Courseiva
Security →hardMultiple Choice

CCNP Security Practice Question

A network security team is hardening a Cisco IOS-XE router that terminates IPsec VPN tunnels. They want to protect the control plane from CPU-intensive IKE and management traffic without dropping legitimate tunnel establishment packets. They decide to apply a Control Plane Policing (CoPP) policy. Which statement best describes how CoPP interacts with the forwarding plane and the control plane on this router?

⚠ Common exam trap

The trap here is assuming CoPP is an interface-level QoS policy that filters transit traffic instead of a control-plane host-path policer targeting only packets destined to the route processor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CoPP uses MQC to classify traffic destined to the route processor and applies a policer in the control-plane host path, so it can rate-limit IKE and SSH without affecting transit traffic that is forwarded in hardware.

CoPP applies MQC classification and policing to packets destined for the route processor via the control-plane host path, protecting the CPU from floods of IKE, SSH, or SNMP without touching hardware-forwarded transit traffic. It is configured once under 'control-plane', not per interface, and does not require distributed CEF or NBAR2 to match common control-plane protocols.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CoPP can only classify traffic using NBAR2 deep packet inspection, so it cannot match IKE or SSH and requires a separate Zone-Based Firewall policy to protect the control plane.

    Why it's wrong here

    CoPP classification uses standard MQC match criteria such as ACLs, DSCP, and protocol port numbers, and it can absolutely match IKE (UDP 500/4500) and SSH (TCP 22). NBAR2 is not required, and Zone-Based Firewall is a separate technology for transit traffic inspection. This option incorrectly limits CoPP's classification capabilities and conflates two distinct features.

  • ✓

    CoPP uses MQC to classify traffic destined to the route processor and applies a policer in the control-plane host path, so it can rate-limit IKE and SSH without affecting transit traffic that is forwarded in hardware.

    Why this is correct

    CoPP leverages Modular QoS CLI to classify packets punted to the route processor, including IKE, SSH, and SNMP, and polices them in a dedicated control-plane host path. Because the policy is applied with 'service-policy input' under 'control-plane', it only affects traffic destined to the device itself, leaving hardware-forwarded transit traffic untouched. This matches the requirement to protect the CPU while preserving legitimate tunnel establishment.

  • ✗

    CoPP requires enabling 'ip cef distributed' and a PFC on the supervisor to offload policed control traffic to hardware, otherwise it cannot rate-limit IKE packets.

    Why it's wrong here

    CoPP operates in the control-plane host path on the route processor and does not depend on distributed CEF or a PFC to police control traffic. While PFCs handle certain ACL and QoS offloads in the data plane, they are not prerequisites for CoPP. The claim that IKE packets cannot be policed without these features is incorrect for IOS-XE routers.

  • ✗

    CoPP classifies and polices all packets entering any interface, including transit traffic, so it must be applied with 'service-policy input' on every physical interface to be effective.

    Why it's wrong here

    This describes interface-level QoS policing, not CoPP. CoPP is applied once under the 'control-plane' configuration stanza, not per physical interface, and it targets only traffic punted to the route processor. Applying a policer on every interface would affect transit traffic and is unnecessary for CPU protection, so this approach mischaracterizes how CoPP actually functions on IOS-XE.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.