300-410 Infrastructure Security Practice Question
A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect the route processor from excessive traffic. The engineer wants to limit ICMP echo requests destined to the router to 100 packets per second, while allowing other traffic. Which configuration snippet correctly applies CoPP for this purpose?
⚠ Common exam trap
The trap here is applying the CoPP policy to an interface instead of the control plane, which would not protect the route processor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
access-list 101 permit icmp any any echo class-map match-any ICMP match access-group 101 policy-map CoPP class ICMP police 100 conform-action transmit exceed-action drop control-plane service-policy input CoPP
CoPP is implemented by defining a class-map to match traffic, a policy-map to police it, and then applying the policy-map to the control plane with 'service-policy input' under the 'control-plane' configuration mode. The correct snippet uses an ACL to match ICMP echo requests, polices them at 100 pps, and applies the policy to the control plane. This protects the route processor from excessive ICMP traffic while allowing other traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
class-map match-any ICMP match access-group 101 policy-map CoPP class ICMP police 100 conform-action transmit exceed-action drop interface GigabitEthernet0/0 service-policy input CoPP
Why it's wrong here
This configuration applies the policy map directly to the interface with 'service-policy input', which is incorrect for CoPP. CoPP requires the policy to be applied globally to the control plane using 'service-policy input CoPP' under 'control-plane' configuration mode. Applying it to an interface would police all input traffic on that interface, not specifically control plane traffic.
- ✗
access-list 101 permit icmp any any echo class-map match-any ICMP match access-group 101 policy-map CoPP class ICMP police 100 conform-action transmit exceed-action drop interface GigabitEthernet0/0 service-policy output CoPP
Why it's wrong here
Applying the policy map as an output service policy on an interface does not affect traffic destined to the router's control plane. CoPP must be applied to the control plane itself. Output policing would only affect traffic leaving the interface, not incoming control plane traffic. Therefore, this configuration does not achieve the goal.
- ✓
access-list 101 permit icmp any any echo class-map match-any ICMP match access-group 101 policy-map CoPP class ICMP police 100 conform-action transmit exceed-action drop control-plane service-policy input CoPP
Why this is correct
This configuration correctly defines an ACL to match ICMP echo requests, uses a class-map to reference the ACL, creates a policy-map to police the matched traffic at 100 pps, and applies the policy map to the control plane with 'service-policy input CoPP' under 'control-plane' mode. This is the proper way to implement CoPP.
- ✗
access-list 101 permit icmp any any echo class-map match-any ICMP match access-group 101 policy-map CoPP class ICMP police 100 conform-action transmit exceed-action drop control-plane service-policy output CoPP
Why it's wrong here
The 'control-plane' configuration mode accepts only 'service-policy input', not 'output'. CoPP is always applied to ingress control plane traffic. Using 'output' under control-plane is invalid syntax and would be rejected by the router. Thus, this configuration is incorrect and would not function.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.