Courseiva
Infrastructure Security →hardMultiple Select

300-410 Infrastructure Security Practice Question

A network security engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS router to protect against denial-of-service attacks. The engineer wants to ensure that CoPP policies are applied correctly and that the router's control plane is protected. Which two statements about CoPP configuration are true? (Choose two.)

⚠ Common exam trap

The trap here is thinking that CoPP automatically drops all unmatched traffic, but actually it permits it unless a class-default with a police action is configured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CoPP can be configured to rate-limit specific types of traffic, such as OSPF and SSH, to protect the route processor.

CoPP uses the MQC framework to classify and police control plane traffic, allowing rate limiting of specific protocols like OSPF and SSH to protect the route processor. The policy is applied to the control plane, not globally or to the data plane. Unmatched traffic is not dropped by default; a class-default can be configured to manage it. Therefore, the true statements are that CoPP uses MQC with class maps and policy maps, and that it can rate-limit specific traffic types.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CoPP policies are applied globally to all interfaces using the service-policy command in global configuration mode.

    Why it's wrong here

    CoPP policies are not applied globally; they are applied to the control plane using the service-policy command within control-plane configuration mode. Applying a service-policy globally would affect all interfaces for data plane traffic, not the control plane. Therefore, this statement is incorrect.

  • ✗

    CoPP policies are applied to the data plane to filter transit traffic.

    Why it's wrong here

    CoPP is specifically designed to protect the control plane, not the data plane. Data plane traffic is typically filtered using interface ACLs or other QoS mechanisms. Applying CoPP to the data plane would not protect the route processor from control plane attacks. Thus, this statement is false.

  • ✓

    CoPP can be configured to rate-limit specific types of traffic, such as OSPF and SSH, to protect the route processor.

    Why this is correct

    CoPP allows the creation of class maps that match specific protocols or ports, such as OSPF or SSH, and policy maps that apply rate limiting (policing) to those classes. This protects the route processor from being overwhelmed by excessive control plane traffic. This statement is accurate.

  • ✓

    CoPP uses a modular QoS CLI (MQC) framework with class maps and policy maps to classify and police control plane traffic.

    Why this is correct

    CoPP leverages the MQC framework, where class maps define the traffic of interest (e.g., routing protocols, management traffic), and policy maps define the actions (e.g., policing). This structured approach allows granular control over control plane traffic. The policy map is then applied to the control plane. This statement is true.

  • ✗

    CoPP requires that all control plane traffic be explicitly permitted in a class map, otherwise it is dropped by default.

    Why it's wrong here

    CoPP does not drop all unmatched traffic by default. The default behavior for traffic not matching any class in the CoPP policy is to be permitted, unless a class-default with a police action is configured. However, best practice is to explicitly configure a class-default to handle unmatched traffic. Therefore, this statement is not true.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.