CCNP Security Practice Question
A network security team is hardening a Cisco IOS-XE router that terminates IPsec VPN tunnels. They want to protect the control plane from CPU-intensive IKE and management traffic without dropping legitimate tunnel establishment packets. They decide to apply a Control Plane Policing (CoPP) policy. Which statement best describes how CoPP interacts with the forwarding plane and the control plane on this router?
⚠ Common exam trap
The trap here is assuming CoPP is an interface-level QoS policy that filters transit traffic instead of a control-plane host-path policer targeting only packets destined to the route processor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CoPP uses MQC to classify traffic destined to the route processor and applies a policer in the control-plane host path, so it can rate-limit IKE and SSH without affecting transit traffic that is forwarded in hardware.
CoPP applies MQC classification and policing to packets destined for the route processor via the control-plane host path, protecting the CPU from floods of IKE, SSH, or SNMP without touching hardware-forwarded transit traffic. It is configured once under 'control-plane', not per interface, and does not require distributed CEF or NBAR2 to match common control-plane protocols.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CoPP can only classify traffic using NBAR2 deep packet inspection, so it cannot match IKE or SSH and requires a separate Zone-Based Firewall policy to protect the control plane.
Why it's wrong here
CoPP classification uses standard MQC match criteria such as ACLs, DSCP, and protocol port numbers, and it can absolutely match IKE (UDP 500/4500) and SSH (TCP 22). NBAR2 is not required, and Zone-Based Firewall is a separate technology for transit traffic inspection. This option incorrectly limits CoPP's classification capabilities and conflates two distinct features.
- ✓
CoPP uses MQC to classify traffic destined to the route processor and applies a policer in the control-plane host path, so it can rate-limit IKE and SSH without affecting transit traffic that is forwarded in hardware.
Why this is correct
CoPP leverages Modular QoS CLI to classify packets punted to the route processor, including IKE, SSH, and SNMP, and polices them in a dedicated control-plane host path. Because the policy is applied with 'service-policy input' under 'control-plane', it only affects traffic destined to the device itself, leaving hardware-forwarded transit traffic untouched. This matches the requirement to protect the CPU while preserving legitimate tunnel establishment.
- ✗
CoPP requires enabling 'ip cef distributed' and a PFC on the supervisor to offload policed control traffic to hardware, otherwise it cannot rate-limit IKE packets.
Why it's wrong here
CoPP operates in the control-plane host path on the route processor and does not depend on distributed CEF or a PFC to police control traffic. While PFCs handle certain ACL and QoS offloads in the data plane, they are not prerequisites for CoPP. The claim that IKE packets cannot be policed without these features is incorrect for IOS-XE routers.
- ✗
CoPP classifies and polices all packets entering any interface, including transit traffic, so it must be applied with 'service-policy input' on every physical interface to be effective.
Why it's wrong here
This describes interface-level QoS policing, not CoPP. CoPP is applied once under the 'control-plane' configuration stanza, not per physical interface, and it targets only traffic punted to the route processor. Applying a policer on every interface would affect transit traffic and is unnecessary for CPU protection, so this approach mischaracterizes how CoPP actually functions on IOS-XE.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.