Courseiva
mediumMultiple Choice

300-410 Practice Question: A router experiences high CPU utilization due to…

A router experiences high CPU utilization due to SSH login attempts from an external attacker. The network engineer implements a CoPP policy to rate-limit SSH traffic to 10000 bps. After applying the policy, the engineer notices that legitimate SSH sessions from the management network are also being dropped intermittently. The CoPP policy uses a class-map that matches TCP port 22 traffic. What should the engineer do to fix this issue?

⚠ Common exam trap

Cisco often tests the misconception that simply increasing the police rate or blocking a single attacker IP is sufficient, when the correct solution requires differentiated treatment of trusted versus untrusted traffic within the same protocol class.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a separate class for legitimate SSH traffic from the management network with a higher police rate, and police the attacker's traffic more aggressively.

It uses a granular CoPP design: legitimate SSH traffic from the management network is placed in a separate class with a higher police rate, while the attacker's traffic is policed more aggressively. This preserves control-plane resources for authorized sessions without dropping them, addressing the root cause of the problem—overly broad rate-limiting of all TCP port 22 traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the police rate for the SSH class to 100000 bps to allow all SSH traffic.

    Why it's wrong here

    Raising the police rate for the entire SSH class to 100000 bps is a blunt instrument that indiscriminately allows all SSH traffic, including the attacker’s flood. This defeats CoPP’s purpose because the control-plane CPU will still be overwhelmed by the attacker’s packets, and a static high rate may also be insufficient if the attack volume scales. The correct fix is to differentiate trusted management SSH from malicious traffic via separate classes and distinct police rates.

  • ✗

    Modify the class-map to match only SSH traffic from the attacker's source IP addresses using an access-list.

    Why it's wrong here

    Modifying the class-map to match only the attacker's source IP addresses using an access-list would require a corresponding drop or police action to actually block the attacker, but the option omits that and leaves legitimate SSH traffic without a proper class. It also relies on static source-IP ACL entries, which are ineffective if the attacker spoofs or changes addresses, and it does not address the root problem of the existing SSH class being policed too low for legitimate users. A better approach is to match legitimate management sources into a higher-rate class while aggressively policing the attacker’s traffic.

  • ✓

    Create a separate class for legitimate SSH traffic from the management network with a higher police rate, and police the attacker's traffic more aggressively.

    Why this is correct

    Creating a separate class for legitimate SSH traffic sourced from the management network allows the engineer to assign a higher police rate to trusted sessions, ensuring they are not dropped during an attack. Simultaneously, the attacker’s SSH traffic can be placed in a separate class with a much lower police rate or explicit drop action, thereby protecting the control-plane CPU without affecting administrative access. This granular, class-based approach is the standard CoPP best practice because it balances availability and security.

  • ✗

    Remove the CoPP policy and implement an ACL on the interface to block the attacker's IP address.

    Why it's wrong here

    Removing the CoPP policy and replacing it with an interface ACL that blocks the attacker's IP address is an extreme measure that eliminates control-plane protection for all traffic, not just the malicious flow. It only blocks the specific attacker address currently identified, while the underlying flood or other attack vectors remain unmitigated. CoPP is a defense-in-depth mechanism that should be tuned, not removed; the correct action is to modify the existing policy to separate legitimate SSH from malicious traffic.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.