Courseiva
mediumMultiple Choice

300-410 Practice Question: Examine the following CoPP configuration on a…

Examine the following CoPP configuration on a Cisco IOS-XE router:

!--- ACL to match traffic

access-list 100 permit tcp any any eq 22
access-list 
100 permit tcp any any eq 23
access-list 
100 permit icmp any any echo

! !--- Class-map class-map match-all COPP-MGMT match access-group 100 ! !--- Policy-map policy-map COPP-POLICY

class COPP-MGMT

police 8000 conform-action transmit exceed-action drop

class class-default

police 64000 conform-action transmit exceed-action drop ! !--- Apply to control-plane control-plane service-policy input COPP-POLICY

What is the effect of this configuration?

⚠ Common exam trap

Cisco often tests the misconception that ICMP echo is not matched by ACL 100 because it uses the 'echo' keyword rather than a port number, but 'echo' is a valid ICMP type that matches ping requests, so candidates may incorrectly assume only TCP traffic is affected.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSH, Telnet, and ICMP echo packets are rate-limited to 8000 bps; all other control-plane traffic is rate-limited to 64000 bps.

The CoPP configuration matches SSH (TCP/22), Telnet (TCP/23), and ICMP echo (ping) traffic via ACL 100 and class-map COPP-MGMT, then applies a police rate of 8000 bps to that class. All other control-plane traffic falls into class-default and is policed at 64000 bps. The 'conform-action transmit exceed-action drop' statements enforce rate-limiting, not blocking, so the correct effect is that SSH, Telnet, and ICMP echo are rate-limited to 8000 bps, while all other control-plane traffic is rate-limited to 64000 bps.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SSH, Telnet, and ICMP echo packets are rate-limited to 8000 bps; all other control-plane traffic is rate-limited to 64000 bps.

    Why this is correct

    The class-map matches SSH, Telnet, and ICMP echo, and its police action caps that traffic at 8000 bps, dropping excess. The class-default police statement rate-limits all remaining control-plane traffic to 64000 bps, so management protocols are throttled more tightly than other control-plane packets.

  • ✗

    Only SSH and Telnet are rate-limited to 8000 bps; ICMP echo is not affected because it is matched by a different class.

    Why it's wrong here

    The class-map uses match-all with a single access-group, so SSH, Telnet and ICMP echo all map to COPP-MGMT and share the 8000 bps policer. ICMP echo is not excluded; it is matched by access-list 100 and therefore rate-limited alongside the management protocols.

  • ✗

    All control-plane traffic is rate-limited to 64000 bps, because the class-default overrides the COPP-MGMT class.

    Why it's wrong here

    Class-default polices only traffic not matched by earlier classes; SSH, Telnet and ICMP echo match COPP-MGMT and receive the 8000 bps limit instead. It is tempting because class-default appears last and carries the higher rate, but policy-map classes are evaluated independently, not overridden by later entries.

  • ✗

    The configuration is invalid because the class-map must be named 'COPP-CLASS' to be used in the policy-map.

    Why it's wrong here

    Class-map names are locally significant; any name matching the policy-map reference works, so COPP-MGMT is valid and the configuration applies. It is tempting because reserved or predefined names exist elsewhere in IOS, but CoPP imposes no naming convention, making this a fabricated restriction rather than a real syntax rule.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.