350-401 Security Practice Question
A network administrator is configuring a Cisco IOS router to protect the control plane from excessive CPU utilization caused by malicious traffic. The administrator wants to rate-limit specific types of traffic destined to the route processor while allowing all other traffic to pass without restriction. Which feature should be configured?
⚠ Common exam trap
Watch out — candidates often confuse Control Plane Policing with Control Plane Protection, when CPPr is a granular extension and CoPP is the standard feature for rate-limiting control plane traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Control Plane Policing
Control Plane Policing applies a QoS policy to the control plane interface, allowing administrators to classify and rate-limit specific traffic types destined to the route processor while permitting other traffic. This directly addresses CPU protection from malicious floods without affecting transit traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy-Based Routing
Why it's wrong here
Policy-Based Routing (PBR) uses route maps to forward traffic based on criteria such as source address, protocol, or port. It affects the forwarding path, not the control plane, and cannot rate-limit traffic destined to the route processor. PBR is used for traffic engineering, not for protecting CPU resources.
- ✗
Management Plane Protection
Why it's wrong here
Management Plane Protection (MPP) restricts which interfaces can receive management traffic such as SSH, SNMP, or TFTP. It does not rate-limit traffic types or protect against CPU exhaustion from routing protocol or ICMP floods. MPP is about interface-based management access control, not control plane policing.
- ✓
Control Plane Policing
Why this is correct
Control Plane Policing (CoPP) uses a modular QoS CLI policy applied to the control plane interface to rate-limit or drop traffic destined to the route processor. It allows granular classification of traffic types such as routing protocols, management access, and ICMP, while permitting unmatched traffic to pass, which matches the requirement exactly.
- ✗
Control Plane Protection
Why it's wrong here
Control Plane Protection (CPPr) extends CoPP by subdividing the control plane into host, transit, and CEF-exception subinterfaces, providing finer granularity. While it can protect the route processor, the scenario asks for rate-limiting specific traffic types while allowing all other traffic, which is the classic CoPP use case. CPPr is more complex and not required here.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
Control Plane Protection
Control Plane Protection (CoPP) is a security feature on Cisco routers and switches that filters traffic destined to the device's control plane to prevent attacks and ensure stability.
Key term
Control Plane Policing
Control Plane Policing is a Cisco security feature that protects a router or switch by rate-limiting the traffic that the device's processor must handle, preventing it from being overwhelmed.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.