350-401 Security Practice Question
A network administrator is deploying a Cisco IOS-XE router as the WAN edge. The security policy requires that the router itself be protected against brute-force SSH attacks originating from the untrusted internet, without affecting transit traffic forwarded through the router. The administrator wants to use a feature that automatically blocks the offending source IP after repeated failed login attempts. Which Cisco IOS-XE feature should be configured?
⚠ Common exam trap
The trap here is assuming that CoPP or an ACL can provide dynamic, attempt-triggered blocking of brute-force sources, when only Login Enhancements tracks failed logins and applies the temporary deny automatically.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Login Enhancements (login block-for) with an ACL triggered after failed attempts
The login block-for command, part of Cisco IOS Login Enhancements, watches failed authentication attempts against the device itself. When the configured failure threshold is crossed inside the observation window, the router installs a temporary access list that denies further login attempts from offending hosts for the quiet period. Because it only affects traffic destined to the router's management plane, transit forwarding is unaffected, which is precisely what the scenario demands.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Zone-Based Firewall with a policy dropping TCP port 22 inbound
Why it's wrong here
A Zone-Based Firewall policy applied to the WAN-facing interface would drop all inbound SSH, including legitimate administrative connections, and does not implement any dynamic, attempt-based blocking. It also introduces stateful inspection overhead on transit paths and does not natively inspect failed logins on the router. This does not satisfy the requirement to block only offending sources after repeated failures.
- ✗
IP Source Guard on the WAN interface
Why it's wrong here
IP Source Guard is a Layer 2 switch feature that uses DHCP snooping bindings to filter spoofed source addresses on access ports. It has no visibility into SSH login attempts and is not supported as a protective mechanism on a routed WAN edge. It therefore cannot dynamically block a brute-force attacker and is irrelevant to protecting the router's management plane.
- ✗
Control Plane Policing (CoPP) with a class-map matching TCP port 22
Why it's wrong here
CoPP rate-limits traffic destined to the control plane, but it does not track failed authentication attempts or dynamically block specific source IPs. It can throttle SSH floods, yet it cannot distinguish a brute-force attacker from a legitimate admin and never adds a deny entry. The policy requirement for automatic blocking of the offending source after repeated failures is therefore not met by CoPP alone.
- ✓
Login Enhancements (login block-for) with an ACL triggered after failed attempts
Why this is correct
The login block-for feature, often called Login Enhancements, monitors failed login attempts against the router's local authentication and, when the threshold is exceeded within the configured window, places a temporary ACL that blocks all further login attempts from offending sources for the quiet period. It protects the router's control plane without affecting transit traffic, matching the stated requirement exactly.
Visual reference
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.