CCNP Security Practice Question
A security engineer is configuring CoPP (Control Plane Policing) on a Cisco router to protect the control plane from DoS attacks. The policy must rate-limit SSH traffic to 1 Mbps with a burst of 2000 bytes, and drop all other traffic destined to the control plane that exceeds a default rate. Which class-map and policy-map configuration is correct?
⚠ Common exam trap
Cisco often tests the requirement for a class-default policy in CoPP to drop all other traffic, and the trap here is that candidates may forget that without it, unmatched traffic is permitted by default, or they may confuse the order of police parameters (rate vs. burst).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
class-map match-all SSH match protocol ssh policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop class class-default police 8000 conform-action transmit exceed-action drop
It uses the 'match protocol ssh' class-map to identify SSH traffic, applies a police rate of 1,000,000 bps (1 Mbps) with a burst of 2000 bytes, and includes a class-default with a police rate of 8000 bps to drop all other control-plane traffic exceeding a default rate. This matches the requirement to rate-limit SSH and drop other traffic that exceeds a default rate, which is a common CoPP best practice to protect the control plane.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
class-map match-all SSH match protocol ssh policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop
Why it's wrong here
This configuration correctly matches SSH using `match protocol ssh`, but it omits a `class-default` definition. Without `class-default`, all non-SSH control-plane traffic (e.g., ARP, OSPF, BGP, ICMP) is implicitly forwarded to the CPU with no policing, leaving the control plane unprotected. A complete CoPP policy must include a `class-default` to apply a baseline police rate to all unclassified traffic.
- ✗
class-map match-all SSH match access-group name SSH_ACL policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop class class-default police 8000 conform-action transmit exceed-action drop
Why it's wrong here
Using an `access-group` for classification is valid in CoPP, but this configuration references a named ACL `SSH_ACL` that is not defined anywhere in the snippet, making the class-map effectively non-functional until the ACL is created. Additionally, matching by protocol (`match protocol ssh`) is simpler and does not rely on ACL semantics or ordering. Although `class-default` with a police rate is present, the incomplete ACL dependency and the less direct classification method make this option incorrect.
- ✓
class-map match-all SSH match protocol ssh policy-map COPP class SSH police 1000000 2000 conform-action transmit exceed-action drop class class-default police 8000 conform-action transmit exceed-action drop
Why this is correct
This is the correct CoPP configuration: `class-map match-all SSH` with `match protocol ssh` classifies SSH control-plane traffic, and the policy map `COPP` applies a police rate of 1,000,000 bps with a burst of 2000 bytes, dropping exceeding traffic. The `class-default` then polices all other control-plane traffic at 8000 bps, ensuring that no unclassified protocol can flood the CPU. The syntax and parameters are correctly ordered (rate in bps, burst in bytes), providing comprehensive control-plane protection.
- ✗
class-map match-all SSH match protocol ssh policy-map COPP class SSH police 2000 1000000 conform-action transmit exceed-action drop
Why it's wrong here
The police command parameters are swapped: `police 2000 1000000` sets the rate to 2000 bps and the burst to 1,000,000 bytes, the exact inverse of the intended configuration. This would rate-limit SSH to an unusably low speed while allowing an enormous burst, defeating the purpose of CoPP. Correct syntax should be `police 1000000 2000`, where the first value is the committed information rate in bits per second and the second is the burst size in bytes.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.