300-410 Infrastructure Security Practice Question
A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against DoS attacks. The engineer wants to rate-limit ARP packets destined to the route processor to 1000 packets per second, with a burst of 2000 packets. Which CoPP policy configuration accomplishes this?
⚠ Common exam trap
The trap here is applying the CoPP service policy to an interface instead of the control plane, or using the wrong direction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
class-map match-all ARP-CLASS match protocol arp policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop control-plane service-policy input COPP-POLICY
The correct configuration uses a class-map with 'match protocol arp', a policy-map with 'police 1000 2000', and applies the policy to the control plane with 'service-policy input COPP-POLICY'. This effectively rate-limits ARP packets destined to the route processor. The other options misapply the service policy to an interface, use an invalid access list for ARP, or apply it in the wrong direction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
class-map match-all ARP-CLASS match protocol arp policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop control-plane service-policy input COPP-POLICY
Why this is correct
This configuration correctly defines a class-map to match ARP protocol, a policy-map to police ARP traffic at 1000 pps with a burst of 2000, and applies it to the control plane using 'service-policy input' under 'control-plane' mode. This is the standard CoPP implementation to protect the route processor.
- ✗
class-map match-all ARP-CLASS match protocol arp policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop interface GigabitEthernet0/0 service-policy input COPP-POLICY
Why it's wrong here
This configuration applies the service policy to the interface, which is incorrect for CoPP. CoPP requires the policy to be applied to the control plane using the 'service-policy input' command under 'control-plane' configuration mode. Applying it to an interface would police traffic entering that interface, not traffic destined to the route processor.
- ✗
class-map match-all ARP-CLASS match access-group 101 access-list 101 permit arp any any policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop control-plane service-policy input COPP-POLICY
Why it's wrong here
This configuration attempts to match ARP using an access list, but access lists cannot match ARP protocol directly. ARP is a Layer 2 protocol and is not matched by IP access lists. The correct method is to use 'match protocol arp' in the class-map. Therefore, this configuration will not match ARP packets.
- ✗
class-map match-any ARP-CLASS match protocol arp policy-map COPP-POLICY class ARP-CLASS police 1000 2000 conform-action transmit exceed-action drop control-plane service-policy output COPP-POLICY
Why it's wrong here
This configuration applies the service policy in the output direction on the control plane. CoPP typically polices traffic that is destined to the route processor (input direction). Using 'output' would police traffic originating from the control plane, which is not the goal. The correct direction is 'input'.
Visual reference
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.