300-410 Infrastructure Security Practice Question
A network administrator is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against DoS attacks. The administrator wants to rate-limit ARP traffic destined to the route processor. Which configuration correctly applies a CoPP policy to ARP traffic?
⚠ Common exam trap
The trap here is applying the CoPP policy to a physical interface instead of the control plane.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY
Control Plane Policing (CoPP) is configured by defining class-maps to match traffic, policy-maps to define actions, and then attaching the policy to the control plane using the 'control-plane' global configuration mode with 'service-policy input'. The class-map must match ARP traffic using 'match protocol arp'. This setup rate-limits ARP packets destined to the route processor, protecting it from DoS attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! interface Control-Plane service-policy input COPP_POLICY
Why it's wrong here
The 'interface Control-Plane' command is not valid in Cisco IOS. The correct method is to use the global 'control-plane' configuration mode and then apply the service-policy under that. This option would result in a syntax error and the policy would not be applied.
- ✗
class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! control-plane host service-policy input COPP_POLICY
Why it's wrong here
The 'control-plane host' subcommand is used to apply policies to host-bound traffic, but it is not the standard way to apply CoPP for all control plane traffic. The correct command is 'control-plane' without the 'host' keyword for global control plane policing. Using 'control-plane host' may limit the policy to specific host traffic, not all ARP traffic destined to the route processor.
- ✓
class-map match-all ARP_CLASS match protocol arp ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP_POLICY
Why this is correct
This configuration defines a class-map that matches ARP protocol traffic, a policy-map that applies policing to that class, and then attaches the policy to the control-plane interface using 'service-policy input'. The 'match protocol arp' command is valid for classifying ARP packets. This correctly implements CoPP for ARP.
- ✗
class-map match-all ARP_CLASS match access-group name ARP_ACL ! policy-map COPP_POLICY class ARP_CLASS police 8000 conform-action transmit exceed-action drop ! interface GigabitEthernet0/0 service-policy input COPP_POLICY
Why it's wrong here
This configuration applies the policy to a physical interface, not the control plane. CoPP is applied to the control plane using the 'control-plane' configuration mode. Applying it to an interface would filter transit traffic, not traffic destined to the route processor. Therefore, it does not protect the control plane as intended.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.