Courseiva
Security →hardMultiple Select

CCNP Security Practice Question

A security team is hardening a Cisco IOS router that terminates IPsec site-to-site tunnels to several branch offices. The team wants to protect the control plane by rate-limiting and filtering traffic destined to the router's own CPU. Which two mechanisms are designed specifically for control plane protection on Cisco IOS? (Choose two.)

⚠ Common exam trap

Candidates often confuse data plane security features like MACsec and ZBFW with control plane protection mechanisms, even though only CoPP and CPPr police traffic destined to the route processor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Control Plane Policing (CoPP)

Control plane protection on Cisco IOS is provided by CoPP, which uses MQC policies on the control-plane interface, and CPPr, which adds subinterface granularity for host, transit, and CEF-exception traffic. Both are purpose-built to classify and rate-limit traffic destined to the route processor. Data plane mechanisms such as MACsec and ZBFW, and tunneling architectures such as DMVPN, do not protect the CPU from control plane floods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Control Plane Policing (CoPP)

    Why this is correct

    CoPP uses a modular QoS CLI policy attached to the control-plane interface to rate-limit and classify traffic destined to the route processor. It allows the engineer to define class maps for protocols such as IKE, SSH, and SNMP, then apply policing actions so that a flood of tunnel negotiation packets cannot exhaust CPU resources. This directly addresses the hardening goal for the IPsec headend by protecting the control plane from abusive traffic.

  • ✗

    MACsec on the WAN interface

    Why it's wrong here

    MACsec provides Layer 2 hop-by-hop encryption and integrity on Ethernet links, typically between switches or between a router and a switch. It does not rate-limit or classify traffic destined to the router's CPU, so it cannot protect the control plane from a flood of IKE or SSH packets. MACsec is a data confidentiality mechanism, not a control plane policing mechanism, and it is irrelevant to the CPU protection goal in this scenario.

  • ✗

    Zone-Based Policy Firewall (ZBFW)

    Why it's wrong here

    ZBFW applies stateful inspection policies between security zones for transit traffic, controlling what flows from one zone to another. While it can drop unwanted traffic, it is not designed to rate-limit traffic destined to the router's own control plane and does not offer the granular per-protocol policing that CoPP and CPPr provide. Using ZBFW alone would not prevent a CPU-exhausting flood of IKE packets aimed at the router itself.

  • ✓

    Control Plane Protection (CPPr)

    Why this is correct

    CPPr extends CoPP by dividing the control plane into subinterfaces such as host, transit, and CEF-exception, allowing more granular policies for traffic destined to the router itself versus traffic being forwarded. For an IPsec headend, CPPr can police IKE and ISAKMP traffic specifically while leaving transit traffic untouched. It is a Cisco IOS feature purpose-built for protecting the route processor from control plane overload.

  • ✗

    IPsec DMVPN with IKEv2

    Why it's wrong here

    DMVPN with IKEv2 is a tunneling and encryption architecture for building scalable hub-and-spoke or partial-mesh VPNs. It secures data in transit but does not include a mechanism to police or rate-limit control plane traffic destined to the route processor. An attacker can still flood the router with IKE negotiation attempts, so DMVPN does not fulfill the control plane protection requirement described in the scenario.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.