300-410 Infrastructure Security Practice Question
A network security engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS router to protect against denial-of-service attacks. The engineer wants to ensure that CoPP policies are applied correctly and that the router's control plane is protected. Which two statements about CoPP configuration are true? (Choose two.)
⚠ Common exam trap
The trap here is thinking that CoPP automatically drops all unmatched traffic, but actually it permits it unless a class-default with a police action is configured.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CoPP can be configured to rate-limit specific types of traffic, such as OSPF and SSH, to protect the route processor.
CoPP uses the MQC framework to classify and police control plane traffic, allowing rate limiting of specific protocols like OSPF and SSH to protect the route processor. The policy is applied to the control plane, not globally or to the data plane. Unmatched traffic is not dropped by default; a class-default can be configured to manage it. Therefore, the true statements are that CoPP uses MQC with class maps and policy maps, and that it can rate-limit specific traffic types.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
CoPP policies are applied globally to all interfaces using the service-policy command in global configuration mode.
Why it's wrong here
CoPP policies are not applied globally; they are applied to the control plane using the service-policy command within control-plane configuration mode. Applying a service-policy globally would affect all interfaces for data plane traffic, not the control plane. Therefore, this statement is incorrect.
- ✗
CoPP policies are applied to the data plane to filter transit traffic.
Why it's wrong here
CoPP is specifically designed to protect the control plane, not the data plane. Data plane traffic is typically filtered using interface ACLs or other QoS mechanisms. Applying CoPP to the data plane would not protect the route processor from control plane attacks. Thus, this statement is false.
- ✓
CoPP can be configured to rate-limit specific types of traffic, such as OSPF and SSH, to protect the route processor.
Why this is correct
CoPP allows the creation of class maps that match specific protocols or ports, such as OSPF or SSH, and policy maps that apply rate limiting (policing) to those classes. This protects the route processor from being overwhelmed by excessive control plane traffic. This statement is accurate.
- ✓
CoPP uses a modular QoS CLI (MQC) framework with class maps and policy maps to classify and police control plane traffic.
Why this is correct
CoPP leverages the MQC framework, where class maps define the traffic of interest (e.g., routing protocols, management traffic), and policy maps define the actions (e.g., policing). This structured approach allows granular control over control plane traffic. The policy map is then applied to the control plane. This statement is true.
- ✗
CoPP requires that all control plane traffic be explicitly permitted in a class map, otherwise it is dropped by default.
Why it's wrong here
CoPP does not drop all unmatched traffic by default. The default behavior for traffic not matching any class in the CoPP policy is to be permitted, unless a class-default with a police action is configured. However, best practice is to explicitly configure a class-default to handle unmatched traffic. Therefore, this statement is not true.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.