Courseiva
Security →easyMultiple Choice

350-401 Security Practice Question

A network administrator is configuring a Cisco IOS router to protect the control plane from excessive CPU utilization caused by malicious traffic. The administrator wants to rate-limit specific types of traffic destined to the route processor while allowing all other traffic to pass without restriction. Which feature should be configured?

⚠ Common exam trap

Watch out — candidates often confuse Control Plane Policing with Control Plane Protection, when CPPr is a granular extension and CoPP is the standard feature for rate-limiting control plane traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Control Plane Policing

Control Plane Policing applies a QoS policy to the control plane interface, allowing administrators to classify and rate-limit specific traffic types destined to the route processor while permitting other traffic. This directly addresses CPU protection from malicious floods without affecting transit traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Policy-Based Routing

    Why it's wrong here

    Policy-Based Routing (PBR) uses route maps to forward traffic based on criteria such as source address, protocol, or port. It affects the forwarding path, not the control plane, and cannot rate-limit traffic destined to the route processor. PBR is used for traffic engineering, not for protecting CPU resources.

  • ✗

    Management Plane Protection

    Why it's wrong here

    Management Plane Protection (MPP) restricts which interfaces can receive management traffic such as SSH, SNMP, or TFTP. It does not rate-limit traffic types or protect against CPU exhaustion from routing protocol or ICMP floods. MPP is about interface-based management access control, not control plane policing.

  • ✓

    Control Plane Policing

    Why this is correct

    Control Plane Policing (CoPP) uses a modular QoS CLI policy applied to the control plane interface to rate-limit or drop traffic destined to the route processor. It allows granular classification of traffic types such as routing protocols, management access, and ICMP, while permitting unmatched traffic to pass, which matches the requirement exactly.

  • ✗

    Control Plane Protection

    Why it's wrong here

    Control Plane Protection (CPPr) extends CoPP by subdividing the control plane into host, transit, and CEF-exception subinterfaces, providing finer granularity. While it can protect the route processor, the scenario asks for rate-limiting specific traffic types while allowing all other traffic, which is the classic CoPP use case. CPPr is more complex and not required here.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.