subinterface. The policy-map contains class-maps for voice (DSCP EF) and data (DSCP AF31), each with a 'police' command that applies token-bucket rate limiting. Therefore, the correct interpretation is that inbound traffic on this subinterface is classified and policed for both voice and data types.

Why this answer

The output shows the 'Service-policy input: QOS_POLICY_VRF_G' line, confirming that a QoS policy is applied inbound on GigabitEthernet0/0.900. The policy contains two user-defined class maps: CLASS_VOICE (matching DSCP EF) with a police rate of 1 Mbps and CLASS_DATA (matching DSCP AF31) with a police rate of 2 Mbps, both with conform/transmit and exceed/violate drop actions. This demonstrates that both voice and data traffic are being policed, making option C correct.

Exam trap

Cisco often tests the ability to read the 'Service-policy input' or 'output' direction in the command output, as candidates may overlook the direction keyword and incorrectly assume the policy is applied outbound or not applied at all.

How to eliminate wrong answers

Option A is wrong because the 'Service-policy input: QOS_POLICY_VRF_G' line explicitly shows a QoS policy is applied inbound on the subinterface. Option B is wrong because the policy includes both CLASS_VOICE and CLASS_DATA class maps, each with policing actions, so it polices both voice and data traffic, not just voice. Option D is wrong because the command output specifies 'Service-policy input', indicating the policy is applied inbound, not outbound.

7
Matchingmedium

Drag and drop each DSCP value on the left to its matching Per-Hop Behavior (PHB) on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

EF

AF11

AF21

AF31

AF41

Why these pairings

DSCP 46 maps to EF (Expedited Forwarding), DSCP 10 maps to AF11 (Assured Forwarding class 1 low drop), DSCP 18 maps to AF21 (Assured Forwarding class 2 low drop), DSCP 26 maps to AF31 (Assured Forwarding class 3 low drop), DSCP 34 maps to AF41 (Assured Forwarding class 4 low drop).

8
MCQmedium

Consider the following configuration: class-map match-all HTTP match protocol http policy-map QOS class HTTP police 2000000 1500 3000 conform-action transmit exceed-action drop interface GigabitEthernet0/1 service-policy input QOS What is the effect of this configuration?

A.HTTP traffic is policed to an average rate of 2 Mbps; packets that exceed the rate are dropped, while conforming packets are transmitted.
B.HTTP traffic is shaped to an average rate of 2 Mbps; excess packets are buffered.
C.The police command will mark HTTP packets with a DSCP value of 0 if they exceed the rate.
D.The configuration is invalid because 'police' cannot be used in a 'service-policy input' direction.
AnswerA

Policing enforces a 2 Mbps average rate using a token bucket; every arriving HTTP packet is evaluated against that bucket. Packets that find enough tokens are transmitted unchanged because of the conform-action transmit clause, while packets that exceed the bucket depth trigger the exceed-action drop and are discarded immediately. Policing does not buffer, so excess traffic is dropped rather than delayed.

Why this answer

The 'police' command in the policy-map enforces a traffic policer on HTTP traffic matched by the class-map. The parameters '2000000' (2 Mbps) define the committed information rate (CIR), '1500' is the normal burst (Bc), and '3000' is the excess burst (Be). Conforming packets are transmitted, while packets exceeding the rate are dropped, which is the standard behavior of a policer in the input direction.

Exam trap

Cisco often tests the distinction between policing and shaping, and the trap here is that candidates confuse 'police' with 'shape' or assume that 'police' cannot be applied in the input direction, when in fact policing is commonly used on input interfaces.

How to eliminate wrong answers

Option B is wrong because 'police' implements policing, not shaping; policing drops excess traffic, while shaping buffers it. Option C is wrong because the 'police' command does not mark packets with DSCP 0 by default; marking requires an additional 'set' action or a 'conform-action' or 'exceed-action' that explicitly sets a DSCP value. Option D is wrong because 'police' is fully valid in the 'service-policy input' direction; policing is commonly applied on input to rate-limit incoming traffic.

9
MCQmedium

A mid-size enterprise is deploying a new branch office with 50 users. The branch will have its own router, switch, and wireless AP. The WAN link is a 50 Mbps MPLS circuit. The company uses VoIP and requires Quality of Service. The network administrator has configured the router with a QoS policy that marks VoIP traffic with DSCP EF and all other traffic with DSCP 0. The policy also shapes traffic to 50 Mbps. After deployment, users report that voice quality is poor during peak hours. The administrator checks the router and sees that the output queue on the WAN interface is often full and drops are occurring. Which action should the administrator take to improve voice quality?

A.Increase the shaping rate to 60 Mbps to allow for burst.
B.Configure a priority queue for DSCP EF traffic within the shaper.
C.Replace shaping with policing to drop non-voice traffic.
D.Change the marking to use CoS instead of DSCP for better QoS.
AnswerB

A priority queue, implemented via LLQ (Low Latency Queuing) within the CBWFQ shaper, ensures that DSCP EF voice packets are dequeued ahead of all other classes before the shaped output is released. This guarantees that voice traffic experiences low latency and jitter, and critically, that voice packets are not tail-dropped when the shaper's buffer is temporarily congested due to bursts. The priority queue's strict scheduling protects real-time traffic from the queue-full condition that causes drops in other classes.

Why this answer

The shaper is limiting traffic to 50 Mbps, but during peak hours, the aggregate traffic exceeds this rate, causing the output queue to fill and drop packets indiscriminately. By configuring a priority queue for DSCP EF (VoIP) traffic within the shaper, the router will service VoIP packets before other traffic, ensuring low latency and jitter even when the link is congested. This is the standard Cisco approach for voice quality on shaped links, as priority queuing bypasses the normal FIFO or CBWFQ behavior for marked traffic.

Exam trap

Cisco often tests the misconception that increasing bandwidth or policing alone solves voice quality issues, but the trap here is that shaping without a priority queue causes all traffic to be treated equally, so VoIP suffers from jitter and delay even if the total rate is within the shaped limit.

How to eliminate wrong answers

Option A is wrong because increasing the shaping rate to 60 Mbps does not solve the underlying congestion; it only shifts the bottleneck and may cause the provider to drop traffic if the CIR is strictly 50 Mbps, leading to continued packet loss for VoIP. Option C is wrong because policing would drop excess traffic indiscriminately, including VoIP packets, unless a separate policer is applied per class, and it does not provide the strict priority queuing needed for voice. Option D is wrong because changing the marking to CoS (Layer 2) does not improve QoS on a WAN interface that typically uses DSCP (Layer 3) for queuing decisions; the router's output queue is based on Layer 3 markings, and CoS is lost when traversing the MPLS network unless explicitly mapped.

10
MCQmedium

A network engineer is configuring QoS on a Cisco router to prioritize business-critical applications. The engineer creates a class-map that matches traffic based on the destination IP address and port. However, the class-map does not match the expected traffic. What is the most likely reason?

A.The class-map uses 'match-all' but the engineer intended to use 'match-any'.
B.The access-list used for matching is not applied to the correct interface.
C.The router does not support matching on both IP and port in the same class-map.
D.The class-map must be applied to the interface before it can match traffic.
AnswerA

Because the class-map is configured with 'match-all', every match statement must evaluate true for a packet to be classified into that class. QoS class-maps default to 'match-all' unless 'match-any' is explicitly specified; if the engineer configured multiple match conditions such as 'match access-group' and 'match protocol' and only one of those conditions is satisfied, the packet will not be placed in this user-defined class. As a result, the intended QoS policy (such as marking, policing, or queuing) will not apply to that traffic, and the packet falls through to the default class. Changing the class-map to 'match-any' allows the traffic to match when any one of the conditions is true.

Why this answer

When a class-map uses 'match-all', all match conditions must be true for a packet to be classified. If the engineer intended to match traffic based on either the destination IP address OR the port, using 'match-any' would allow the class-map to match if any single condition is met. The mismatch occurs because the class-map is too restrictive, requiring both conditions to be satisfied simultaneously.

Exam trap

Cisco often tests the subtle difference between 'match-all' (default) and 'match-any' in class-maps, trapping candidates who assume that multiple match conditions automatically use OR logic.

How to eliminate wrong answers

Option B is wrong because the access-list used for matching is referenced inside the class-map, not applied directly to the interface; the class-map itself is applied to the interface via a policy-map, so the access-list does not need separate interface application. Option C is wrong because Cisco routers fully support matching on both IP and port in the same class-map using nested match statements or an extended access-list; there is no inherent limitation. Option D is wrong because a class-map does not need to be applied to an interface to match traffic; it is the policy-map that references the class-map and is applied to the interface, and the class-map itself can be tested independently.

11
Drag & Dropmedium

Drag and drop the steps of DSCP re-marking at enterprise WAN edge into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

At the enterprise WAN edge, traffic is first classified based on existing markings or other criteria. Then a policy-map is created to set the new DSCP value. The policy is applied outbound on the WAN interface.

The router re-marks packets as they exit. Finally, the new DSCP value is verified using show commands.

12
MCQmedium

An enterprise is designing a QoS architecture for its WAN edge routers connecting to multiple service providers. The design must support traffic shaping to avoid packet drops due to provider policers, while also prioritizing real-time traffic. Which approach should the architect use to shape traffic to the contracted CIR while still allowing bursts?

A.Apply a shape average policy on the egress interface of the WAN edge router, setting the CIR and burst parameters to match the provider contract.
B.Use a policer on the ingress interface to drop traffic exceeding the CIR.
C.Configure a shaper on the provider's device instead of the customer router.
D.Set the interface bandwidth to the CIR and rely on FIFO queuing.
AnswerA

Shape average on the egress interface uses a token bucket to constrain the long-term average traffic rate to the CIR while permitting short bursts up to the configured Bc (and optionally Be). Unlike a policer, the shaper queues excess packets so they are transmitted later, which smooths traffic sent toward the provider and prevents the provider's ingress policer from seeing micro-bursts that trigger tail drops. Matching the CIR and burst parameters to the provider contract ensures the shaped output stays within the contracted traffic profile, making this the only option that actively enforces the committed rate while preserving burst absorption.

Why this answer

'shape average' on the egress interface allows the router to buffer excess traffic and transmit it at the contracted CIR, while the burst parameters (Bc and Be) enable short-term bursts above CIR to accommodate real-time traffic spikes without drops. This prevents the provider's policer from discarding packets, as the shaper ensures the outbound traffic rate stays within the agreed contract limits.

Exam trap

Cisco often tests the distinction between shaping and policing—the trap here is that candidates may choose policing (Option B) because it seems simpler, but they overlook that shaping buffers bursts to avoid drops, which is essential when the provider enforces a policer downstream.

How to eliminate wrong answers

Option B is wrong because policing on the ingress interface drops or marks traffic exceeding the CIR, which does not prevent packet loss from the provider's egress policer and fails to buffer bursts; it also does not shape traffic to match the contract. Option C is wrong because the provider's device is typically not under the customer's administrative control, and shaping on the provider side would not allow the customer to prioritize their own real-time traffic or manage bursts locally. Option D is wrong because setting interface bandwidth to CIR does not perform shaping—it only influences routing metrics and QoS calculations, and FIFO queuing provides no prioritization for real-time traffic, leading to jitter and potential drops.

13
MCQmedium

Examine the following configuration: policy-map MARKING class VOICE set dscp ef class VIDEO set dscp af41 class class-default set dscp default interface GigabitEthernet0/0 service-policy input MARKING Which statement is true?

A.Incoming packets matching the VOICE class will have their DSCP set to EF (46), VIDEO to AF41 (34), and all others to default (0).
B.The policy-map will only mark packets if the interface is congested.
C.The configuration is invalid because 'set dscp' cannot be used in a 'service-policy input' direction.
D.The policy-map will remark the DSCP of outgoing packets on GigabitEthernet0/0.
AnswerA

In a Modular QoS CLI policy-map, the 'set dscp' action unconditionally rewrites the DSCP field of every packet that matches the class. Because the policy-map is attached with 'service-policy input', this marking occurs as packets enter the interface: voice traffic is set to EF (46), video to AF41 (34), and class-default traffic to 0. This makes the statement correct.

Why this answer

The configuration applies the MARKING policy-map as a service-policy input on GigabitEthernet0/0. This means all incoming packets are classified and have their DSCP values set according to the policy: VOICE class packets get DSCP EF (46), VIDEO class packets get DSCP AF41 (34), and all other packets (class-default) get DSCP default (0). The 'set dscp' action is valid in the input direction and does not require congestion to take effect.

Exam trap

The trap here is that candidates often confuse marking with congestion management, assuming that QoS actions like 'set dscp' only take effect during congestion, when in fact marking is a non-congestion-dependent action that applies to every matching packet.

How to eliminate wrong answers

Option B is wrong because the 'set dscp' action in a policy-map is a marking action that occurs on every matching packet regardless of congestion; it is not a queuing or dropping action that depends on congestion. Option C is wrong because 'set dscp' is perfectly valid in the input direction; marking can be applied to incoming packets before they are processed by the router. Option D is wrong because the service-policy is applied in the input direction, meaning it processes incoming packets, not outgoing packets; for outgoing marking, the policy would need to be applied as 'service-policy output'.

14
MCQhard

A network engineer is configuring QoS on a Cisco switch to ensure that video traffic (DSCP AF41) is not dropped during congestion. The engineer creates a policy-map that sets the queue-limit for the AF41 class. However, the switch is still dropping video packets. What is the most likely cause?

A.The queue-limit is set too low, causing tail drops.
B.The switch uses a single queue for all traffic unless multiple queues are configured.
C.The video traffic is not being marked with DSCP AF41.
D.The policy-map must be applied to the output direction.
AnswerB

Modern switching platforms often use a single FIFO or default priority queue for all traffic until multiple egress queues are explicitly configured through QoS profile or class-map-to-queue mappings. If the engineer only attached a policy-map that sets DSCP/CoS but did not map the class to one of the available hardware queues, the video traffic remains in the default queue and receives no dedicated bandwidth or drop protection. Therefore, the root cause is the absence of a multi-queue schedule, not the marking or policy-map direction.

Why this answer

By default, Cisco switches use a single queue for all traffic. Creating a policy-map that sets a queue-limit for the AF41 class does not automatically create a separate queue for that class; the switch must have multiple egress queues configured (e.g., via the 'priority-queue out' command or by mapping DSCP values to specific queues). Without multiple queues, all traffic shares the same queue, and setting a queue-limit on a class within a single-queue system does not prevent drops during congestion.

Exam trap

Cisco often tests the misconception that creating a class-map and policy-map with a queue-limit automatically creates a separate queue for that traffic, when in fact the switch must have multiple queues explicitly configured to isolate traffic classes.

How to eliminate wrong answers

Option A is wrong because setting the queue-limit too low could cause tail drops, but the question states the engineer created a queue-limit for the AF41 class, and the core issue is that the switch is not using separate queues for different traffic classes. Option C is wrong because the problem is not about marking; the engineer is configuring QoS for video traffic marked as DSCP AF41, and the drops occur even if the marking is correct, due to the lack of multiple queues. Option D is wrong because the policy-map must be applied in the output direction for egress queuing, but the engineer likely applied it correctly; the real issue is that the switch does not have multiple queues configured to isolate the AF41 traffic.

15
MCQhard

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-POLICY Class-map: ICMP-CLASS (match-all) 10 packets, 1000 bytes 5 minute offered rate 0 bps Match: access-group name ICMP-ACL police: cir 8000 bps, bc 1500 bytes, be 1500 bytes conformed 10 packets, 1000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: SSH-CLASS (match-all) 5 packets, 500 bytes 5 minute offered rate 0 bps Match: access-group name SSH-ACL police: cir 16000 bps, bc 3000 bytes, be 3000 bytes conformed 5 packets, 500 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: class-default (match-any) 20 packets, 2000 bytes 5 minute offered rate 0 bps Match: any police: cir 64000 bps, bc 8000 bytes, be 8000 bytes conformed 20 packets, 2000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Based on this output, what can be concluded?

A.ICMP traffic to the control plane is rate-limited to 8 kbps, and all packets so far have been within the conform rate.
B.SSH traffic to the control plane is being dropped because it exceeds the CIR.
C.The control-plane policy is applied in the output direction.
D.All traffic to the control plane is rate-limited to 64 kbps.
AnswerA

The output for the ICMP class shows a police CIR of 8000 bps, and the conformed counter equals the total packet count while the exceeded/dropped counter is zero. This means every ICMP packet destined to the control plane was measured as within the committed information rate and was marked conform, so the packets were transmitted normally rather than rate-limited further. The correct statement identifies both the configured rate and the observed behavior: rate-limited to 8 kbps, but with no actual drops because traffic never exceeded the conform burst. This is supported by the 'police' configuration and the accumulated conformed/exceeded statistics in the control-plane policy output.

Why this answer

The output shows that for the ICMP-CLASS, the police command sets a CIR of 8000 bps (8 kbps). The counters show 10 packets conformed and 0 packets exceeded or violated, meaning all ICMP traffic to the control plane has been within the conform rate and transmitted. This directly confirms that ICMP traffic is rate-limited to 8 kbps and has not yet exceeded that limit.

Exam trap

Cisco often tests the misconception that the class-default police rate applies to all traffic, but in CoPP, each class-map has its own independent police rate, and only traffic not matching explicit classes falls into class-default.

How to eliminate wrong answers

Option B is wrong because the output shows 0 exceeded and 0 violated packets for SSH-CLASS, indicating no SSH traffic has been dropped due to exceeding the CIR; all 5 packets were conformed and transmitted. Option C is wrong because the command 'show policy-map control-plane' and the output line 'Service-policy input: CoPP-POLICY' explicitly show the policy is applied in the input direction, not output. Option D is wrong because the 64 kbps police rate applies only to the class-default catch-all class, not to all traffic; ICMP and SSH have their own separate police rates (8 kbps and 16 kbps respectively), so not all traffic is rate-limited to 64 kbps.

16
MCQmedium

A network administrator is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH, and SNMP. The administrator needs to verify which traffic classes are being matched and how many packets are being dropped by the policy. Which command should be used to display the CoPP policy statistics and class-map information?

A.show policy-map interface
B.show class-map
C.show policy-map control-plane
D.show control-plane host open-ports
AnswerC

This command displays the Control Plane policy-map configuration and the per-class packet statistics, including matched and dropped packets. It directly shows which traffic classes are being matched and how many packets are being dropped, which is exactly what the administrator needs to verify CoPP operation.

Why this answer

The show policy-map control-plane command is specifically designed to display the CoPP policy configuration and per-class statistics, including matched and dropped packets. It allows the administrator to verify which traffic classes are being matched and how many packets are being dropped by the policy. The other commands either show only class-map definitions or interface-level policy statistics, which are not relevant to the control plane.

Exam trap

The trap here is confusing interface-level policy statistics with control plane policy statistics, or assuming that show class-map displays counters when it only shows match criteria.

17
MCQhard

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-POLICY Class-map: MGMT-CLASS (match-all) 100 packets, 5000 bytes 5 minute offered rate 1000 bps Match: access-group name MGMT-ACL police: cir 32000 bps, bc 4000 bytes, be 4000 bytes conformed 80 packets, 4000 bytes; actions: transmit exceeded 15 packets, 750 bytes; actions: drop violated 5 packets, 250 bytes; actions: drop Class-map: class-default (match-any) 200 packets, 10000 bytes 5 minute offered rate 2000 bps Match: any police: cir 64000 bps, bc 8000 bytes, be 8000 bytes conformed 200 packets, 10000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Based on this output, what can be concluded?

A.Management traffic to the control plane is being policed, and some packets are being dropped because they exceed the configured rate.
B.All management traffic is being transmitted without drops.
C.The policer is configured in the output direction.
D.The class-default is dropping packets.
AnswerA

Management traffic matching MGMT-ACL is policed at 32 kbps, and the exceeded and violated counters confirm drops: 15 exceeded packets plus 5 violated packets were discarded rather than transmitted. This satisfies the stem's constraint that control-plane policing actively rate-limits management traffic, proving CoPP enforcement is operational on R1.

Why this answer

The output shows that the CoPP-POLICY policy map is applied to the control plane in the input direction. For the MGMT-CLASS class, the policer has a CIR of 32000 bps, and the counters show 15 packets exceeded and 5 packets violated, both with a drop action. This confirms that some management traffic is being dropped because it exceeds the configured rate, making option A correct.

Exam trap

Cisco often tests the distinction between 'input' and 'output' direction for CoPP, and the trap here is that candidates assume the policy is applied in the output direction or overlook the drop counters in the MGMT-CLASS, leading them to incorrectly select option B or C.

How to eliminate wrong answers

Option B is wrong because the output clearly shows 15 exceeded and 5 violated packets being dropped for the MGMT-CLASS, so not all management traffic is transmitted without drops. Option C is wrong because the command 'show policy-map control-plane' without specifying 'output' defaults to the input direction, and the output explicitly states 'Service-policy input: CoPP-POLICY', confirming it is applied in the input direction. Option D is wrong because the class-default counters show 0 exceeded and 0 violated packets, meaning no packets are being dropped in that class.

18
MCQhard

A network engineer is configuring CoPP on a Cisco router to protect the control plane from excessive traffic. The engineer creates a class-map that matches traffic with a specific ACL that permits TCP port 22 (SSH) from a management subnet (192.168.1.0/24) and denies all other traffic. The CoPP policy applies a police rate of 1 Mbps to this class. After applying the policy, the engineer notices that SSH sessions from the management subnet are being dropped intermittently. The engineer checks the CoPP statistics and sees that the traffic rate is 500 kbps. What is the most likely cause?

A.The CoPP policy has a conform-action of drop, which drops all traffic matching the class.
B.The police rate is too low, and the traffic is being dropped due to exceeding the rate.
C.The ACL is denying SSH traffic from the management subnet.
D.The CoPP policy is applied to the wrong interface, so it is not affecting SSH traffic.
AnswerB

The police rate alone can cause drops even when the average bit rate is below the configured police rate because CoPP uses a token bucket that only allows short bursts up to the burst size. Once the bucket is empty, every packet that exceeds the sustained rate or even a momentary burst is marked as exceeding and is dropped by the exceed-action. Intermittent drops are the classic symptom of a policer with a low rate or small burst parameters, not a config error.

Why this answer

The most likely cause is that traffic is exceeding the police rate in bursts, even though the average rate is 500 kbps and the configured police rate is 1 Mbps. Policing uses a token bucket, and TCP SSH traffic from the management subnet can burst above the configured rate. When bursts exceed the police rate, the exceed-action (by default, drop) drops the excess packets, causing intermittent SSH drops.

If the conform-action were set to drop, all conforming traffic would be dropped consistently, not intermittently. The default conform-action is transmit, and there is no indication it was changed.

Exam trap

A common pitfall is assuming that an average traffic rate below the police rate means there should be no drops. CoPP policing is based on bursts as well as average rate; intermittent drops often occur when bursts exceed the configured rate, even if the average rate is below the police rate.

How to eliminate wrong answers

Option B is wrong because the traffic rate is 500 kbps, which is below the police rate of 1 Mbps, so exceeding the rate is not the cause of drops. Option C is wrong because the ACL permits TCP port 22 from the management subnet, so it is not denying SSH traffic. Option D is wrong because CoPP policies are applied globally to the control plane via the 'control-plane' command, not to a specific interface, and the policy is affecting SSH traffic (drops are occurring).

19
MCQhard

A network engineer is configuring CoPP on a Cisco ASR 1000 router to protect the control plane from excessive traffic. The engineer wants to allow BGP traffic from a specific peer (10.0.0.1) while rate-limiting all other BGP traffic. The engineer creates an ACL that permits TCP port 179 from host 10.0.0.1 and denies all other BGP traffic. The CoPP class-map matches this ACL. However, after applying the policy, BGP sessions from other peers are still being established. What is the most likely reason?

A.The ACL denies all other BGP traffic, so CoPP does not match it, and it falls through to the default class, which permits it.
B.The ACL is applied in the wrong order; the deny statement should be before the permit statement.
C.BGP uses UDP port 179, not TCP, so the ACL does not match BGP traffic.
D.CoPP does not affect BGP sessions because they are established before the policy is applied.
AnswerA

CoPP class-maps only act on traffic the ACL permits; denied traffic matches no class and falls to the default class, which typically permits it. So other BGP peers are not rate-limited, explaining why their sessions still establish.

Why this answer

The ACL is designed to match BGP traffic from host 10.0.0.1 (permit) and deny all other BGP traffic. However, CoPP class-maps match traffic based on permit statements in the ACL; a deny statement in the ACL causes the traffic to not be matched by that class. As a result, BGP traffic from other peers is not classified into the rate-limiting class and falls through to the default class, which typically permits all traffic.

This explains why BGP sessions from other peers are still being established.

Exam trap

Cisco often tests the misconception that a deny statement in an ACL used with CoPP will drop traffic, when in reality it only prevents the traffic from being matched by that class, allowing it to fall through to the default class which typically permits everything.

How to eliminate wrong answers

Option B is wrong because the order of permit and deny statements in an ACL is critical, but here the permit for host 10.0.0.1 is correctly placed before the deny all; the issue is not about order but about how CoPP treats deny entries. Option C is wrong because BGP uses TCP port 179, not UDP; this is a fundamental protocol fact. Option D is wrong because CoPP affects all traffic arriving at the control plane after the policy is applied, regardless of when sessions were established; existing sessions are still subject to rate-limiting.

20
MCQmedium

Given the following configuration: policy-map MARKING_POLICY class CRITICAL_DATA set dscp af31 class BULK_DATA set dscp af11 class class-default set dscp default What is the effect of the set dscp default command in the class-default?

A.It sets the DSCP value to 0, which is the default best-effort marking.
B.It sets the DSCP value to the original value of the packet, effectively not changing it.
C.It sets the DSCP value to 46, which is the default for voice.
D.It is invalid because class-default cannot have a set action.
AnswerA

The `set dscp 0` command explicitly overwrites the Differentiated Services Code Point bits with binary 000000. DSCP 0, also known as CS0 or default PHB, is the standard best-effort marking applied to normal IP traffic. Because this is an explicit action in a policy-map, it always results in DSCP 0 regardless of any original marking.

Why this answer

The 'set dscp default' command explicitly sets the DSCP field to a value of 0, which corresponds to the default best-effort per-hop behavior (PHB) as defined in RFC 2474. This ensures that any traffic not matching the user-defined classes (CRITICAL_DATA or BULK_DATA) is marked with the lowest priority, which is the standard behavior for class-default in a marking policy.

Exam trap

Cisco often tests the misconception that 'default' means 'leave the original value unchanged' or that it refers to a specific high-priority default like voice, rather than the actual DSCP value of 0 for best-effort traffic.

How to eliminate wrong answers

Option B is wrong because 'set dscp default' does not preserve the original packet value; it overwrites the DSCP field with a fixed value of 0. Option C is wrong because DSCP 46 (EF) is the default for voice traffic, not the 'default' keyword, which maps to DSCP 0. Option D is wrong because class-default can indeed have a set action; it is a valid and common practice to mark all unmatched traffic with a specific DSCP value.

21
MCQeasy

What is the purpose of the 'police' command in a QoS policy-map?

A.To shape traffic to a specific rate by buffering excess packets.
B.To limit the rate of traffic and take action (drop or remark) on packets that exceed the rate.
C.To prioritize traffic by assigning it to a strict priority queue.
D.To classify traffic based on IP precedence or DSCP values.
AnswerB

Policing uses a token bucket (or single/two-rate policer) to measure traffic arrival against a configured committed information rate (CIR) and burst size. Packets that conform are forwarded unchanged, while excess packets are either dropped or have their precedence/DSCP marked down (e.g., set to a lower drop probability). This fits the classic definition of policing, which is a rate-limiting action that takes immediate action on nonconforming packets without buffering.

Why this answer

The 'police' command in a Cisco QoS policy-map implements traffic policing, which enforces a rate limit by measuring traffic flow and taking immediate action—typically dropping or remarking packets—when the traffic exceeds the configured rate. Unlike shaping, policing does not buffer excess traffic; it acts on packets in real time, making it ideal for marking down or discarding non-compliant traffic at the ingress or egress of an interface.

Exam trap

Cisco often tests the distinction between policing and shaping—the trap here is that candidates confuse 'police' with 'shape' because both limit traffic rates, but policing drops/remarks without buffering, while shaping queues and delays excess traffic.

How to eliminate wrong answers

Option A is wrong because shaping (not policing) buffers excess packets to smooth traffic to a specific rate; the 'police' command drops or remarks, not buffers. Option C is wrong because strict priority queuing is configured with the 'priority' command within a class, not with 'police'; policing controls rate, not queue scheduling. Option D is wrong because traffic classification based on IP precedence or DSCP is done with the 'class-map' and 'match' commands, not with the 'police' action; policing is applied after classification.

22
MCQhard

A network engineer is configuring QoS on a Cisco IOS router. The engineer needs to ensure that packets marked with DSCP AF31 are placed into a queue that guarantees at least 30% of the interface bandwidth during congestion, while allowing other traffic to use any remaining bandwidth. Which configuration should be used?

A.policy-map QOS class AF31 shape average percent 30
B.policy-map QOS class AF31 bandwidth remaining percent 30
C.policy-map QOS class AF31 bandwidth percent 30
D.policy-map QOS class AF31 priority percent 30
AnswerC

The 'bandwidth percent 30' command guarantees that the class AF31 receives at least 30% of the interface bandwidth during congestion. This is a CBWFQ configuration that provides a minimum bandwidth guarantee, ensuring that AF31 traffic is prioritized while allowing other classes to use the remaining bandwidth. It directly satisfies the requirement.

Why this answer

The 'bandwidth percent 30' command in a policy map class guarantees that the class receives at least 30% of the interface bandwidth during congestion. This is part of CBWFQ and provides a minimum bandwidth guarantee, meeting the requirement while allowing other traffic to utilize remaining bandwidth.

Exam trap

The trap here is confusing bandwidth guarantee commands like 'bandwidth percent' with priority or shaping commands that limit or prioritize traffic differently.

23
MCQhard

A network engineer is configuring QoS on a Cisco IOS XE router. The router must mark all ingress traffic from a specific subnet with DSCP AF31 and ensure that this marking is trusted throughout the network. Which configuration step is required to achieve this?

A.Apply a policy map that sets DSCP AF31 as an output service policy on the router's uplink interface.
B.Create a class map matching the subnet, then a policy map that sets DSCP AF31, and apply it as a service policy on the ingress interface.
C.Configure 'mls qos trust dscp' on the ingress interface and rely on the subnet's existing markings.
D.Use a route map to set DSCP AF31 for all routes matching the subnet and redistribute into OSPF.
AnswerB

To mark traffic from a subnet, you must classify it with a class map, define the marking action in a policy map using 'set dscp af31', and attach the policy to the ingress interface with 'service-policy input'. This ensures packets are marked at ingress, and subsequent devices can trust the DSCP if configured to do so.

Why this answer

To mark traffic from a specific subnet with DSCP AF31, you need a class map to identify the traffic, a policy map to set the DSCP, and the policy applied as an ingress service policy. This ensures packets are marked before any queuing or forwarding decisions, allowing downstream devices to trust and act on the marking.

Exam trap

The trap here is confusing QoS marking with trusting markings; trusting DSCP only preserves existing values and does not mark unmarked traffic.

24
MCQhard

A network engineer is implementing QoS on a Cisco IOS router. The engineer wants to ensure that VoIP traffic is marked with DSCP EF and that the router prioritizes this traffic during congestion. Which mechanism should be used to provide priority queuing for VoIP?

A.Class-Based Weighted Fair Queuing (CBWFQ)
B.Weighted Random Early Detection (WRED)
C.Traffic Shaping
D.Low Latency Queuing (LLQ)
AnswerD

LLQ combines CBWFQ with a strict priority queue. It allows VoIP traffic to be placed in a priority queue that is serviced before other queues, ensuring minimal delay and jitter. LLQ is the recommended mechanism for prioritizing real-time traffic like VoIP during congestion.

Why this answer

LLQ is the QoS mechanism that provides strict priority queuing, ensuring that VoIP traffic marked with DSCP EF is serviced before other traffic during congestion. This minimizes latency and jitter, which are critical for voice quality. LLQ is configured using the 'priority' command within a policy map.

Exam trap

The trap here is assuming that CBWFQ alone can provide priority, when it only guarantees bandwidth without strict priority.

25
MCQmedium

A network engineer runs the following command on Router R8: R8# show policy-map interface GigabitEthernet0/1 GigabitEthernet0/1 Service-policy output: QOS_POLICY Class-map: VOICE (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp ef (46) Queueing strict priority queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 0/0 police cir 1000000 bc 15625 be 15625 conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: DATA (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp af31 (26) Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 0/0 bandwidth remaining percent 50 Class-map: class-default (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 0/0 bandwidth remaining percent 50 Based on this output, what can be concluded?

A.Voice traffic is being prioritized but not policed.
B.The interface is not passing any traffic.
C.Data traffic is being dropped due to policing.
D.The policy-map is applied to input traffic.
AnswerB

This is correct because the output of `show policy-map interface` displays all class counters as zero, including classifications, bytes, and drops. A zero packet count across every class indicates that no packets have been classified or forwarded on this interface since the policy was attached. Therefore, the interface is not passing any traffic at all.

Why this answer

The output shows all counters at zero for every class, including the class-default, and the '5 minute offered rate' is 0 bps for all classes. This indicates that no packets have been processed by this policy-map on GigabitEthernet0/1, meaning the interface is not passing any traffic. The presence of policing and queuing configurations does not imply traffic is being dropped; the counters confirm zero activity.

Exam trap

Cisco often tests the ability to interpret zero counters in QoS output, trapping candidates who assume that configured policies (like policing or queuing) are actively dropping or shaping traffic without verifying the actual packet counts.

How to eliminate wrong answers

Option A is wrong because the output explicitly shows a police command under the VOICE class with a CIR of 1000000 bps, meaning voice traffic is both prioritized (strict priority queue) and policed. Option B is correct as explained. Option C is wrong because the DATA class shows zero packets, zero drops, and a drop rate of 0 bps, indicating no traffic has been processed, let alone dropped due to policing.

Option D is wrong because the output states 'Service-policy output: QOS_POLICY', which means the policy-map is applied in the output direction, not input.

26
MCQmedium

Given the following configuration on a Cisco IOS router: policy-map SHAPE class class-default shape average 1000000 interface Serial0/0/0 service-policy output SHAPE What is the effect of this configuration?

A.The router will limit the transmit rate on Serial0/0/0 to an average of 1 Mbps by queuing excess packets.
B.The router will drop any traffic exceeding 1 Mbps on Serial0/0/0.
C.The router will mark all traffic with a rate limit of 1 Mbps but not enforce it.
D.The configuration is invalid because 'shape average' requires a class-map with a match statement.
AnswerA

This is the definition of traffic shaping. The 'shape average 1000000' command configures a token bucket that allows bursts up to the committed burst size, but the average transmit rate is capped at 1 Mbps. When traffic exceeds this rate, excess packets are buffered in the shaping queue rather than dropped (unless the queue overflows and tail drop occurs). This smoothing of traffic avoids packet loss and is appropriate for interfaces that can tolerate delay but need to conform to a subscribed rate.

Why this answer

The configuration applies a shaping policy to the Serial0/0/0 interface, which limits the transmit rate to an average of 1 Mbps. Shaping works by queuing excess packets that exceed the configured rate, smoothing the traffic burst and preventing packet loss due to interface congestion. This is why Option A is correct.

Exam trap

Cisco often tests the distinction between shaping (queuing) and policing (dropping/remarking), so candidates mistakenly choose the dropping option (B) when they see a rate limit, not realizing shaping buffers excess traffic.

How to eliminate wrong answers

Option B is wrong because shaping does not drop traffic; it queues excess packets to enforce the rate, whereas policing would drop or remark traffic. Option C is wrong because shaping actively enforces the rate by buffering, not just marking traffic without enforcement. Option D is wrong because 'shape average' in the class-default class does not require a match statement; class-default matches all unclassified traffic by default.

27
MCQmedium

A network engineer is configuring CoPP on a Cisco router to protect the control plane from excessive traffic. The router experiences high CPU utilization due to SSH and SNMP traffic. The engineer creates a class-map to match SSH (TCP/22) and SNMP (UDP/161) and applies a policy-map that polices this traffic to 1 Mbps. After applying the policy, legitimate SSH sessions from the management station start dropping intermittently. What is the most likely cause?

A.The police rate of 1 Mbps is too low for the combined SSH and SNMP traffic from the management station.
B.The CoPP policy is applied to the wrong interface, affecting transit traffic instead of control plane traffic.
C.The class-map should match on DSCP values instead of port numbers to be effective.
D.The policy-map should use the 'drop' action instead of 'police' to protect the control plane.
AnswerA

The police rate of 1 Mbps is insufficient for the aggregated SSH (TCP/22) and SNMP (UDP/161) control-plane traffic generated by the management station. Under CoPP, the policer uses a token bucket that drops packets exceeding the committed information rate, and if the peak management traffic exceeds 1 Mbps, legitimate packets will be dropped, causing timeouts or loss of management access. The correct remedy is to raise the police rate above the expected combined throughput, not to change the classification or action.

Why this answer

The most likely cause is that the police rate of 1 Mbps is too low for the combined SSH and SNMP traffic from the management station. CoPP polices all traffic matching the class-map (SSH and SNMP) as a single aggregate flow. If the management station generates bursts of SSH and SNMP traffic that together exceed 1 Mbps, the policer will drop packets, causing legitimate SSH sessions to drop intermittently.

Exam trap

Cisco often tests the misconception that a single police rate applied to a class-map containing multiple protocols is sufficient, when in reality the aggregate rate must account for the combined peak traffic of all matched protocols.

How to eliminate wrong answers

Option B is wrong because CoPP is applied to the control plane using the 'service-policy' command under 'control-plane' configuration, not to an interface; applying it to an interface would affect transit traffic, but the scenario states the policy was applied correctly to protect the control plane. Option C is wrong because matching on port numbers (TCP/22, UDP/161) is the correct and standard method for identifying SSH and SNMP traffic in a CoPP class-map; DSCP values are not typically used for these protocols and would not solve the dropping issue. Option D is wrong because the 'police' action is the correct way to rate-limit traffic in CoPP; using 'drop' would discard all matching traffic unconditionally, which would be even more disruptive than policing.

28
MCQeasy

A network engineer is designing a QoS policy for a Cisco router that connects to an MPLS VPN. The service provider expects all traffic to be marked with IP Precedence values. The engineer wants to ensure that voice traffic (DSCP EF) is mapped to IP Precedence 5. What configuration is required on the router to perform this mapping?

A.Configure a policy-map that sets the IP precedence to 5 using 'set ip precedence 5'.
B.Configure a policy-map that sets the DSCP to EF, and the router will automatically set IP precedence to 5.
C.Use the 'qos map dscp-ip-precedence' command to create a mapping table.
D.The router will automatically map DSCP EF to IP precedence 5 without any configuration.
AnswerA

The MQC policy-map action `set ip precedence 5` explicitly writes the 3-bit IP precedence value in the Type of Service byte. Precedence 5 is the standard value associated with the EF PHB (DSCP 46), so this command satisfies the marking requirement directly. In Cisco IOS/IOS-XE, this is the correct method when the requirement is specifically to mark IP precedence, and attaching the policy map to the interface (or globally) makes the classification and marking take effect.

Why this answer

The 'set ip precedence 5' command in a policy-map explicitly marks the IP Precedence field to 5, which corresponds to the same value as DSCP EF (46) in the IP header. This ensures that voice traffic is marked with IP Precedence 5 as required by the service provider, regardless of any existing DSCP markings.

Exam trap

Cisco often tests the misconception that DSCP and IP Precedence are automatically synchronized or that a single command like 'set dscp ef' will implicitly set the IP Precedence field, when in fact they are independent markings that require separate configuration.

How to eliminate wrong answers

Option B is wrong because setting DSCP to EF does not automatically set IP Precedence to 5; the router treats DSCP and IP Precedence as separate fields, and explicit configuration is needed to map between them. Option C is wrong because the 'qos map dscp-ip-precedence' command does not exist; the correct command for creating a mapping table is 'qos map dscp-ip-precedence' is not a valid Cisco IOS command, and such mappings are typically done via policy-map actions. Option D is wrong because the router does not automatically map DSCP EF to IP Precedence 5; without explicit configuration, the IP Precedence field remains unchanged or is set based on default behavior, which may not meet the service provider's requirement.

29
MCQhard

A network engineer runs the following command on Router R1: R1# show policy-map control-plane Control Plane Service-policy input: CoPP-POLICY Class-map: BGP-CLASS (match-all) 50 packets, 2500 bytes 5 minute offered rate 500 bps Match: access-group name BGP-ACL police: cir 64000 bps, bc 8000 bytes, be 8000 bytes conformed 50 packets, 2500 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: SNMP-CLASS (match-all) 200 packets, 10000 bytes 5 minute offered rate 2000 bps Match: access-group name SNMP-ACL police: cir 16000 bps, bc 2000 bytes, be 2000 bytes conformed 150 packets, 7500 bytes; actions: transmit exceeded 40 packets, 2000 bytes; actions: drop violated 10 packets, 500 bytes; actions: drop Class-map: class-default (match-any) 100 packets, 5000 bytes 5 minute offered rate 1000 bps Match: any police: cir 32000 bps, bc 4000 bytes, be 4000 bytes conformed 100 packets, 5000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Based on this output, what can be concluded?

A.SNMP traffic to the control plane is experiencing drops due to exceeding its policer rate, while BGP traffic is within its rate.
B.BGP traffic is being dropped because it exceeds the CIR.
C.All traffic to the control plane is being dropped.
D.The control-plane policy is applied in the output direction.
AnswerA

The SNMP-CLASS policer shows 40 exceeded and 10 violated packets dropped against its 16000 bps CIR, while BGP-CLASS reports zero exceeded and zero violated with all 50 packets conformed and transmitted, confirming BGP stayed within its 64000 bps rate.

Why this answer

The output shows that for the SNMP-CLASS, 40 packets exceeded and 10 packets violated the policer, resulting in drops, while the BGP-CLASS had 0 exceeded and 0 violated packets, meaning all BGP traffic conformed to its CIR of 64000 bps. This confirms that SNMP traffic is being dropped due to exceeding its policer rate, while BGP traffic is within its rate.

Exam trap

The trap here is that candidates may misinterpret the 'exceeded' and 'violated' counters as indicating that all traffic in a class is being dropped, when in fact only packets that exceed the policer thresholds are dropped, while conforming traffic is still transmitted.

How to eliminate wrong answers

Option B is wrong because the BGP-CLASS shows 0 exceeded and 0 violated packets, indicating no drops; it is not exceeding its CIR. Option C is wrong because the output shows that conformed packets for all classes are being transmitted, so not all traffic is dropped. Option D is wrong because the command 'show policy-map control-plane' and the output explicitly state 'Service-policy input: CoPP-POLICY', meaning the policy is applied in the input direction, not output.

30
MCQmedium

A network engineer is configuring a zone-based firewall (ZBF) on a Cisco router to allow traffic from the inside zone to the outside zone while blocking traffic from outside to inside. The engineer creates zones, assigns interfaces, and configures a policy-map with a class-map that matches all traffic from inside to outside. The engineer applies the policy to the zone-pair inside-to-outside. However, traffic from inside to outside is being dropped. What is the most likely reason?

A.The policy-map does not include an 'inspect' or 'pass' action for the matched traffic.
B.The zone-pair should be configured as outside-to-inside instead.
C.The class-map must also match return traffic for the firewall to allow the session.
D.The policy-map is applied to the wrong zone-pair; it should be applied to the inside zone.
AnswerA

In Zone-Based Firewall, a policy-map that matches traffic but does not specify an explicit action such as 'inspect' or 'pass' causes the router to apply the implicit default action of 'drop'. The class-map correctly identifies the inside-to-outside traffic, but the missing action means no forwarding or stateful inspection is performed, so all matched packets are silently discarded. The fix is to configure an 'inspect' action (or 'pass' for stateless forwarding) under the policy-map for that class.

Why this answer

In a zone-based firewall (ZBF), a policy-map applied to a zone-pair defines the actions to be taken on traffic flowing between the two zones. By default, traffic between zones is denied unless explicitly permitted. The class-map matches traffic from inside to outside, but without an 'inspect' or 'pass' action in the policy-map, the matched traffic is implicitly dropped.

The 'inspect' action enables stateful inspection and allows return traffic, while 'pass' permits traffic without stateful tracking; omitting either results in a deny.

Exam trap

Cisco often tests the misconception that simply matching traffic in a class-map and applying it to a zone-pair is enough to permit traffic, when in fact an explicit action (inspect or pass) is required in the policy-map.

How to eliminate wrong answers

Option B is wrong because the zone-pair direction is correct: traffic flows from inside to outside, so the zone-pair must be configured as inside-to-outside, not outside-to-inside. Option C is wrong because the class-map does not need to match return traffic; the 'inspect' action automatically creates stateful entries to allow return traffic. Option D is wrong because policy-maps are applied to zone-pairs, not directly to zones; applying a policy-map to the inside zone is not a valid ZBF configuration.

31
MCQhard

A network engineer runs the following command on Router R6: R6# show policy-map interface GigabitEthernet0/1 GigabitEthernet0/1 Service-policy output: QOS_POLICY Class-map: VOICE (match-any) 500 packets, 50000 bytes 5 minute offered rate 50000 bps, drop rate 0 bps Match: ip dscp ef (46) Queueing strict priority queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 500/50000 police cir 1000000 bc 15625 be 15625 conformed 500 packets, 50000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: DATA (match-any) 1000 packets, 100000 bytes 5 minute offered rate 100000 bps, drop rate 0 bps Match: ip dscp af31 (26) Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 1000/100000 bandwidth remaining percent 50 Class-map: class-default (match-any) 2000 packets, 200000 bytes 5 minute offered rate 200000 bps, drop rate 0 bps Match: any Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 2000/200000 bandwidth remaining percent 50 Based on this output, what can be concluded?

A.Voice traffic is being dropped because it exceeds the police rate.
B.Data traffic is being guaranteed 50% of the remaining bandwidth.
C.All traffic is being shaped to a CIR of 1 Mbps.
D.The policy-map is applied to input traffic.
AnswerB

The `bandwidth remaining percent 50` command on the DATA class ensures that data packets receive 50% of the bandwidth that is left over after the strict-priority voice queue has been serviced. This is a proportional share of residual capacity, not an absolute fixed bandwidth guarantee. In a CBWFQ policy, this allows the data class to compete with other default classes using the remaining bandwidth percentage toward the total unallocated bandwidth.

Why this answer

The 'bandwidth remaining percent 50' command under the DATA class guarantees that class 50% of any bandwidth left unused by the strict-priority VOICE class. The policy-map is applied in the output direction, and the VOICE class uses a police (not shape) with a CIR of 1 Mbps, so only excess voice packets are dropped, not all traffic shaped. The class-default also gets 50% of the remaining bandwidth, confirming that the DATA class is indeed guaranteed 50% of the leftover bandwidth.

Exam trap

Cisco often tests the distinction between 'police' (which drops or marks excess traffic) and 'shape' (which buffers to a rate), and candidates mistakenly assume 'police cir' implies shaping or that any CIR command shapes all traffic.

How to eliminate wrong answers

Option A is wrong because the police output shows 0 exceeded and 0 violated packets, meaning no voice traffic has been dropped due to exceeding the police rate. Option C is wrong because the policy uses a 'police' command (which meters and drops or marks) on the VOICE class, not a 'shape' command; shaping would buffer and delay traffic to a CIR, which is not configured here. Option D is wrong because the command 'show policy-map interface GigabitEthernet0/1' output explicitly states 'Service-policy output: QOS_POLICY', indicating the policy is applied to output traffic, not input.

32
MCQhard

A security engineer is configuring CoPP (Control Plane Policing) on a Cisco router to protect the control plane from DoS attacks. The policy must rate-limit SSH traffic to 1 Mbps with a burst of 2000 bytes, and drop all other traffic destined to the control plane that exceeds a default rate. Which class-map and policy-map configuration is correct?

A.class-map match-all SSH match protocol ssh policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop
B.class-map match-all SSH match access-group name SSH_ACL policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop class class-default police 8000 conform-action transmit exceed-action drop
C.class-map match-all SSH match protocol ssh policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop class class-default police 8000 conform-action transmit exceed-action drop
D.class-map match-all SSH match protocol ssh policy-map COPP class SSH police 2000 1000000 conform-action transmit exceed-action drop
AnswerC

This is the correct CoPP configuration: `class-map match-all SSH` with `match protocol ssh` classifies SSH control-plane traffic, and the policy map `COPP` applies a police rate of 1,000,000 bps with a burst of 2000 bytes, dropping exceeding traffic. The `class-default` then polices all other control-plane traffic at 8000 bps, ensuring that no unclassified protocol can flood the CPU. The syntax and parameters are correctly ordered (rate in bps, burst in bytes), providing comprehensive control-plane protection.

Why this answer

It uses the 'match protocol ssh' class-map to identify SSH traffic, applies a police rate of 1,000,000 bps (1 Mbps) with a burst of 2000 bytes, and includes a class-default with a police rate of 8000 bps to drop all other control-plane traffic exceeding a default rate. This matches the requirement to rate-limit SSH and drop other traffic that exceeds a default rate, which is a common CoPP best practice to protect the control plane.

Exam trap

Cisco often tests the requirement for a class-default policy in CoPP to drop all other traffic, and the trap here is that candidates may forget that without it, unmatched traffic is permitted by default, or they may confuse the order of police parameters (rate vs. burst).

How to eliminate wrong answers

Option A is wrong because it lacks a class-default policy; without it, any traffic not matching the SSH class is implicitly permitted, failing to drop other traffic exceeding a default rate. Option B is wrong because it uses 'match access-group name SSH_ACL' instead of 'match protocol ssh', which is less efficient and not the direct method for matching SSH protocol traffic; also, the class-default police rate of 8000 is correct, but the match method is incorrect for the requirement. Option D is wrong because it swaps the police parameters: the first value (2000) is the burst size and the second (1000000) is the rate, but the correct syntax is 'police rate burst', so this would apply a rate of 2000 bps and a burst of 1,000,000 bytes, which does not meet the 1 Mbps rate requirement.

33
MCQmedium

A company is implementing QoS on its campus network. The network engineer configures a policy-map that sets the CoS value for voice traffic to 5 on a switch interface. However, when the traffic reaches the router, the CoS marking is lost. What is the most likely reason?

A.The router does not trust the CoS marking and re-marks it to 0.
B.CoS is a Layer 2 marking and is not carried across a Layer 3 hop; the router must map CoS to DSCP.
C.The switch must be configured to set DSCP instead of CoS.
D.The router must have 'mls qos trust cos' configured on the interface.
AnswerB

CoS is a Layer 2 class-of-service field carried exclusively in the 802.1Q VLAN tag, so it is only meaningful on a single Layer 2 segment. When a router receives a frame, it de-encapsulates the Layer 2 header, including the 802.1Q tag, and then forwards the packet as a Layer 3 IP packet. The CoS value is therefore lost and cannot be preserved across a routed hop; the router must explicitly map the incoming CoS value to the IP DSCP field before routing. This mapping must occur at the ingress or before the Layer 3 forwarding decision to maintain end-to-end QoS priority.

Why this answer

CoS (Class of Service) is a Layer 2 marking field in the 802.1Q VLAN tag, which is stripped when a frame passes through a Layer 3 device (router). Since the router operates at Layer 3, it does not preserve the CoS value; instead, the router must map the CoS to a DSCP (Differentiated Services Code Point) value at Layer 3 to maintain QoS across the routed hop. Option B correctly identifies this fundamental Layer 2 vs.

Layer 3 boundary issue.

Exam trap

The trap here is that candidates assume CoS is preserved across routers because they see 'trust cos' on switches, but Cisco tests the understanding that CoS is a Layer 2-only marking that disappears at a Layer 3 boundary, requiring DSCP for inter-VLAN or routed QoS.

How to eliminate wrong answers

Option A is wrong because the router does not automatically 'trust' or 're-mark' CoS to 0; CoS is simply not present in the IP packet after the Layer 2 header is removed, so no re-marking occurs. Option C is wrong because setting DSCP instead of CoS on the switch would not solve the problem—the issue is that CoS is lost at the Layer 3 boundary, and DSCP must be used on the router, but the switch can set both CoS and DSCP; the root cause is the Layer 2/3 demarcation. Option D is wrong because 'mls qos trust cos' is a Catalyst switch command (not a router command) that tells the switch to trust the CoS value on ingress; it does not apply to routers and would not preserve CoS across a Layer 3 hop.

34
MCQmedium

Examine this configuration: policy-map QOS_POLICY class VOICE priority percent 10 class VIDEO bandwidth percent 30 class class-default fair-queue ! interface GigabitEthernet0/0 service-policy output QOS_POLICY What is the effect of this policy-map?

A.Voice traffic gets strict priority up to 10% of interface bandwidth, video gets at least 30%, and all other traffic is fair-queued.
B.Voice and video both get priority queuing, with voice at 10% and video at 30%.
C.The policy-map is invalid because you cannot use both priority and bandwidth in the same policy-map.
D.The policy-map will only shape traffic, not prioritize it.
AnswerA

In the policy-map, the voice class is configured with the priority command, which creates a strict priority queue capped at 10% of the interface bandwidth, ensuring Voice over IP packets are serviced first and minimizing delay and jitter. The video class uses the bandwidth command, which reserves a minimum of 30% of link capacity for video traffic using class-based weighted fair queuing (CBWFQ), though this does not guarantee immediate scheduling over other classes. All other traffic falls into the default class, where the fair-queue command applies, permitting equal distribution of the remaining bandwidth among remaining flows. Thus, the statement accurately describes the configured queuing behavior.

Why this answer

The policy-map uses the 'priority percent 10' command under class VOICE, which provides strict priority queuing for voice traffic, guaranteeing it is serviced first up to 10% of the interface bandwidth. The 'bandwidth percent 30' command under class VIDEO allocates a minimum bandwidth guarantee of 30% for video traffic, while the 'fair-queue' command under class-default ensures all other traffic shares the remaining bandwidth fairly using Cisco's Class-Based Weighted Fair Queuing (CBWFQ). This configuration is valid and commonly used in enterprise QoS designs to prioritize real-time traffic while still providing bandwidth guarantees for other critical traffic.

Exam trap

Cisco often tests the misconception that 'priority' and 'bandwidth' cannot coexist in the same policy-map, or that 'bandwidth' implies priority queuing, when in fact they serve different roles (strict priority vs. guaranteed minimum bandwidth) and are commonly used together in enterprise QoS designs.

How to eliminate wrong answers

Option B is wrong because it incorrectly states that both voice and video get priority queuing; in this configuration, only the VOICE class uses the 'priority' command, while the VIDEO class uses 'bandwidth', which provides a minimum bandwidth guarantee, not strict priority. Option C is wrong because it claims the policy-map is invalid; Cisco IOS allows the use of both 'priority' and 'bandwidth' commands in the same policy-map, as long as the priority class is configured first and the total bandwidth allocations do not exceed 100%. Option D is wrong because the policy-map does not include any 'shape' command; it applies queuing and scheduling policies (priority, bandwidth, and fair-queue) on output, not traffic shaping.

35
MCQmedium

A network engineer runs the following command on Router R4: R4# show policy-map interface GigabitEthernet0/1 GigabitEthernet0/1 Service-policy input: SHAPE_POLICY Class-map: class-default (match-any) 1000 packets, 100000 bytes 5 minute offered rate 100000 bps, drop rate 0 bps Match: any Queueing shape (average) cir 500000, bc 5000, be 5000 target shape rate 500000 Based on this output, what can be concluded?

A.Traffic is being shaped to an average rate of 500 kbps.
B.Traffic is being policed to 500 kbps.
C.The policy is applied to output traffic.
D.The offered rate exceeds the shaping rate, causing drops.
AnswerA

The `shape` command with a CIR of 500000 bits per second configures a token-bucket shaper that limits the long-term average transmit rate to 500 kbps. Unlike policing, shaping smooths traffic by buffering excess packets in a queue, then sending them at the configured rate, so the output is a regulated, even flow rather than bursty with drops. This is exactly what the policy-map does for the matched traffic.

Why this answer

The output shows a shape (average) cir 500000 with a target shape rate of 500000, which is 500,000 bps (500 kbps). Shaping buffers excess traffic to enforce an average rate, unlike policing which drops or marks. The 'drop rate 0 bps' confirms no drops are occurring, so traffic is being shaped to 500 kbps.

Exam trap

Cisco often tests the distinction between shaping and policing, where candidates confuse the 'shape' keyword with 'police' or misinterpret the 'input' direction as output, especially when the interface is GigabitEthernet0/1 and the policy is named SHAPE_POLICY.

How to eliminate wrong answers

Option B is wrong because the command is 'shape (average)', not 'police', and shaping buffers traffic rather than dropping or marking it like policing does. Option C is wrong because the output explicitly states 'Service-policy input: SHAPE_POLICY', indicating the policy is applied to input traffic, not output. Option D is wrong because the offered rate is 100,000 bps, which is below the shaping rate of 500,000 bps, and the drop rate is 0 bps, so no drops are occurring.

36
MCQhard

A network architect is designing a QoS policy for a Cisco Catalyst switch. The architect needs to ensure that voice traffic is marked with the appropriate DSCP value for expedited forwarding. Which DSCP value should be used for voice traffic?

A.CS7 (56)
B.CS6 (48)
C.AF31 (26)
D.EF (46)
AnswerD

EF (Expedited Forwarding) with DSCP value 46 is the standard marking for voice traffic. It provides low latency, low jitter, and low loss, which are critical for voice quality. Voice traffic should be marked with EF to ensure it receives priority treatment in the network. This is a widely accepted best practice.

Why this answer

Voice traffic should be marked with DSCP EF (46) to ensure expedited forwarding, which provides low latency, jitter, and loss. Other DSCP values like AF31 are used for call signaling, while CS6 and CS7 are reserved for network control. Proper marking ensures that voice packets receive priority treatment in QoS-enabled networks.

Exam trap

The trap here is confusing voice payload marking with call signaling marking, or using control traffic DSCP values for voice.

37
MCQmedium

Consider the following configuration: class-map match-any VOICE match ip dscp ef class-map match-any VIDEO match ip dscp af41 match ip dscp af42 What is the effect of the match-any keyword in these class-maps?

A.A packet must match all specified DSCP values to be classified into the class.
B.A packet matching either DSCP EF or AF41 will be classified into both classes.
C.A packet matching any one of the specified DSCP values is classified into that class.
D.The match-any keyword is invalid for DSCP matching; only match-all is supported.
AnswerC

The match-any keyword in a class-map means the match conditions are combined with a logical OR. Consequently, a packet is classified into that class if it matches any one of the specified DSCP values—for example, either DSCP EF or AF41. This is the standard behavior for DSCP-based classification in the Modular QoS CLI (MQC).

Why this answer

The `match-any` keyword in a Cisco class-map means that a packet needs to match only one of the listed match criteria to be classified into that class. In the VIDEO class-map, a packet matching either DSCP AF41 or AF42 will be classified as VIDEO. This is the default behavior for class-maps when no keyword is specified, but explicitly using `match-any` reinforces that logical OR operation is applied.

Exam trap

Cisco often tests the confusion between `match-any` (logical OR) and `match-all` (logical AND), expecting candidates to mistakenly think that `match-any` requires all conditions or that it causes a packet to be placed into multiple classes simultaneously.

How to eliminate wrong answers

Option A is wrong because `match-any` uses logical OR, not AND; a packet does not need to match all specified DSCP values. Option B is wrong because a packet matching DSCP EF would be classified only into the VOICE class, not both classes, as class-maps are evaluated independently and a single packet can match multiple class-maps but the keyword does not cause cross-classification. Option D is wrong because `match-any` is perfectly valid for DSCP matching; Cisco IOS supports both `match-any` and `match-all` keywords in class-map definitions.

38
MCQmedium

Examine the following configuration snippet on a Cisco IOS-XE router: interface GigabitEthernet0/1 service-policy output QOS_POLICY policy-map QOS_POLICY class VOICE priority percent 10 class VIDEO bandwidth percent 30 class class-default fair-queue What is the effect of this configuration?

A.VOICE traffic is guaranteed 10% of the interface bandwidth with strict priority queuing, VIDEO traffic is guaranteed 30%, and all other traffic shares the remaining bandwidth using fair-queuing.
B.VOICE traffic is limited to 10% of bandwidth, VIDEO to 30%, and all other traffic is dropped if the interface is congested.
C.VOICE traffic is given priority over VIDEO, but VIDEO can use up to 30% of bandwidth only if VOICE is not using its allocation.
D.The policy-map is invalid because 'priority' and 'bandwidth' cannot be used together in the same policy-map.
AnswerA

This is correct. The 'priority' command places VOICE in a strict-priority (LLQ) queue and, during congestion, guarantees it the configured 10% of interface bandwidth so it cannot be starved by other traffic. The 'bandwidth' command reserves 30% of bandwidth for VIDEO, ensuring its minimum service under load. The default class with 'fair-queue' applies flow-based WFQ to all other traffic, which fairly shares the remaining bandwidth without dropping any class outright.

Why this answer

The 'priority percent 10' command under class VOICE enables strict priority queuing, guaranteeing that VOICE traffic is served first up to 10% of the interface bandwidth. The 'bandwidth percent 30' under class VIDEO provides a minimum bandwidth guarantee of 30% during congestion. The 'fair-queue' under class-default ensures that all other traffic shares the remaining bandwidth fairly using flow-based queuing, which is the default behavior when no explicit bandwidth is configured.

Exam trap

Cisco often tests the misconception that 'priority' and 'bandwidth' cannot coexist in the same policy-map, but they are allowed as long as they are in different classes; the trap is that candidates think the policy-map is invalid, when in fact it is a standard LLQ configuration.

How to eliminate wrong answers

Option B is wrong because it incorrectly states that all other traffic is dropped during congestion; in reality, class-default uses fair-queuing to share remaining bandwidth, not drop. Option C is wrong because it suggests VIDEO can use up to 30% only if VOICE is not using its allocation; the 'bandwidth percent' command guarantees a minimum bandwidth regardless of VOICE usage, not a conditional maximum. Option D is wrong because 'priority' and 'bandwidth' can be used together in the same policy-map; they are applied to different classes, which is perfectly valid and common in Cisco QoS designs.

39
MCQeasy

A network team must design QoS for a campus network that carries voice, video, and data traffic. The design must use the DiffServ model and ensure that voice traffic is prioritized over all other traffic classes. Which DSCP marking and queuing strategy should be used for voice?

A.Mark voice with AF41 and place in a weighted fair queue.
B.Mark voice with EF and place in a strict priority queue.
C.Mark voice with CS3 and place in a low-latency queue.
D.Mark voice with BE and rely on WRED for drop precedence.
AnswerB

DiffServ uses DSCP to classify traffic. EF (46) provides low latency, low jitter and assured bandwidth for voice, and a strict priority queue services it ahead of all other classes, guaranteeing voice is prioritised over video and data.

Why this answer

Voice traffic requires strict priority to ensure minimal jitter and latency. DSCP EF (Expedited Forwarding, per RFC 3246) is the standard marking for real-time traffic like voice, and placing it in a strict priority queue (LLQ) guarantees that voice packets are serviced before any other queue, which is essential for meeting QoS requirements in a DiffServ model.

Exam trap

The trap here is that candidates often confuse AF41 (used for video) with voice marking, or assume that any low-latency queue (LLQ) works regardless of DSCP value, but Cisco specifically tests that voice must use EF and strict priority queue, not just any low-latency queue.

How to eliminate wrong answers

Option A is wrong because AF41 (Assured Forwarding class 4, low drop probability) is designed for traffic that can tolerate some delay and jitter, such as video conferencing, not for voice which needs strict priority; weighted fair queue does not provide the absolute priority required for voice. Option C is wrong because CS3 (Class Selector 3) is a legacy marking that does not guarantee low latency or strict priority; while a low-latency queue (LLQ) is correct, the DSCP marking must be EF for voice, not CS3. Option D is wrong because BE (Best Effort, DSCP 0) is the default marking for non-priority traffic, and WRED (Weighted Random Early Detection) is a congestion avoidance mechanism that drops packets before queue overflow, which is unsuitable for voice as it introduces jitter and packet loss.

40
MCQmedium

Examine the following configuration: policy-map SHAPE_POLICY class class-default shape average 10000000 service-policy INNER_POLICY What is the purpose of the nested service-policy (service-policy INNER_POLICY) under the shape command?

A.It applies the INNER_POLICY to traffic after shaping, allowing per-class queuing within the shaped rate.
B.It applies the INNER_POLICY to traffic before shaping, which is not supported.
C.It is used to shape traffic twice, first at 10 Mbps and then again based on INNER_POLICY.
D.This configuration is invalid because service-policy cannot be nested under shape.
AnswerA

In hierarchical QoS (HQoS), the outer policy performs shaping at the parent level, and after the shaper has metered the traffic to the configured rate, the inner policy is applied to the shaped output. This allows the child policy to classify and queue traffic into multiple classes, all within the aggregate shaped bandwidth. The result is that each class gets its own queue and scheduling behavior, but the total output never exceeds the parent's shaped rate, so per-class queuing occurs inside the shaper's token bucket.

Why this answer

The nested service-policy under the shape command applies the INNER_POLICY to traffic after it has been shaped to 10 Mbps. This allows per-class queuing and scheduling within the shaped rate, enabling finer QoS control such as bandwidth allocation or priority queuing for specific traffic classes while ensuring the overall output does not exceed the shaped rate.

Exam trap

Cisco often tests the concept that a nested service-policy under shape applies after shaping, not before, and that it is a valid method for hierarchical QoS, leading candidates to incorrectly assume it is unsupported or that it shapes traffic twice.

How to eliminate wrong answers

Option B is wrong because the nested service-policy under shape is applied after shaping, not before; applying a policy before shaping would require a different configuration (e.g., a parent policy with a service-policy before the shape command). Option C is wrong because the configuration does not shape traffic twice; the shape command defines the shaping rate, and the nested policy manages queuing within that rate, not additional shaping. Option D is wrong because nesting a service-policy under shape is a valid and supported Cisco IOS QoS feature, commonly used for hierarchical QoS (HQoS).

41
MCQhard

An engineer is implementing a QoS policy on a Cisco IOS XE router. The requirement is to prioritize voice traffic (marked DSCP EF) and ensure that it receives strict priority scheduling with a guaranteed bandwidth of 30% of the interface capacity. Which queuing mechanism should be configured on the interface?

A.First-In, First-Out (FIFO) queuing with a rate limit for voice traffic.
B.Low Latency Queuing (LLQ) with a priority statement for the voice class.
C.Weighted Random Early Detection (WRED) with a precedence-based drop policy for voice.
D.Class-Based Weighted Fair Queuing (CBWFQ) with a bandwidth guarantee for the voice class.
AnswerB

LLQ is an extension of CBWFQ that adds a strict priority queue for delay-sensitive traffic such as voice. Configuring a priority statement for the voice class ensures that packets marked DSCP EF are dequeued first, up to the specified bandwidth (30%). This provides strict priority scheduling and guarantees bandwidth, meeting both requirements for voice traffic.

Why this answer

Low Latency Queuing (LLQ) combines the bandwidth guarantees of CBWFQ with a strict priority queue. By configuring a priority statement for the voice class, packets marked DSCP EF are placed in a low-latency queue that is serviced before other queues, ensuring minimal delay and jitter. The priority bandwidth allocation of 30% guarantees that voice traffic receives the necessary bandwidth even during congestion.

Exam trap

The trap here is assuming that CBWFQ alone can provide strict priority for voice; in reality, only LLQ (CBWFQ with a priority queue) offers strict priority scheduling.

42
MCQmedium

A network engineer is implementing QoS on a Cisco IOS router. The requirement is to classify traffic based on the DSCP value in the IP header and then mark it with a new DSCP value. Which QoS mechanism should be used to accomplish this?

A.Class-based weighted fair queueing (CBWFQ)
B.Policy-based routing (PBR)
C.Low latency queueing (LLQ)
D.Modular QoS CLI (MQC)
AnswerD

MQC is the framework for configuring QoS on Cisco IOS. It uses class-maps to classify traffic (e.g., matching DSCP) and policy-maps to define actions such as marking with a new DSCP value. The service-policy command applies the policy to an interface. This is the standard and correct method to classify and mark traffic based on DSCP.

Why this answer

The Modular QoS CLI (MQC) is the correct framework for classifying traffic based on DSCP and marking it with a new DSCP value. It involves creating a class-map to match the desired DSCP, a policy-map to set the new DSCP, and applying the service-policy to an interface. This provides a flexible and standardized way to implement QoS policies.

Exam trap

The trap here is confusing QoS mechanisms that use MQC (like CBWFQ and LLQ) with MQC itself. CBWFQ and LLQ are queuing actions within a policy-map, but the classification and marking is done by the MQC framework.

43
MCQmedium

A network engineer runs the following command on Router R3: R3# show mls qos interface GigabitEthernet0/1 GigabitEthernet0/1 trust state: trust DSCP trust mode: trust dscp COS override: dis default COS: 0 DSCP Mutation Map: default dscp mutation map trust device: none qos mode: port-based R3# show mls qos QoS is enabled globally QoS global counters: total packets not matching QoS criteria = 0 Total packets with known CoS = 0 Total packets dropped by policing = 0 Based on this output, what can be concluded?

A.The interface is configured to trust CoS values.
B.The interface will overwrite incoming DSCP values with default CoS.
C.The interface trusts the DSCP markings of incoming packets.
D.QoS is disabled globally.
AnswerC

The command output states 'trust state: trust DSCP' and 'trust mode: trust dscp', confirming that the interface is configured to honor the DSCP markings carried in the IP header of incoming packets. In this mode, the switch classifies each packet according to its DSCP value and maps that value to the appropriate QoS queue or policy, without altering the original DSCP field.

Why this answer

The output shows 'trust state: trust DSCP' and 'trust mode: trust dscp', which explicitly indicates that the interface trusts the DSCP markings of incoming packets. Additionally, 'qos mode: port-based' confirms that QoS is enabled on the interface, and the global QoS status shows 'QoS is enabled globally'. Therefore, the interface will preserve and use the incoming DSCP values for QoS classification.

Exam trap

Cisco often tests the distinction between 'trust DSCP' and 'trust CoS'—the trap here is that candidates may confuse the 'trust state: trust DSCP' output with trusting CoS, especially when the 'default COS' field is present, leading them to incorrectly select Option A or B.

How to eliminate wrong answers

Option A is wrong because the interface trusts DSCP, not CoS; 'trust state: trust DSCP' and 'COS override: dis' confirm that CoS values are not trusted. Option B is wrong because the interface does not overwrite incoming DSCP values; 'trust mode: trust dscp' means DSCP values are preserved, and 'default COS: 0' only applies when no trust is set. Option D is wrong because the output explicitly states 'QoS is enabled globally' and the interface shows 'qos mode: port-based', indicating QoS is active.

44
MCQmedium

Consider the following configuration snippet: policy-map QOS_POLICY class VOICE priority percent 30 class VIDEO bandwidth percent 20 queue-limit 50 packets class class-default fair-queue queue-limit 100 packets What is the effect of this configuration?

A.The VOICE class traffic is always sent before other classes, but if it exceeds 30% of the interface bandwidth, excess traffic is dropped.
B.The VOICE class traffic is always sent before other classes, and excess traffic beyond 30% is queued in the default class.
C.The VIDEO class traffic is treated with strict priority after the VOICE class.
D.The class-default uses Weighted Fair Queuing with a maximum queue size of 100 packets, and all classes share the remaining bandwidth equally.
AnswerA

The VOICE class is assigned strict priority through the `priority` command, so its packets are dequeued before any other class whenever the priority queue is non-empty. The `percent 30` keyword configures an aggregate policer that allows traffic up to 30% of the interface bandwidth and drops any excess immediately (conform-action transmit, exceed-action drop). This is a hard ceiling—excess voice traffic is not re-queued or forwarded, it is discarded on the spot.

Why this answer

The 'priority percent 30' command under the VOICE class enables strict priority queuing, meaning VOICE traffic is always transmitted before any other class. However, the priority queue is policed at 30% of the interface bandwidth; any traffic exceeding this rate is dropped, not queued. This is a fundamental behavior of the priority command in Cisco IOS — excess priority traffic is dropped to prevent starvation of other queues.

Exam trap

Cisco often tests the misconception that excess priority traffic is re-queued into the default class or another queue, when in fact it is always dropped to enforce the bandwidth limit and protect other traffic classes.

How to eliminate wrong answers

Option B is wrong because excess priority traffic beyond the configured percentage is dropped, not re-queued into the default class; the priority command does not allow excess traffic to fall back to another queue. Option C is wrong because the VIDEO class uses bandwidth percent 20, which is a non-priority queue (class-based weighted fair queuing), not strict priority; only the VOICE class has strict priority. Option D is wrong because the class-default uses fair-queue, but the remaining bandwidth is not shared equally among all classes — the VIDEO class has a guaranteed 20%, and the remaining bandwidth after VOICE and VIDEO is shared among the default class flows via fair-queuing, not equally across all classes.

45
MCQhard

A network engineer is configuring control plane policing (CoPP) on a Cisco IOS XE router that peers BGP with two service providers and is managed over SSH from a jump host. After applying a new policy-map, the engineer notices that BGP sessions remain up but SSH logins intermittently time out during traffic spikes. Which action should the engineer take to resolve the SSH timeouts while preserving the CoPP protection model?

A.Add a class-map matching TCP port 22 traffic and attach it to the policy-map with an appropriate rate and conform/exceed actions.
B.Remove the service-policy from the control plane and rely on QoS on the data plane instead.
C.Increase the BGP class rate and move the SSH class into the BGP class-map.
D.Configure an ACL that permits only the jump host's IP and apply it as the match for the class-default class.
AnswerA

SSH traffic must be explicitly classified so CoPP can rate-limit it separately instead of letting it fall into a default or catch-all class that may be policed aggressively. Adding a TCP port 22 class with a suitable rate and transmit action preserves protection while guaranteeing management access. This is the standard CoPP design practice for management protocols.

Why this answer

CoPP works by classifying punted control-plane traffic into classes and applying per-class policers. If SSH is not explicitly matched, it is handled by class-default, which is often policed conservatively. Creating a dedicated class matching TCP port 22 with an adequate rate and a conform action of transmit ensures interactive management traffic survives bursts while BGP and other protocols stay protected.

Exam trap

The trap here is treating CoPP as an all-or-nothing filter and removing it, rather than recognizing that unclassified management traffic is the real cause of the timeouts.

46
MCQmedium

Consider the following configuration on a Cisco router: class-map match-any CRITICAL_DATA match ip dscp af21 af22 af23 policy-map QOS class CRITICAL_DATA bandwidth remaining percent 50 class class-default fair-queue interface GigabitEthernet0/0 service-policy output QOS Which statement about this configuration is true?

A.Traffic matching DSCP AF21, AF22, or AF23 is guaranteed 50% of the interface bandwidth, and all other traffic is subject to fair-queuing.
B.Only traffic with DSCP AF21 is matched; AF22 and AF23 are ignored because 'match-any' requires all conditions to be true.
C.The configuration is invalid because 'bandwidth remaining percent' cannot be used with 'fair-queue' in the same policy-map.
D.The policy-map will only be applied to incoming traffic on GigabitEthernet0/0.
AnswerA

Because the class map uses match-any, traffic marked with DSCP AF21, AF22, or AF23 is all placed into this class. The 'bandwidth remaining percent 50' command reserves half of the interface's available non-priority bandwidth for that class, and since no priority queue is configured, this effectively gives those AF flows a 50% share of the link when congestion occurs. Traffic that does not match any listed DSCP value falls into the implicit class-default, which is explicitly configured with fair-queue, so all other flows share the remaining 50% fairly.

Why this answer

The 'bandwidth remaining percent 50' command under class CRITICAL_DATA guarantees that traffic matching DSCP AF21, AF22, or AF23 will receive 50% of any remaining bandwidth after any explicit bandwidth reservations are satisfied. The 'class-default' uses fair-queuing, which distributes the remaining bandwidth equally among flows in that class. Since no explicit bandwidth is reserved elsewhere, the CRITICAL_DATA class effectively gets 50% of the interface bandwidth, and all other traffic is subject to fair-queuing.

Exam trap

Cisco often tests the distinction between 'match-any' and 'match-all' in class-maps, where candidates mistakenly think 'match-any' requires all conditions to be true, when in fact it matches if any one condition is true.

How to eliminate wrong answers

Option B is wrong because 'match-any' means the class matches if any one of the listed DSCP values (AF21, AF22, or AF23) is present, not all; the statement incorrectly claims that only AF21 is matched. Option C is wrong because 'bandwidth remaining percent' and 'fair-queue' can coexist in the same policy-map; 'bandwidth remaining percent' allocates a percentage of leftover bandwidth to a class, while 'fair-queue' in class-default provides per-flow queuing without conflict. Option D is wrong because the 'service-policy output QOS' command applies the policy to outgoing traffic on GigabitEthernet0/0, not incoming traffic.

47
MCQhard

An engineer is using the Cisco pyATS framework to test the configuration of a new QoS policy on a router. The engineer writes a testbed file and a test script that logs into the router, applies the configuration, and then verifies the output of 'show policy-map interface'. The test script fails because the verification step cannot find the expected output. The engineer confirms that the configuration was applied successfully. What is the most likely cause of the failure?

A.The pyATS library requires Python 3.8 or later, and the engineer is using an older version.
B.The testbed file has incorrect credentials for the router.
C.The test script does not include a sleep or wait mechanism after applying the configuration.
D.The test script uses the 'genie' library instead of 'pyats' for parsing.
AnswerC

When a QoS policy is applied on a Cisco IOS-XE device, the operational output—such as 'show policy-map interface'—does not update instantly; the device takes a short period to propagate the configuration into its internal data structures and hardware abstraction layer. The test script pushes the configuration and immediately parses the output without any sleep, wait, or polling loop, so the verification runs before the policy is fully reflected. Adding a delay (for example, 'time.sleep(5)' or a Genie 'learn' with a 'sleep' argument) or implementing a retry loop would give the device time to converge and allow the test to pass.

Why this answer

After applying a QoS policy with the `service-policy` command, the router may take a short time to update the operational state shown in `show policy-map interface`. Without an explicit sleep or wait mechanism in the pyATS test script, the verification step executes before the router has processed and reflected the new policy, causing a mismatch even though the configuration was applied successfully.

Exam trap

Cisco often tests the misconception that CLI configuration changes are reflected immediately in show commands, when in reality there is often a brief propagation delay that automation scripts must account for with a wait mechanism.

How to eliminate wrong answers

Option A is wrong because pyATS supports Python 3.6 and later, and the question does not indicate any Python version incompatibility; the failure is not related to Python version requirements. Option B is wrong because the engineer confirmed the configuration was applied successfully, which means the testbed file credentials were correct and the login step succeeded. Option D is wrong because the 'genie' library is actually the parsing library that works with pyATS, not a separate framework; using 'genie' for parsing is standard and would not cause the verification to fail to find expected output.

48
Drag & Dropmedium

Drag and drop the steps of CoPP class-map match criteria and rate-limit application into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

CoPP configuration requires defining class-maps first, then policy-map with police statements, then applying to control-plane. The order ensures proper traffic classification and rate-limiting.

49
MCQmedium

Given the following CoPP configuration: class-map match-all COPP_ICMP match access-group name ICMP_ACL ! policy-map COPP_POLICY class COPP_ICMP police 8000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY What is the effect?

A.All ICMP traffic to the control plane is rate-limited to 8000 bps.
B.ICMP traffic is permitted unconditionally.
C.The policy is applied to all interfaces, not just the control plane.
D.The class-map is missing a match-all statement.
AnswerA

The correct interpretation is that the policy-map applies a police command to the class containing ICMP traffic destined for the control plane, setting a committed information rate (CIR) of 8000 bps. The conform-action transmit allows traffic within the rate, while the exceed-action drop causes any excess ICMP packets to be discarded, so the net effect is a hard rate limit on ICMP control-plane traffic.

Why this answer

The CoPP policy matches ICMP traffic via the class-map and applies a police rate of 8000 bps to the control plane. The 'conform-action transmit exceed-action drop' ensures that traffic within the rate is forwarded, while excess traffic is dropped, effectively rate-limiting ICMP to the control plane.

Exam trap

Cisco often tests the misconception that 'match-all' is required for class-maps with a single match condition, but it is optional and the configuration is valid; the trap here is that candidates think the class-map is missing a match-all statement, but it is explicitly present.

How to eliminate wrong answers

Option B is wrong because the policy explicitly polices ICMP traffic to 8000 bps, not permitting it unconditionally; exceeding the rate results in drops. Option C is wrong because the 'service-policy input COPP_POLICY' is applied under the 'control-plane' configuration, which only affects traffic destined to the control plane, not all interfaces. Option D is wrong because the class-map already includes 'match-all' (the default behavior is match-all when not specified, but here it is explicitly stated), and the configuration is valid; the class-map correctly references an access-group named ICMP_ACL.

50
MCQmedium

Consider the following configuration: policy-map QUEUE_POLICY class VOICE priority level 1 police cir 1000000 class VIDEO priority level 2 police cir 2000000 class class-default fair-queue What is the effect of using priority level 1 and priority level 2?

A.VOICE traffic (level 1) is always sent before VIDEO traffic (level 2), and both are policed.
B.VOICE and VIDEO traffic are treated equally and share the priority bandwidth.
C.VIDEO traffic (level 2) is sent before VOICE traffic (level 1) because it has a higher police rate.
D.This configuration is invalid because only one priority level is allowed.
AnswerA

In Cisco's hierarchical QoS, 'priority level 1' and 'priority level 2' create separate strict-priority queues. The scheduler empties level 1 before level 2, so voice is always sent before video, even if video's policed rate were higher. Both levels are independently policed to their configured rates; excess traffic is dropped or optionally re-marked. This is valid on platforms such as the ASR 1000 that support multiple priority levels.

Why this answer

The 'priority level' command under a class in a policy-map allows multiple priority queues with different levels. Level 1 is the highest priority, so VOICE traffic (level 1) is always scheduled before VIDEO traffic (level 2). Both classes are also subject to policing, which enforces a maximum rate (CIR) and drops or remarks excess traffic.

This ensures low-latency treatment for VOICE while still providing priority queuing for VIDEO, but with a lower scheduling preference.

Exam trap

The trap here is that candidates often assume only one priority queue is allowed per policy-map, but Cisco tests the 'priority level' feature which permits multiple priority queues with hierarchical strict scheduling.

How to eliminate wrong answers

Option B is wrong because VOICE and VIDEO are not treated equally; priority level 1 (VOICE) is strictly scheduled before priority level 2 (VIDEO), creating a hierarchical priority structure. Option C is wrong because a higher police rate does not affect scheduling priority; priority level determines scheduling order, not the policing rate. Option D is wrong because the configuration is valid; Cisco IOS supports multiple priority levels (up to 16 in some platforms) using the 'priority level' command, allowing differentiated priority queuing.

51
MCQmedium

A network engineer runs the following command on Router R1: R1# show policy-map interface GigabitEthernet0/1 GigabitEthernet0/1 Service-policy output: QOS_POLICY Class-map: VOICE (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp ef (46) Queueing queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 0/0 police cir 1000000 bc 15625 be 15625 conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: class-default (match-any) 100 packets, 10000 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any Queueing queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 100/10000 Based on this output, what can be concluded?

A.Voice traffic is being marked with DSCP EF and is being policed at 1 Mbps.
B.Voice traffic is not being classified because no packets match the VOICE class.
C.All traffic is being dropped due to the police action.
D.The policy-map is applied in the input direction.
AnswerB

This is the correct interpretation of the output. The VOICE class, which likely uses a class-map matching DSCP EF, shows 0 packets in the 'show policy-map interface' output, meaning no traffic has been classified into that class. This could be because voice traffic is absent, is not marked with DSCP EF at the source, or the match statement is misconfigured. As a result, the QoS actions (like police) inside the VOICE class have never been triggered.

Why this answer

The output shows 0 packets matched for the VOICE class, meaning no traffic has been classified as voice despite the policy being configured. The police action is configured but never triggered because no packets match the class. Therefore, the correct conclusion is that voice traffic is not being classified.

Exam trap

Cisco often tests the ability to read 'show policy-map interface' output carefully, where the trap is that candidates assume a configured policy is actively shaping or policing traffic without verifying the packet match counters.

How to eliminate wrong answers

Option A is wrong because while the policy does police voice traffic at 1 Mbps (cir 1000000), the output shows 0 packets matched, so voice traffic is not actually being marked or policed. Option C is wrong because the class-default shows 100 packets output with 0 drops, indicating traffic is being forwarded, not dropped. Option D is wrong because the command 'show policy-map interface' output explicitly states 'Service-policy output', meaning the policy is applied in the output direction, not input.

52
MCQmedium

Examine the CoPP configuration: class-map match-any COPP_SSH match access-group name SSH_ACL ! policy-map COPP_POLICY class COPP_SSH police 10000 conform-action transmit exceed-action drop class class-default police 5000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY Which statement is true?

A.SSH traffic is limited to 10 kbps; all other control plane traffic is limited to 5 kbps.
B.All control plane traffic is limited to 10 kbps.
C.The class-default police rate is ignored because it is not explicitly matched.
D.The policy-map should be applied to an interface, not the control plane.
AnswerA

SSH class (COPP_SSH) is explicitly matched with a police rate of 10000 bps, so SSH control-plane packets conform to that 10 kbps limit. The class-default is configured with a police rate of 5000 bps, applying to all other control-plane traffic not matched by a specific class. Since CoPP uses a hierarchy where class-default catches unmatched traffic, the effective result is SSH at 10 kbps and everything else at 5 kbps.

Why this answer

The CoPP policy explicitly matches SSH traffic via the COPP_SSH class and applies a police rate of 10,000 bps (10 kbps) to it. All other control plane traffic falls into class-default, which is policed at 5,000 bps (5 kbps). The 'conform-action transmit exceed-action drop' ensures that traffic exceeding these rates is dropped, so SSH is limited to 10 kbps and all other control plane traffic to 5 kbps.

Exam trap

Cisco often tests the misconception that class-default is optional or ignored when not explicitly configured, but in reality it is always present and must be considered in CoPP policies to avoid unintended drops of essential control plane traffic.

How to eliminate wrong answers

Option B is wrong because it incorrectly states that all control plane traffic is limited to 10 kbps, ignoring the separate police rate of 5 kbps applied to class-default. Option C is wrong because class-default is explicitly matched in the policy-map and its police rate is not ignored; it is a default class that catches all unmatched traffic. Option D is wrong because CoPP policies are specifically designed to be applied to the control plane using the 'control-plane' command, not to an interface; applying it to an interface would not protect the control plane from CPU-bound traffic.

53
MCQhard

A network engineer issues the following command on Router R8: R8# show policy-map interface gigabitethernet 0/1 GigabitEthernet0/1 Service-policy output: SHAPE-1M Class-map: class-default (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any queue limit 64 packets (queue depth 0) (congestion occurrences) shape (average) cir 1000000, bc 10000, be 10000 target shape rate 1000000 Based on this output, what is true about the traffic shaping policy?

A.The policy is policing traffic to 1 Mbps.
B.The policy is shaping traffic to an average rate of 1 Mbps.
C.The policy is dropping all traffic because the queue is full.
D.The policy is applied in the input direction.
AnswerB

The configuration 'shape (average) cir 1000000' indicates a committed information rate (CIR) of 1,000,000 bits per second, which equals 1 Mbps. Shaping averages the traffic rate over time by buffering bursts and draining them through a token bucket, so the long-term average matches the CIR. This is the correct interpretation of the policy's behavior.

Why this answer

The output shows 'shape (average) cir 1000000', which configures traffic shaping to an average rate of 1 Mbps. Shaping buffers excess traffic and smooths it out over time, unlike policing which drops or marks packets. The 'target shape rate 1000000' confirms the shaped rate is 1 Mbps.

Exam trap

Cisco often tests the distinction between shaping and policing; the trap here is that candidates see 'cir 1000000' and assume policing, but shaping uses the same CIR terminology and the 'shape' keyword is the giveaway.

How to eliminate wrong answers

Option A is wrong because the command 'shape (average)' implements shaping, not policing; policing would use the 'police' command and would show actions like 'conform-action' or 'exceed-action'. Option C is wrong because the queue depth is 0, indicating no packets are currently queued, and the queue limit is 64 packets, so the queue is not full. Option D is wrong because the output explicitly states 'Service-policy output: SHAPE-1M', meaning the policy is applied in the output (egress) direction, not input.

54
MCQhard

A network engineer runs the following command on Router R9: R9# show queueing interface GigabitEthernet0/1 Interface GigabitEthernet0/1 queueing strategy: class-based weighted fair Queueing on output: Class-based Weighted Fair Queueing Queueing on input: FIFO R9# show policy-map interface GigabitEthernet0/1 GigabitEthernet0/1 Service-policy output: QOS_POLICY Class-map: VOICE (match-any) 100 packets, 10000 bytes 5 minute offered rate 10000 bps, drop rate 0 bps Match: ip dscp ef (46) Queueing strict priority queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 100/10000 police cir 1000000 bc 15625 be 15625 conformed 100 packets, 10000 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: DATA (match-any) 200 packets, 20000 bytes 5 minute offered rate 20000 bps, drop rate 0 bps Match: ip dscp af31 (26) Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 200/20000 bandwidth remaining percent 50 Class-map: class-default (match-any) 300 packets, 30000 bytes 5 minute offered rate 30000 bps, drop rate 0 bps Match: any Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 300/30000 bandwidth remaining percent 50 Based on this output, what can be concluded?

A.The interface uses WFQ for output queuing.
B.Voice traffic is being dropped because it exceeds the police rate.
C.Data traffic is guaranteed 50% of the remaining bandwidth after priority queuing.
D.The policy-map is applied to input traffic.
AnswerC

The DATA class is configured with 'bandwidth remaining percent 50', meaning it is guaranteed 50% of the bandwidth left after the strict priority queue (LLQ) for VOICE has been served. This is relative to remaining bandwidth, not a fixed absolute percentage of the interface rate, so data can use more than half when voice is silent but is protected to at least half when voice is active. It is a correct statement about the policy's bandwidth allocation.

Why this answer

The 'bandwidth remaining percent 50' command under the DATA class-map allocates 50% of the interface bandwidth that remains after the strict-priority VOICE queue has been serviced. This is the standard behavior for class-based weighted fair queuing (CBWFQ) when a priority queue is present: the priority queue is served first, and then the remaining bandwidth is distributed among the non-priority classes according to their configured percentages.

Exam trap

Cisco often tests the distinction between 'bandwidth percent' (which allocates a percentage of the total interface bandwidth) and 'bandwidth remaining percent' (which allocates a percentage of the bandwidth left after priority queuing), and candidates frequently confuse these two commands.

How to eliminate wrong answers

Option A is wrong because the output shows 'queueing strategy: class-based weighted fair', not legacy WFQ; CBWFQ is a distinct mechanism that allows user-defined classes and bandwidth guarantees, whereas WFQ is a flow-based algorithm without class maps. Option B is wrong because the police statistics show 'conformed 100 packets, 10000 bytes' and 'exceeded 0 packets, 0 bytes', indicating that no voice traffic has exceeded the police rate of 1 Mbps and thus no drops have occurred. Option D is wrong because the 'show policy-map interface' output explicitly states 'Service-policy output: QOS_POLICY', confirming the policy is applied to output traffic, not input.

55
MCQmedium

Consider the following partial configuration for QoS on a Cisco IOS-XE router: class-map match-all VOICE match ip dscp ef ! policy-map QOS_POLICY class VOICE priority 1000 class class-default fair-queue ! interface GigabitEthernet0/0 service-policy output QOS_POLICY What is the effect of the 'priority 1000' command under class VOICE?

A.Voice traffic is placed in a strict priority queue with a bandwidth limit of 1000 kbps.
B.Voice traffic is given a minimum bandwidth guarantee of 1000 kbps but no priority.
C.Voice traffic is dropped if it exceeds 1000 kbps.
D.Voice traffic is shaped to 1000 kbps.
AnswerA

The `priority` command creates a low-latency queue serviced before other classes, and its 1000 value sets the guaranteed bandwidth in kbps. This satisfies the stem's requirement to identify the effect of `priority 1000`: voice traffic receives strict priority scheduling capped at 1000 kbps, while `fair-queue` handles remaining class-default traffic.

Why this answer

The 'priority 1000' command under a class in a policy-map enables Low Latency Queuing (LLQ) for that class, placing its traffic in a strict priority queue. The value 1000 specifies the bandwidth limit in kbps that the priority queue is policed to; traffic exceeding this rate is dropped when congestion occurs. This ensures voice traffic gets low latency while preventing it from starving other classes.

Exam trap

The trap is confusing priority with bandwidth; candidates may think priority 1000 guarantees 1000 kbps without dropping, but it actually polices and drops excess traffic during congestion.

How to eliminate wrong answers

Option B is wrong because 'priority' provides strict priority service, not just a minimum bandwidth guarantee; the 'bandwidth' command would give a minimum guarantee without priority. Option C is wrong because although excess traffic above 1000 kbps is dropped during congestion, the primary effect is strict priority queuing with a policed rate, not simply dropping all traffic above the limit. Option D is wrong because shaping buffers excess traffic to smooth it, whereas priority policing drops excess traffic immediately.

56
Drag & Dropmedium

Drag and drop the steps of DSCP-to-CoS mapping at LAN boundary into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Why this order

At the LAN boundary (switch port), DSCP is mapped to CoS for 802.1Q trunking. The order ensures proper trust, mapping, and queuing for consistent QoS across the campus network.

57
MCQmedium

A network engineer is deploying Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, OSPF, and SSH management. The engineer applies a CoPP policy-map to the control plane with a class that matches BGP traffic and sets police rate 8000 conform-action transmit exceed-action drop. After applying the policy, BGP sessions intermittently flap during route convergence. Which action should the engineer take to resolve the issue while maintaining control plane protection?

A.Apply the CoPP policy to all router interfaces as an input service policy instead of to the control plane.
B.Remove the CoPP policy from the control plane interface and rely on interface ACLs instead.
C.Increase the police rate for the BGP class or change the exceed-action to transmit, after verifying the offered rate.
D.Change the CoPP policy to use priority queuing instead of policing for the BGP class.
AnswerC

The intermittent BGP flaps during convergence indicate that legitimate BGP control traffic is exceeding the 8,000 pps police rate and being dropped by the exceed-action. Increasing the police rate or changing the exceed-action to transmit for the BGP class restores session stability while still policing other control plane traffic. Verification of the offered rate is essential to size the policer correctly.

Why this answer

BGP session flapping immediately after applying a policer that drops exceeded traffic points to legitimate BGP control packets being dropped because the configured rate is too low for convergence bursts. The correct remediation is to right-size the policer for the BGP class, either by raising the rate or by permitting excess traffic, after confirming the actual offered rate from the control plane.

Exam trap

The trap here is assuming that any control plane drops must be caused by an attack rather than by an undersized policer that drops legitimate routing protocol traffic.

58
MCQmedium

Examine the following configuration: policy-map QUEUE class GOLD bandwidth percent 25 queue-limit 64 packets class SILVER bandwidth percent 25 queue-limit 128 packets class class-default fair-queue interface GigabitEthernet0/2 service-policy output QUEUE Which statement about this configuration is true?

A.The GOLD class has a smaller queue limit than SILVER, which may cause more packet drops for GOLD traffic under congestion.
B.The SILVER class will always receive more bandwidth than GOLD because of its larger queue limit.
C.The configuration is invalid because 'queue-limit' cannot be used with 'bandwidth percent' in the same class.
D.The 'fair-queue' command in class-default will override the bandwidth allocation for GOLD and SILVER.
AnswerA

GOLD's queue-limit of 64 packets is half SILVER's 128, so during congestion GOLD fills its buffer sooner and tail-drops excess packets earlier, despite both classes receiving equal 25 percent bandwidth guarantees. Bandwidth percent governs scheduling weight, not buffer depth, so the smaller limit directly increases GOLD's drop probability.

Why this answer

The GOLD class has a queue-limit of 64 packets, while the SILVER class has a queue-limit of 128 packets. Under congestion, the smaller queue for GOLD will fill up faster, leading to more tail drops for GOLD traffic, even though both classes are allocated the same bandwidth percentage. This demonstrates that queue-limit directly affects drop probability, not bandwidth allocation.

Exam trap

Cisco often tests the misconception that a larger queue-limit implies more bandwidth, when in fact queue-limit only affects buffer depth and drop behavior, not bandwidth allocation.

How to eliminate wrong answers

Option B is wrong because queue-limit does not affect bandwidth allocation; bandwidth is controlled by the 'bandwidth percent' command, which is set to 25% for both GOLD and SILVER, so they receive equal bandwidth under congestion. Option C is wrong because 'queue-limit' can be used with 'bandwidth percent' in the same class; they are independent QoS parameters that control different aspects (bandwidth guarantee vs. queue depth). Option D is wrong because 'fair-queue' in class-default only applies to the default class and does not override the explicit bandwidth allocation for GOLD and SILVER classes, which are configured with strict bandwidth percentages.

59
MCQmedium

A network architect is designing QoS for a converged network carrying voice, video, and data. The design must use the DiffServ model and ensure that voice traffic is marked with the highest priority and that video traffic is marked with a lower priority but still above data. Which DSCP markings should be assigned to voice and video traffic, respectively, to comply with the standard Per-Hop Behavior (PHB) definitions?

A.Voice: DSCP 46 (EF); Video: DSCP 34 (AF41)
B.Voice: DSCP 56 (CS7); Video: DSCP 48 (CS6)
C.Voice: DSCP 40 (AF41); Video: DSCP 46 (EF)
D.Voice: DSCP 26 (AF31); Video: DSCP 18 (AF21)
AnswerA

Voice is marked DSCP 46 (EF), which places it in the strict-priority queue in every Cisco router/switch, ensuring minimal delay, jitter, and loss—essential for real-time voice. Video uses DSCP 34 (AF41), an assured-forwarding class with low drop precedence, giving it priority over ordinary data but not over voice, while still allowing it to be dropped gracefully under severe congestion. This pairing follows the standard Cisco Enterprise QoS model and ensures voice quality is never compromised by video bursts.

Why this answer

The DiffServ model defines specific Per-Hop Behaviors (PHBs) for different traffic types. Voice traffic requires low latency, jitter, and loss, which is best served by the Expedited Forwarding (EF) PHB, assigned DSCP 46. Video traffic, while still delay-sensitive, can tolerate some loss and is typically marked with Assured Forwarding (AF41, DSCP 34), which provides a lower priority queue than EF but higher than best-effort data.

Exam trap

Cisco often tests the specific DSCP values for EF (46) and AF41 (34) and the fact that voice must use EF (not AF or CS) to ensure strict priority queuing, while video uses the highest AF class (AF41) to differentiate it from data without breaking the EF queue.

How to eliminate wrong answers

Option B is wrong because DSCP 56 (CS7) and DSCP 48 (CS6) are Class Selector codepoints used for network control traffic (e.g., routing protocols), not for voice or video; they would starve other traffic and violate the standard PHB definitions. Option C is wrong because it reverses the priority: DSCP 40 (AF41) is for video, not voice, and DSCP 46 (EF) is for voice, not video; this would incorrectly prioritize video over voice. Option D is wrong because DSCP 26 (AF31) and DSCP 18 (AF21) are Assured Forwarding classes with lower drop precedence, typically used for mission-critical data or streaming video, not for real-time voice; they do not provide the strict priority queuing required for voice traffic.

60
MCQmedium

A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router that runs BGP, SSH management, and SNMP polling. A class-map named CLASS-MGMT matches SNMP and SSH traffic, and a policy-map named COPP-POLICY applies a police rate of 8000 bps with a conform-action transmit and exceed-action drop for that class. After the policy is attached to the control plane, SNMP polling intermittently fails while BGP remains stable. Which action should the engineer take to resolve the SNMP failures while still protecting the route processor?

A.Move the policy-map from the control plane to the data plane interface facing the SNMP server.
B.Add a new class-map that matches BGP and apply a lower police rate to it, then reattach the policy.
C.Increase the police rate in the CLASS-MGMT class to a value that accommodates the normal SNMP and SSH burst rate.
D.Change the exceed-action from drop to transmit so that SNMP packets are never discarded.
AnswerC

SNMP polling and SSH generate bursty traffic to the route processor. An 8000 bps police rate is far below the normal management traffic rate, so conforming packets are transmitted but excess packets are dropped, causing intermittent SNMP failures. Raising the rate for that class to match observed management traffic preserves CoPP protection while allowing legitimate management polling to reach the control plane.

Why this answer

SNMP polling is bursty and can briefly exceed a very low police rate. When the exceed-action drops packets, polling becomes intermittent. The correct fix is to raise the police rate for the management class to a value that reflects real SNMP and SSH traffic while keeping CoPP in place to protect the route processor from abuse.

Disabling enforcement or moving the policy to the data plane is not appropriate.

Exam trap

The trap here is assuming that any CoPP drop means the policy should be removed or the exceed-action changed to transmit, rather than tuning the rate to match legitimate control-plane traffic.

61
MCQhard

A network engineer runs the following command on Router R2: R2# show class-map Class Map match-any VOICE (id 1) Match ip dscp ef (46) Class Map match-any DATA (id 2) Match ip dscp af31 (26) Class Map match-any class-default (id 0) Match any R2# show policy-map Policy Map QOS_POLICY Class VOICE priority level 1 police cir 1000000 bc 15625 be 15625 Class DATA bandwidth remaining percent 50 Class class-default bandwidth remaining percent 50 R2# show policy-map interface GigabitEthernet0/1 GigabitEthernet0/1 Service-policy output: QOS_POLICY Class-map: VOICE (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp ef (46) Queueing strict priority queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 0/0 police cir 1000000 bc 15625 be 15625 conformed 0 packets, 0 bytes; actions: transmit exceeded 0 packets, 0 bytes; actions: drop violated 0 packets, 0 bytes; actions: drop Class-map: DATA (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp af31 (26) Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 0/0 bandwidth remaining percent 50 (0 kbps) Class-map: class-default (match-any) 100 packets, 10000 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any Queueing (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 100/10000 bandwidth remaining percent 50 (0 kbps) Based on this output, what can be concluded?

A.Voice traffic is being prioritized with strict priority queuing and policed at 1 Mbps.
B.Data traffic is being guaranteed 50% of the remaining bandwidth.
C.All traffic is being handled by class-default, which gets 100% of the bandwidth.
D.The police command on VOICE is causing drops for voice traffic.
AnswerC

This option is correct because the policy-map output shows that only class-default has matched traffic, with 100 packets. On Cisco IOS, class-default is the implicit final class that catches all packets not matched by user-defined class-maps; when it is the only class with non-zero traffic, it is allowed to use 100% of the interface bandwidth. Since VOICE and DATA classes are empty, no other queuing or policing actions are invoked, and class-default receives the full link capacity.

Why this answer

The output shows that only class-default has processed any packets (100 packets, 10000 bytes), while the VOICE and DATA classes have zero packets. This indicates that no traffic matching DSCP EF or AF31 has been offered, so all traffic falls into class-default, which is allocated 50% of the remaining bandwidth. However, since the VOICE class is empty, the priority queue is unused, and class-default effectively receives all available bandwidth.

Exam trap

Cisco often tests the misconception that simply configuring a QoS policy means it is actively shaping or prioritizing traffic, but the key is to check the actual packet counters to see which classes are receiving traffic.

How to eliminate wrong answers

Option A is wrong because although the VOICE class is configured with strict priority queuing and a police rate of 1 Mbps, the output shows zero packets matched for VOICE, so no voice traffic is being prioritized or policed. Option B is wrong because the DATA class is configured with bandwidth remaining percent 50, but again zero packets have been matched for DATA, so no data traffic is being guaranteed that bandwidth. Option D is wrong because the police command on VOICE is not causing drops for voice traffic; the output shows zero packets in the VOICE class, so no policing actions have been triggered.

62
MCQmedium

Given the following policy-map: policy-map QOS_POLICY class VOICE priority percent 30 class VIDEO bandwidth percent 20 queue-limit 100 packets class class-default fair-queue What is the effect of the 'priority percent 30' command in the VOICE class?

A.Voice traffic is placed in a strict priority queue with a guaranteed bandwidth of 30% of the interface bandwidth.
B.Voice traffic is limited to 30% of the interface bandwidth and will be dropped if exceeded.
C.Voice traffic is given a weight of 30 in the weighted fair queueing algorithm.
D.Voice traffic is re-marked with IP precedence 30.
AnswerA

The priority command in a Cisco MQC policy map creates a strict priority queue (PQ) for the voice class, which is drained by the scheduler before any other queue. The percentage specifies the bandwidth reserved for that queue during congestion, ensuring low latency and jitter for real-time traffic. This guarantee is measured against the interface bandwidth, so voice always has a dedicated share of link capacity even under heavy load.

Why this answer

The 'priority percent 30' command in the VOICE class configures a strict priority queue (LLQ) that guarantees voice traffic up to 30% of the interface bandwidth. During congestion, voice packets are always transmitted before other traffic, but they are policed to ensure they do not exceed the allocated 30%, preventing starvation of other queues.

Exam trap

Cisco often tests the misconception that 'priority percent' simply limits bandwidth like a policer, but the key trap is that it also provides strict priority queuing, which guarantees low latency for voice traffic, not just a bandwidth cap.

How to eliminate wrong answers

Option B is wrong because the priority percent command does not simply drop traffic that exceeds 30%; it polices the traffic, but during congestion, excess packets are dropped, while under no congestion, voice can burst above the percentage. Option C is wrong because the priority command creates a strict priority queue, not a weighted fair queue; weighted fair queueing uses weights for bandwidth allocation, not for priority queuing. Option D is wrong because the priority percent command does not re-mark packets; it only affects queuing and policing behavior, while marking is done by a separate 'set' command in a policy-map.

63
MCQhard

A network engineer is troubleshooting QoS on a Cisco Nexus 9000 switch. The switch is configured with a policy map that uses a class-default with a bandwidth remaining percent of 100. However, during congestion, traffic in a priority queue (class-map for EF) is experiencing drops even though the priority queue is not fully utilized. What is the most likely cause?

A.The priority queue is implicitly policed to a default rate on Nexus switches
B.The class-default bandwidth remaining percent should be set to 0
C.The priority queue is not configured with a queue-limit
D.The switch is using strict priority queuing without any shaping
AnswerA

On Cisco Nexus switches, the strict priority queue is not left uncapped; NX-OS implicitly applies a default policer to the priority queue (often the interface line rate or a platform-specific default) even when you do not configure a 'police' command. This policer uses a token bucket that drops traffic exceeding the allowed rate, so bursts of high-priority traffic can be dropped. The drops are therefore caused by policing, not by queuing or scheduling, which is why this is the correct diagnosis.

Why this answer

On Cisco Nexus 9000 switches, a priority queue (class-map for EF) is implicitly policed to a default rate of 1 Gbps (or the interface speed, whichever is lower) when no explicit policer is configured. This implicit policing can cause drops in the priority queue even if the queue itself is not fully utilized, because the policer rate limits the traffic before it enters the queue. The class-default bandwidth remaining percent of 100 is unrelated to this issue, as it only affects non-priority queues during congestion.

Exam trap

Cisco often tests the misconception that priority queue drops are always due to queue exhaustion or misconfigured bandwidth percentages, when in reality the implicit policer on Nexus platforms is the hidden cause.

How to eliminate wrong answers

Option B is wrong because setting class-default bandwidth remaining percent to 0 would starve all non-priority traffic, but it does not address the implicit policing of the priority queue. Option C is wrong because a queue-limit is not required for priority queues on Nexus switches; the default queue-limit is sufficient, and drops are caused by policing, not queue depth. Option D is wrong because strict priority queuing without shaping is the expected behavior for a priority queue, and it does not cause drops unless the policer rate is exceeded.

64
MCQhard

A network engineer runs the following command on Router R1: R1# show policy-map interface GigabitEthernet0/0 GigabitEthernet0/0 Service-policy input: QOS_POLICY Class-map: VOICE (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: ip dscp ef (46) Queueing queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 0/0 police cir 1000000 bc 31250 be 31250 conformed 0 bytes; actions: transmit exceeded 0 bytes; actions: drop violated 0 bytes; actions: drop Class-map: class-default (match-any) 100 packets, 12000 bytes 5 minute offered rate 8000 bps, drop rate 0 bps Match: any Queueing queue limit 64 packets (queue depth/total drops/no-buffer drops) 0/0/0 (pkts output/bytes output) 100/12000 Based on this output, what can be concluded?

A.The policy is applied in the output direction.
B.Voice traffic is being policed at 1 Mbps and any excess is dropped.
C.All traffic is being policed at 8 kbps.
D.The policy is shaping traffic to 1 Mbps.
AnswerB

The VOICE class is configured with the 'police' command using a CIR of 1,000,000 bps (1 Mbps). Both the exceed-action and violate-action are 'drop', so any traffic above the committed information rate is immediately discarded rather than remarked or re-queued. This makes the statement that voice traffic is policed at 1 Mbps with excess dropped accurate.

Why this answer

The output shows a police statement for the VOICE class with a CIR of 1,000,000 bps (1 Mbps) and actions to transmit conforming traffic while dropping exceeding and violating traffic. This confirms that voice traffic is being policed at 1 Mbps and any excess is dropped. The presence of policing (not shaping) and the input direction (Service-policy input) further support this conclusion.

Exam trap

Cisco often tests the distinction between policing and shaping, where candidates mistakenly interpret a police statement as shaping or assume the policy direction is output when the output clearly shows 'input'.

How to eliminate wrong answers

Option A is wrong because the command output explicitly states 'Service-policy input: QOS_POLICY', indicating the policy is applied in the input direction, not output. Option C is wrong because the policing is applied only to the VOICE class (match ip dscp ef), not to all traffic; the class-default shows no policing and only a queue limit. Option D is wrong because the configuration uses 'police' (policing), which drops excess traffic, not 'shape' (shaping), which buffers excess traffic; shaping would show a shape statement, not a police statement.

65
MCQhard

A network engineer is implementing QoS on a Cisco router that connects to a service provider. The provider uses MPLS and expects the MPLS EXP bits to be set for voice traffic. The engineer configures a policy-map that sets the MPLS EXP to 5. However, the provider reports that the EXP bits are not being set. What is the most likely reason?

A.The policy-map is applied to the incoming interface, but MPLS EXP marking must be done on the outgoing interface.
B.The router does not support setting MPLS EXP bits.
C.The MPLS EXP bits are set automatically based on the IP precedence.
D.The policy-map must use 'set mpls experimental imposition 5' instead of 'set mpls experimental 5'.
AnswerA

The correct issue is that the policy-map is applied to the incoming interface, but MPLS EXP marking must be performed on the outgoing interface. When a packet enters the MPLS domain, the label is not yet imposed on the inbound interface; the label push occurs during forwarding, and the MPLS encapsulation is added on the outgoing interface toward the next hop. Therefore, applying 'set mpls experimental 5' inbound cannot affect the EXP bits of a label that has not yet been created—marking must be configured on the outbound interface where the label exists.

Why this answer

The most likely reason is that the policy-map is applied to the incoming interface, but MPLS EXP marking must be applied on the outgoing interface. MPLS EXP bits are set at the imposition (ingress) of the MPLS label stack, which occurs when the packet is forwarded out of an interface that has MPLS enabled. If the policy-map is applied inbound, it marks the IP packet before MPLS encapsulation, and the EXP bits are not set on the MPLS label.

The correct approach is to apply the policy-map outbound on the interface facing the service provider, so that the 'set mpls experimental' command marks the EXP bits on the imposed label.

Exam trap

Cisco often tests the concept that MPLS EXP marking must be applied on the outgoing interface (where MPLS encapsulation occurs), not on the incoming interface, leading candidates to incorrectly assume that inbound marking is sufficient.

How to eliminate wrong answers

Option B is wrong because modern Cisco routers that support MPLS (e.g., ISR, ASR series) fully support setting MPLS EXP bits via policy-maps; this is a standard QoS feature. Option C is wrong because MPLS EXP bits are not automatically set based on IP precedence; they must be explicitly configured using a policy-map or can be copied from IP precedence if the 'mpls ip' command with 'mpls experimental' is configured, but this is not automatic and requires specific configuration. Option D is wrong because 'set mpls experimental 5' is the correct command for marking the EXP bits on the imposed label; 'set mpls experimental imposition 5' is not a valid Cisco IOS command.

66
MCQmedium

A network engineer is troubleshooting an issue where a Cisco router is not responding to SNMP polls from a network management station (NMS) at 192.168.1.50. The router has a CoPP policy that includes a class-map matching SNMP traffic (UDP port 161). The engineer checks the CoPP statistics and sees that SNMP packets from the NMS are being dropped. The engineer wants to allow SNMP from the NMS while still protecting the control plane. Which configuration change should the engineer make?

A.Modify the CoPP ACL to include a permit statement for UDP port 161 from host 192.168.1.50 before the deny statement.
B.Increase the police rate for the CoPP class that matches SNMP traffic.
C.Remove the CoPP policy from the control plane and rely on interface ACLs.
D.Change the SNMP port on the router to a non-standard port to avoid the CoPP policy.
AnswerA

The CoPP policy evaluates control-plane traffic using an ordered ACL; if the class-map references an ACL with a deny hit for the NMS's source, SNMP from 192.168.1.50 is not classified into the intended class and may fall through to a default drop action. Inserting a permit statement for UDP port 161 from that host before the existing deny entry ensures the class-map matches correctly, allowing the traffic to be policed under the appropriate CoPP class. This is the only option that directly fixes the selective source-based drop while preserving the security policy.

Why this answer

The CoPP policy is dropping SNMP packets from the NMS because the class-map matching SNMP traffic (UDP port 161) is applied without an exception for the specific management station. By modifying the ACL to include a permit statement for UDP port 161 from host 192.168.1.50 before the deny statement, the router will match and allow those packets before they hit the drop action, preserving control plane protection while permitting the NMS polls.

Exam trap

Cisco often tests the concept that CoPP ACLs are processed in order, and candidates may incorrectly assume that increasing the police rate or removing the policy entirely is the solution, rather than understanding that a specific permit entry for the trusted host must be placed before the deny statement.

How to eliminate wrong answers

Option B is wrong because increasing the police rate for the CoPP class would allow more SNMP traffic in general, but it would not selectively permit the NMS while still dropping other SNMP traffic; it would also reduce protection against SNMP-based DoS attacks. Option C is wrong because removing the CoPP policy entirely and relying on interface ACLs would leave the control plane unprotected against other types of control plane attacks, as interface ACLs do not provide the same granular rate-limiting and classification for control plane traffic. Option D is wrong because changing the SNMP port on the router to a non-standard port would require reconfiguring both the router and the NMS, and it would not bypass the CoPP policy unless the class-map is also updated; the CoPP policy matches UDP port 161, so a different port would not be matched and thus not dropped, but this is an impractical workaround that does not address the root cause.

67
MCQmedium

Examine the following CoPP configuration on a Cisco IOS-XE router: ``` class-map match-all CONTROL-PLANE match access-group name COPP-ACL ! policy-map COPP-POLICY class CONTROL-PLANE police 1000000 200000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP-POLICY ``` What is the effect of this configuration?

A.Traffic matching the ACL is rate-limited to 1 Mbps; traffic exceeding the rate is dropped.
B.All control plane traffic is rate-limited to 1 Mbps.
C.Traffic exceeding 1 Mbps is marked down but still transmitted.
D.The policy-map is applied to the data plane, not the control plane.
AnswerA

This answer is correct because the class-map references an access control list (ACL) that selects specific control-plane traffic, and the police command in the policy-map enforces a committed information rate (CIR) of 1 Mbps. When a packet matches the ACL, it is evaluated by the token bucket; conforming traffic is transmitted, while non-conforming (excess) traffic is dropped due to the configured exceed-action drop. This rate limiting is therefore applied narrowly to only the ACL-matched subset of control-plane traffic, not to all traffic or any other class.

Why this answer

The CoPP configuration uses a `police` command with a committed information rate (CIR) of 1,000,000 bits per second (1 Mbps) and a burst size of 200,000 bytes. Traffic that matches the class-map (via the named ACL) is subject to this policer; conforming traffic is transmitted, while exceeding traffic is dropped. This effectively rate-limits the matched control-plane traffic to 1 Mbps.

Exam trap

Cisco often tests the distinction between matching all control-plane traffic versus matching only traffic that hits a specific ACL, and candidates mistakenly assume the class-map applies to all control-plane traffic without reading the `match access-group` line.

How to eliminate wrong answers

Option B is wrong because the class-map uses `match-all CONTROL-PLANE` with an access-group named `COPP-ACL`, so only traffic matching that specific ACL is rate-limited, not all control-plane traffic. Option C is wrong because the `police` command specifies `conform-action transmit exceed-action drop`, meaning exceeding traffic is dropped, not marked down or transmitted. Option D is wrong because the `service-policy input COPP-POLICY` is applied under the `control-plane` configuration mode, which explicitly applies the policy to the control plane, not the data plane.

68
MCQhard

A network security engineer is configuring Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect the route processor from excessive traffic. The engineer wants to rate-limit SSH traffic to 100 kbps with a burst of 8000 bytes, and ensure that any traffic exceeding the rate is dropped. The engineer applies the following policy: policy-map COPP-POLICY class SSH-CLASS police 100000 8000 exceed-action drop After applying the service-policy to the control plane, the engineer notices that SSH sessions intermittently disconnect during large file transfers over SCP. What is the most likely cause?

A.Control Plane Policing does not support the exceed-action drop keyword; the correct action is transmit.
B.The service-policy must be applied to the control plane with the input keyword, otherwise SSH traffic is not policed.
C.The police rate is configured in kilobits per second, but the burst size is in kilobytes, causing a mismatch that drops all SSH packets.
D.The police rate is configured in bits per second, but the burst size is too small for SCP transfers, causing packets to be dropped.
AnswerD

The police command specifies the rate in bits per second (100000 bps = 100 kbps) and the burst in bytes (8000 bytes). During large SCP transfers, the burst of SSH packets can exceed 8000 bytes, causing the policer to drop packets and disconnect sessions. Increasing the burst size would allow more data before policing, resolving the intermittent drops.

Why this answer

The police command uses bits per second for the rate and bytes for the burst. A 100 kbps rate with an 8000-byte burst is too restrictive for SCP file transfers, which generate bursts of SSH packets larger than 8000 bytes. The policer drops excess packets, causing SSH sessions to disconnect intermittently.

Increasing the burst size or rate would resolve the problem.

Exam trap

The trap here is confusing the units of the police command, assuming the burst is in bits or kilobytes, when it is actually in bytes, leading to an undersized burst for the traffic profile.

Ready to test yourself?

Try a timed practice session using only Qos questions.