Courseiva
Security →mediumMultiple Choice

350-401 Security Practice Question

A network administrator is deploying a Cisco IOS-XE router as the WAN edge. The security policy requires that the router itself be protected against brute-force SSH attacks originating from the untrusted internet, without affecting transit traffic forwarded through the router. The administrator wants to use a feature that automatically blocks the offending source IP after repeated failed login attempts. Which Cisco IOS-XE feature should be configured?

⚠ Common exam trap

The trap here is assuming that CoPP or an ACL can provide dynamic, attempt-triggered blocking of brute-force sources, when only Login Enhancements tracks failed logins and applies the temporary deny automatically.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Login Enhancements (login block-for) with an ACL triggered after failed attempts

The login block-for command, part of Cisco IOS Login Enhancements, watches failed authentication attempts against the device itself. When the configured failure threshold is crossed inside the observation window, the router installs a temporary access list that denies further login attempts from offending hosts for the quiet period. Because it only affects traffic destined to the router's management plane, transit forwarding is unaffected, which is precisely what the scenario demands.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Zone-Based Firewall with a policy dropping TCP port 22 inbound

    Why it's wrong here

    A Zone-Based Firewall policy applied to the WAN-facing interface would drop all inbound SSH, including legitimate administrative connections, and does not implement any dynamic, attempt-based blocking. It also introduces stateful inspection overhead on transit paths and does not natively inspect failed logins on the router. This does not satisfy the requirement to block only offending sources after repeated failures.

  • ✗

    IP Source Guard on the WAN interface

    Why it's wrong here

    IP Source Guard is a Layer 2 switch feature that uses DHCP snooping bindings to filter spoofed source addresses on access ports. It has no visibility into SSH login attempts and is not supported as a protective mechanism on a routed WAN edge. It therefore cannot dynamically block a brute-force attacker and is irrelevant to protecting the router's management plane.

  • ✗

    Control Plane Policing (CoPP) with a class-map matching TCP port 22

    Why it's wrong here

    CoPP rate-limits traffic destined to the control plane, but it does not track failed authentication attempts or dynamically block specific source IPs. It can throttle SSH floods, yet it cannot distinguish a brute-force attacker from a legitimate admin and never adds a deny entry. The policy requirement for automatic blocking of the offending source after repeated failures is therefore not met by CoPP alone.

  • ✓

    Login Enhancements (login block-for) with an ACL triggered after failed attempts

    Why this is correct

    The login block-for feature, often called Login Enhancements, monitors failed login attempts against the router's local authentication and, when the threshold is exceeded within the configured window, places a temporary ACL that blocks all further login attempts from offending sources for the quiet period. It protects the router's control plane without affecting transit traffic, matching the stated requirement exactly.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.