hardMultiple Choice
300-410 Practice Question: An engineer configures Control Plane Policing…
An engineer configures Control Plane Policing (CoPP) on a router to protect the control plane. After applying the policy, the router becomes unreachable via SSH and SNMP. The engineer checks the policy and confirms that the class-map for SSH and SNMP traffic is set to 'permit'. What is the most likely explanation?
⚠ Common exam trap
The trap is to focus on the SSH/SNMP class-map being 'permit' and overlook the class-default action; candidates must remember that unmatched traffic is handled by class-default, which can drop traffic if configured to do so.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The class-default is set to 'drop', causing all unmatched traffic to be dropped, including SSH and SNMP if they are not correctly classified.
In CoPP, the class-default class defines the action for traffic that does not match any of the defined classes. If class-default is set to 'drop', then any traffic not explicitly matched by a permit class will be dropped. Even though the class-map for SSH and SNMP is set to 'permit', if the traffic is not correctly classified (e.g., due to an incorrect ACL or match condition), it falls into class-default and is dropped. This would cause SSH and SNMP to become unreachable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The class-default is set to 'drop', causing all unmatched traffic to be dropped, including SSH and SNMP if they are not correctly classified.
Why this is correct
In CoPP, the class-default is the default class for all traffic not matched by other classes. If it is set to drop, any traffic that does not match the explicit classes will be dropped. If SSH or SNMP traffic is not correctly matched by the class-map (e.g., due to a typo in the access-list), it will fall into class-default and be dropped.
- ✗
The 'rate-limit' is configured in bps instead of pps, causing excessive policing.
Why it's wrong here
While unit mismatch can cause issues, it would not cause complete unreachability unless the rate is set to 0. The question states the policy is applied, but the router becomes unreachable, suggesting dropping rather than policing.
- ✗
The 'service-policy' is applied to the control-plane input direction, but SSH and SNMP are output traffic.
Why it's wrong here
CoPP only polices traffic destined to the control plane, which is ingress from the router's perspective; SSH and SNMP arriving for the router are input, not output, so the direction is misapplied. Output policing governs traffic the router itself originates, which is why the class-map appears correct yet traffic is dropped.
- ✗
The class-map for SSH and SNMP uses a 'match-all' condition, but the access-list has multiple entries that are ORed.
Why it's wrong here
A match-all class-map with ORed ACL entries still matches any single permitted line, so SSH and SNMP would be permitted rather than dropped. Match-any versus match-all governs how multiple match statements combine, not how entries within one ACL are evaluated.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.