Courseiva
Infrastructure Security →mediumMultiple Select

300-410 Infrastructure Security Practice Question

A network security engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS router to protect against denial-of-service attacks. The engineer wants to classify and police traffic destined to the route processor. Which two types of traffic should be considered for policing? (Choose two.)

⚠ Common exam trap

The trap here is assuming that all traffic passing through the router should be policed by CoPP, but CoPP only applies to traffic destined to the route processor, not transit traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Management traffic (e.g., SSH, SNMP)

CoPP is used to protect the route processor from excessive traffic that could cause high CPU utilization. The most critical types of traffic to police are those destined to the control plane, such as routing protocol updates and management traffic (SSH, SNMP, etc.). These are essential for network operation but can be exploited in DoS attacks. Transit traffic, ARP, and IPsec data traffic are not primary control plane traffic and should be handled by other mechanisms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ARP requests and replies

    Why it's wrong here

    ARP traffic is used for address resolution and is typically handled in the data plane, although some ARP packets may be punted to the control plane. However, ARP is not a primary control plane protocol like routing updates or management traffic. While ARP can be policed, it is not one of the two most critical types to consider for CoPP in this scenario.

  • ✓

    Management traffic (e.g., SSH, SNMP)

    Why this is correct

    Management traffic such as SSH and SNMP is destined to the router itself and is essential for administration. However, it can also be exploited in DoS attacks. Policing this traffic ensures that a flood of management packets does not overwhelm the route processor, while still permitting legitimate administrative access. Therefore, it is a key consideration for CoPP.

  • ✗

    User data traffic transiting the router

    Why it's wrong here

    User data traffic that transits the router is not destined to the route processor; it is forwarded through the router. CoPP is specifically designed to police traffic destined to the control plane (the route processor), not transit traffic. Transit traffic should be handled by data plane policing mechanisms, such as interface ACLs or QoS policies, not CoPP.

  • ✗

    IPsec encrypted traffic

    Why it's wrong here

    IPsec encrypted traffic is typically data plane traffic that is either transiting the router or destined to the router for decryption. While some IPsec control traffic (like IKE) is destined to the control plane, general IPsec encrypted traffic is not a primary target for CoPP. Policing it could disrupt VPN services, so it is not recommended as a primary CoPP classification.

  • ✓

    Routing protocol updates (e.g., OSPF, EIGRP)

    Why this is correct

    Routing protocol updates are critical control plane traffic that must be policed to prevent excessive CPU utilization. An attacker could flood the router with fake routing updates, causing high CPU and potential network instability. CoPP can rate-limit this traffic to a reasonable level while allowing legitimate updates, thus protecting the route processor from DoS attacks.

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.