Courseiva
mediumMultiple Choice

300-410 Practice Question: Consider the following CoPP configuration:…

Consider the following CoPP configuration:

access-list 150 permit tcp any any eq 179
access-list 
150 permit udp any any eq 646

! class-map match-all COPP-CORE match access-group 150 ! policy-map COPP-POLICY

class COPP-CORE

police 64000 conform-action transmit exceed-action drop

class class-default

police 128000 conform-action transmit exceed-action drop ! control-plane service-policy input COPP-POLICY

What is missing from this configuration to also protect against ICMP-based control-plane attacks?

⚠ Common exam trap

Cisco often tests the misconception that class-default alone is sufficient for all unmatched traffic, but the trap here is that ICMP is a direct control-plane threat that must be explicitly classified and rate-limited, not left to the default catch-all policer which may be too permissive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add 'permit icmp any any' to access-list 150 to include ICMP in the COPP-CORE class.

The current CoPP configuration only matches BGP (TCP port 179) and LDP (UDP port 646) traffic in the COPP-CORE class. ICMP-based control-plane attacks (e.g., ICMP floods, Smurf attacks) are not matched by any explicit class, so they fall into class-default, which has a higher police rate (128 kbps) and may allow excessive ICMP traffic to reach the control plane. Adding 'permit icmp any any' to access-list 150 ensures ICMP packets are classified into COPP-CORE and subjected to the more restrictive 64 kbps policer, protecting the control plane from ICMP-based attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add 'permit icmp any any' to access-list 150 to include ICMP in the COPP-CORE class.

    Why this is correct

    Adding 'permit icmp any any' to access-list 150 causes the COPP-CORE class-map to match ICMP packets, which are currently not classified and thus fall into class-default. This minimal, targeted change subjects ICMP traffic to the 64000 bps policer, protecting the control plane from ping floods while leaving all other control-plane traffic unaffected. It directly addresses the missing classification and is the simplest correct fix.

  • ✗

    Change the class-default police rate to 64000 bps to match the COPP-CORE rate.

    Why it's wrong here

    Lowering the class-default police rate to 64000 bps would indeed rate-limit ICMP, but it would also throttle all other unclassified control-plane traffic, including routing protocol hellos, keepalives, and management protocols that do not match ACL 150. This indiscriminate shaping could disrupt essential control-plane operations, potentially causing routing instability or loss of management access. The proper solution is to classify ICMP specifically within the COPP-CORE class, not penalize the entire default class.

  • ✗

    Add a second class-map for ICMP and apply a separate policer.

    Why it's wrong here

    A second class-map for ICMP with a separate policer is functionally possible, but it introduces unnecessary configuration overhead and complexity. The current configuration already has an ACL (150) attached to the COPP-CORE class, so the missing piece is merely an ACL entry for ICMP—not a new class-map. Duplicating policy for the same protocol fragment is less efficient and not the simplest remedy the question is seeking.

  • ✗

    The configuration is complete; ICMP is not a significant control-plane threat.

    Why it's wrong here

    ICMP is absolutely a significant control-plane threat; ping floods and other ICMP-based DDoS attacks can saturate the route processor and degrade router performance. Without explicit classification, ICMP packets are processed by class-default, which may be polised at a higher rate or not rate-limited at all, leaving the control plane exposed. Best practices require rate-limiting all control-plane protocols, including ICMP, so the configuration is incomplete without adding the permit statement.

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.