300-410 Infrastructure Security Practice Question
A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against DoS attacks. The engineer has created a class-map to match malicious traffic and a policy-map to police it. Which two statements are true regarding the application and behavior of CoPP? (Choose two.)
⚠ Common exam trap
The trap here is assuming CoPP can be applied to interfaces or that class-default must be policed, or misunderstanding the token bucket parameters and exceed-action behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CoPP uses a token bucket algorithm to enforce rate limits, where the first value is the committed information rate and the second is the burst size.
CoPP is applied to the control plane via the service-policy command under control-plane configuration mode, and it uses a token bucket algorithm with a committed information rate and burst size. The other statements are false: CoPP is not applied to interfaces, class-default does not require a police action, and the exceed-action determines the fate of excess traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CoPP automatically drops all traffic that exceeds the configured rate, regardless of the exceed-action specified in the policy.
Why it's wrong here
CoPP does not automatically drop all excess traffic; the action taken on packets that exceed the rate is defined by the exceed-action in the police command. Common actions include drop, transmit, or mark. The default exceed-action is drop, but it can be changed. Therefore, it is incorrect to say it always drops all excess traffic.
- ✗
The class-default class in a CoPP policy-map must always have a police action configured to drop all unmatched traffic.
Why it's wrong here
The class-default class does not require a police action. By default, unmatched traffic is transmitted without policing. Configuring a police action on class-default would restrict all other traffic, which may not be desired. It is a common practice to leave class-default unpoliced to allow legitimate traffic, or to configure a high policing rate if needed.
- ✓
CoPP uses a token bucket algorithm to enforce rate limits, where the first value is the committed information rate and the second is the burst size.
Why this is correct
CoPP, like other policing mechanisms, uses a token bucket algorithm. The police command specifies the committed information rate (CIR) and the burst size. The CIR is the average rate, and the burst size allows for temporary bursts above the CIR. Packets exceeding the burst are dropped or marked according to the exceed-action.
- ✓
CoPP policies are applied to the control plane using the service-policy command under the control-plane configuration mode.
Why this is correct
CoPP is applied globally to the control plane, not to individual interfaces. The service-policy command under control-plane configuration mode attaches the policy-map to the control plane, where it polices all traffic destined to the router's CPU. This is the correct application point for CoPP.
- ✗
CoPP can be applied to a specific interface to police traffic entering that interface before it reaches the control plane.
Why it's wrong here
CoPP is not applied to interfaces; it is applied to the control plane. Interface-level policing would affect all traffic, not just control plane traffic. CoPP specifically targets traffic destined to the router itself, and it is applied under the control-plane configuration. Applying a policy-map to an interface would police transit traffic as well, which is not the purpose of CoPP.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.