Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium

A network security engineer is configuring a Cisco router to protect its CPU from excessive traffic destined to the control plane, such as BGP updates, OSPF hellos, and SSH login attempts. The goal is to prevent denial-of-service attacks targeting the router's control plane resources. Which security feature should be implemented?

  1. AManagement Plane Policing (MPP)
  2. BData Plane Policing (DPP)
  3. CControl Plane Policing (CoPP)
  4. DAccess Control Lists (ACLs)
Show answer & explanation

Correct answer: C. Control Plane Policing (CoPP)

Control Plane Policing (CoPP) is specifically designed to protect the router's CPU by controlling the rate of traffic destined for the control plane. This prevents malicious or excessive traffic from overwhelming the router's processing capabilities.

Why the other options are wrong

  • A. MPP protects management interfaces (e.g., Telnet, SSH) but is a subset of control plane protection.
  • B. DPP controls traffic flowing through the router (data plane), not to its CPU.
  • D. ACLs filter traffic but don't inherently rate-limit or protect the CPU from control plane overload.

Control Plane Policing (CoPP)

A Cisco IOS feature that protects the router's control plane (CPU) from excessive traffic by classifying and rate-limiting packets destined for the CPU.

  • Protects the router's brain (CPU).
  • Targets traffic like routing updates, management protocols, and ICMP.
  • Uses MQC (Modular QoS CLI) to define policies.

Memory trick: Each plane of traffic needs its own police force.

More Security questions