300-410 · Question #28
Which option is the best for protecting CPU utilization on a device?
The correct answer is B. CoPP. Control Plane Policing (CoPP) is the most effective method for protecting a device's CPU from excessive or malicious traffic by applying QoS policies to traffic destined for the control plane.
Question
Exhibit
Options
- Afragmentation
- BCoPP
- CICMP redirects
- DICMP unreachable messages
How the community answered
(33 responses)- A6% (2)
- B91% (30)
- C3% (1)
Why each option
Control Plane Policing (CoPP) is the most effective method for protecting a device's CPU from excessive or malicious traffic by applying QoS policies to traffic destined for the control plane.
Fragmentation is the process of breaking packets into smaller units and is a standard network function that can increase, not decrease, CPU load due to reassembly overhead.
CoPP (Control Plane Policing) allows administrators to define QoS policies to classify, rate-limit, and drop traffic that is destined for the router's control plane CPU. This protects the router's core functions from being overwhelmed by denial-of-service attacks, routing protocol floods, or excessive management traffic, ensuring the device remains stable and operational.
ICMP redirects are diagnostic messages used by routers to inform hosts about a better path to a destination, not a mechanism to protect CPU utilization.
ICMP unreachable messages are sent to indicate that a destination is inaccessible and are a symptom of network issues, not a preventative measure for CPU overload.
Concept tested: Control Plane Policing (CoPP) for CPU protection
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_data_copp/configuration/xe-16/sec-data-copp-xe-16-book/sec-data-copp-overview.html
Topics
Community Discussion
No community discussion yet for this question.
