300-410 · Question #6
Refer to the exhibit. Which control plan policy limits BGP traffic that is destined to the CPU to 1 Mbps and ignores BGP traffic that is higher rate?
The correct answer is D. policy-map COPP. Control Plane Policing (CoPP) is the policy mechanism used to protect a device's CPU from excessive traffic, such as BGP, by limiting the rate of packets destined to the CPU and dropping any traffic exceeding the defined rate.
Question
Options
- Apolicy-map SHAPE_BGP
- Bpolicy-map LIMIT_BGP
- Cpolicy-map POLICE_BGP
- Dpolicy-map COPP
How the community answered
(32 responses)- B6% (2)
- C3% (1)
- D91% (29)
Why each option
Control Plane Policing (CoPP) is the policy mechanism used to protect a device's CPU from excessive traffic, such as BGP, by limiting the rate of packets destined to the CPU and dropping any traffic exceeding the defined rate.
'policy-map SHAPE_BGP' implies traffic shaping, which buffers and delays excess traffic, typically applied to user plane, not for direct CPU protection.
'policy-map LIMIT_BGP' is a generic name and doesn't specifically refer to the Cisco feature for control plane protection.
'policy-map POLICE_BGP' describes the *action* of policing within a policy map, but 'COPP' is the overarching policy framework specifically for protecting the control plane using such actions.
Control Plane Policing (CoPP) is a feature designed to protect the router's CPU from denial-of-service (DoS) attacks or excessive traffic, including routing protocol traffic like BGP. A CoPP policy explicitly classifies and rate-limits traffic destined for the CPU, and 'ignoring BGP traffic that is higher rate' perfectly describes a policing action that drops exceeding traffic.
Concept tested: Control Plane Policing (CoPP)
Source: https://www.cisco.com/c/en/us/td/docs/ios/security/security_management/qos_based_rate_limiting/configuration/guide/sec_copp.html
Topics
Community Discussion
No community discussion yet for this question.