CCNP Security Practice Question
A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect the route processor from excessive SSH traffic. The engineer wants to classify SSH traffic destined to the router itself and apply a policer to it. Which mechanism is used by CoPP to classify traffic before the policer is applied?
⚠ Common exam trap
It's easy for candidates to confuse VTY access-class filtering with CoPP policing; access-class restricts who can connect, while CoPP actually rate-limits traffic destined to the route processor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Class maps that match on the control-plane interface and access control lists
CoPP is built on the modular QoS CLI, where class maps identify control-plane traffic using the control-plane keyword combined with ACLs or protocol matches. A policy map then applies a policer to those classes, and the policy is attached to the control plane with service-policy. This layered approach lets administrators rate-limit SSH and other punted traffic without affecting transit forwarding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Class maps that match on the control-plane interface and access control lists
Why this is correct
CoPP uses a modular QoS CLI structure in which class maps match traffic destined to the control plane. Matching combines the control-plane keyword with ACLs, protocol keywords, or NBAR to identify specific flows such as SSH. The matched traffic is then referenced by a policy map that applies a policer, which is attached to the control plane with the service-policy command.
- ✗
Policy maps that match on the ingress data-plane interface
Why it's wrong here
Policy maps are applied after classification, not used to classify traffic. Matching on an ingress data-plane interface would affect transit traffic rather than traffic destined to the router's own control plane, so it would not protect the route processor. CoPP specifically requires the control-plane keyword in the class map to select traffic punted to the CPU for local processing.
- ✗
Route maps that match on the management VRF and next-hop address
Why it's wrong here
Route maps are used for route redistribution, policy-based routing, and BGP attribute manipulation, not for CoPP classification. They operate on routing information rather than packets destined to the route processor, so they cannot select SSH traffic for policing. Using a route map here would not affect the control plane and would leave the router's SSH process unprotected from excessive session attempts.
- ✗
ACLs applied directly to the VTY lines with the access-class command
Why it's wrong here
The access-class command on VTY lines filters which remote addresses may establish SSH or Telnet sessions, but it does not rate-limit traffic or protect the control plane from a flood of connection attempts. It is an access control mechanism, not a policing mechanism, and it does not integrate with the modular QoS CLI used by CoPP. It also cannot classify traffic for a policer.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.