Courseiva
Infrastructure Security →hardMultiple Select

300-410 Infrastructure Security Practice Question

A network administrator is deploying Control Plane Policing (CoPP) on a Cisco IOS-XE router to protect the route processor from excessive traffic. The administrator creates a class-map to match all management traffic (SSH, SNMP, TACACS+) and a policy-map to police that traffic to 1 Mbps. After applying the service-policy to the control-plane, the administrator notices that some legitimate SNMP polling is being dropped. Which two actions can the administrator take to resolve this issue while maintaining protection against DoS attacks? (Choose two.)

⚠ Common exam trap

The trap here is thinking that any change to CoPP must involve removing or disabling policing to stop drops.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase the police rate for the management class to accommodate the SNMP polling volume.

The legitimate SNMP polling is being dropped because the policer rate is too low for the combined management traffic. Increasing the overall rate or creating a separate class with a higher rate for SNMP will allow legitimate traffic while still policing excess. Both actions maintain protection against DoS by keeping policing in place.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Increase the police rate for the management class to accommodate the SNMP polling volume.

    Why this is correct

    Increasing the policer rate allows more management traffic to pass while still enforcing a limit, providing protection against excessive traffic. This is a valid tuning step when legitimate traffic exceeds the configured rate. It maintains CoPP's protective function while reducing false positives. This action directly addresses the drops without disabling protection.

  • ✗

    Remove the police action and use a bandwidth guarantee instead.

    Why it's wrong here

    Using a bandwidth guarantee (e.g., priority or bandwidth) does not provide the same DoS protection as policing. CoPP is designed to police (drop) excess traffic, not to guarantee bandwidth. Removing policing would leave the control plane vulnerable to attack. This action would not maintain protection against DoS.

  • ✗

    Apply the service-policy to the data plane interfaces instead of the control plane.

    Why it's wrong here

    Applying CoPP to data plane interfaces would not protect the route processor from control plane traffic. CoPP must be applied to the control plane to filter traffic destined to the router's CPU. This action would not address the SNMP drops and would leave the control plane unprotected.

  • ✗

    Enable SNMPv3 authentication to reduce the volume of SNMP traffic.

    Why it's wrong here

    SNMPv3 authentication adds security but does not reduce the volume of polling requests. It would not resolve drops caused by rate limiting. While it is a good security practice, it does not address the policer configuration issue. The drops are due to rate limiting, not authentication.

  • ✓

    Configure a separate class-map for SNMP and assign a higher police rate to that class.

    Why this is correct

    Creating a separate class for SNMP allows granular policing, so SNMP traffic can have a higher rate limit while other management traffic remains tightly policed. This maintains overall protection and resolves the drops for SNMP. It is a best practice to separate critical protocols into their own classes for fine-tuned control.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.