Courseiva
Infrastructure Security →hardMultiple Choice

300-410 Infrastructure Security Practice Question

A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against DoS attacks. The engineer wants to rate-limit ARP packets destined to the route processor to 1000 packets per second, with a burst of 2000 packets. Which CoPP policy configuration accomplishes this?

⚠ Common exam trap

The trap here is applying the CoPP service policy to an interface instead of the control plane, or using the wrong direction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

class-map match-all ARP-CLASS match protocol arp policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop control-plane service-policy input COPP-POLICY

The correct configuration uses a class-map with 'match protocol arp', a policy-map with 'police 1000 2000', and applies the policy to the control plane with 'service-policy input COPP-POLICY'. This effectively rate-limits ARP packets destined to the route processor. The other options misapply the service policy to an interface, use an invalid access list for ARP, or apply it in the wrong direction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    class-map match-all ARP-CLASS match protocol arp policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop control-plane service-policy input COPP-POLICY

    Why this is correct

    This configuration correctly defines a class-map to match ARP protocol, a policy-map to police ARP traffic at 1000 pps with a burst of 2000, and applies it to the control plane using 'service-policy input' under 'control-plane' mode. This is the standard CoPP implementation to protect the route processor.

  • ✗

    class-map match-all ARP-CLASS match protocol arp policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop interface GigabitEthernet0/0 service-policy input COPP-POLICY

    Why it's wrong here

    This configuration applies the service policy to the interface, which is incorrect for CoPP. CoPP requires the policy to be applied to the control plane using the 'service-policy input' command under 'control-plane' configuration mode. Applying it to an interface would police traffic entering that interface, not traffic destined to the route processor.

  • ✗

    class-map match-all ARP-CLASS match access-group 101 access-list 101 permit arp any any policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop control-plane service-policy input COPP-POLICY

    Why it's wrong here

    This configuration attempts to match ARP using an access list, but access lists cannot match ARP protocol directly. ARP is a Layer 2 protocol and is not matched by IP access lists. The correct method is to use 'match protocol arp' in the class-map. Therefore, this configuration will not match ARP packets.

  • ✗

    class-map match-any ARP-CLASS match protocol arp policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop control-plane service-policy output COPP-POLICY

    Why it's wrong here

    This configuration applies the service policy in the output direction on the control plane. CoPP typically polices traffic that is destined to the route processor (input direction). Using 'output' would police traffic originating from the control plane, which is not the goal. The correct direction is 'input'.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.