CCNP Security Practice Question
A security team is hardening a Cisco IOS router that terminates IPsec site-to-site tunnels to several branch offices. The team wants to protect the control plane by rate-limiting and filtering traffic destined to the router's own CPU. Which two mechanisms are designed specifically for control plane protection on Cisco IOS? (Choose two.)
⚠ Common exam trap
Candidates often confuse data plane security features like MACsec and ZBFW with control plane protection mechanisms, even though only CoPP and CPPr police traffic destined to the route processor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Control Plane Policing (CoPP)
Control plane protection on Cisco IOS is provided by CoPP, which uses MQC policies on the control-plane interface, and CPPr, which adds subinterface granularity for host, transit, and CEF-exception traffic. Both are purpose-built to classify and rate-limit traffic destined to the route processor. Data plane mechanisms such as MACsec and ZBFW, and tunneling architectures such as DMVPN, do not protect the CPU from control plane floods.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Control Plane Policing (CoPP)
Why this is correct
CoPP uses a modular QoS CLI policy attached to the control-plane interface to rate-limit and classify traffic destined to the route processor. It allows the engineer to define class maps for protocols such as IKE, SSH, and SNMP, then apply policing actions so that a flood of tunnel negotiation packets cannot exhaust CPU resources. This directly addresses the hardening goal for the IPsec headend by protecting the control plane from abusive traffic.
- ✗
MACsec on the WAN interface
Why it's wrong here
MACsec provides Layer 2 hop-by-hop encryption and integrity on Ethernet links, typically between switches or between a router and a switch. It does not rate-limit or classify traffic destined to the router's CPU, so it cannot protect the control plane from a flood of IKE or SSH packets. MACsec is a data confidentiality mechanism, not a control plane policing mechanism, and it is irrelevant to the CPU protection goal in this scenario.
- ✗
Zone-Based Policy Firewall (ZBFW)
Why it's wrong here
ZBFW applies stateful inspection policies between security zones for transit traffic, controlling what flows from one zone to another. While it can drop unwanted traffic, it is not designed to rate-limit traffic destined to the router's own control plane and does not offer the granular per-protocol policing that CoPP and CPPr provide. Using ZBFW alone would not prevent a CPU-exhausting flood of IKE packets aimed at the router itself.
- ✓
Control Plane Protection (CPPr)
Why this is correct
CPPr extends CoPP by dividing the control plane into subinterfaces such as host, transit, and CEF-exception, allowing more granular policies for traffic destined to the router itself versus traffic being forwarded. For an IPsec headend, CPPr can police IKE and ISAKMP traffic specifically while leaving transit traffic untouched. It is a Cisco IOS feature purpose-built for protecting the route processor from control plane overload.
- ✗
IPsec DMVPN with IKEv2
Why it's wrong here
DMVPN with IKEv2 is a tunneling and encryption architecture for building scalable hub-and-spoke or partial-mesh VPNs. It secures data in transit but does not include a mechanism to police or rate-limit control plane traffic destined to the route processor. An attacker can still flood the router with IKE negotiation attempts, so DMVPN does not fulfill the control plane protection requirement described in the scenario.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.