Courseiva
Infrastructure Security →mediumMultiple Choice

300-410 Infrastructure Security Practice Question

A network administrator is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against DoS attacks. The administrator wants to rate-limit ARP traffic destined to the route processor. Which configuration correctly applies a CoPP policy to ARP traffic?

⚠ Common exam trap

The trap here is applying the CoPP policy to a physical interface instead of the control plane.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY

Control Plane Policing (CoPP) is configured by defining class-maps to match traffic, policy-maps to define actions, and then attaching the policy to the control plane using the 'control-plane' global configuration mode with 'service-policy input'. The class-map must match ARP traffic using 'match protocol arp'. This setup rate-limits ARP packets destined to the route processor, protecting it from DoS attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! interface Control-Plane service-policy input COPP_POLICY

    Why it's wrong here

    The 'interface Control-Plane' command is not valid in Cisco IOS. The correct method is to use the global 'control-plane' configuration mode and then apply the service-policy under that. This option would result in a syntax error and the policy would not be applied.

  • ✗

    class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! control-plane host service-policy input COPP_POLICY

    Why it's wrong here

    The 'control-plane host' subcommand is used to apply policies to host-bound traffic, but it is not the standard way to apply CoPP for all control plane traffic. The correct command is 'control-plane' without the 'host' keyword for global control plane policing. Using 'control-plane host' may limit the policy to specific host traffic, not all ARP traffic destined to the route processor.

  • ✓

    class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY

    Why this is correct

    This configuration defines a class-map that matches ARP protocol traffic, a policy-map that applies policing to that class, and then attaches the policy to the control-plane interface using 'service-policy input'. The 'match protocol arp' command is valid for classifying ARP packets. This correctly implements CoPP for ARP.

  • ✗

    class-map match-all ARP_CLASS match access-group name ARP_ACL ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! interface GigabitEthernet0/0 service-policy input COPP_POLICY

    Why it's wrong here

    This configuration applies the policy to a physical interface, not the control plane. CoPP is applied to the control plane using the 'control-plane' configuration mode. Applying it to an interface would filter transit traffic, not traffic destined to the route processor. Therefore, it does not protect the control plane as intended.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.