ETExamTower
Q32Network Assurance

Refer to the exhibit. How does the router treat traffic after the CoPP policy has been configured on it?

Question exhibit
← → navigate · a answer
Community votes
A
69% (9)
B
23% (3)
C
8% (1)
D
0% (0)
Discussion · 22
11
I think the correct answer is A because the output says "Service-policy output: CoPP," so the traffic will be policed.
B 7
Selected Answer: B "Only ingress CoPP is supported. The system-cpp-policy policy-map is available on the control plane interface, and only in the ingress direction". https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-11/configuration_guide/sec/b_1611_sec_9300_cg/configuring_control_plane_policing.pdf So A can't be right. B is the answer.
5
https://www.cisco.com/c/en/us/td/docs/ios/12_2sb/feature/guide/cpp.html * input—Applies the specified service policy to packets received on the control plane. * output—Applies the specified service policy to packets transmitted from the control plane and enables the router to silently discard packets.
A 5
Selected Answer: A Service Policy is in the output direction. So traffic generated by the router will be policed.
C 4
Selected Answer: C Come on guys, the correct answer is C. "Another special note on Cisco ACLs is that ACLs never apply to traffic generated by the router. So, even if you have an inbound and an outbound ACL on a router denying all traffic, the router will still be able to send any packet it wants; the return packet, however, will be blocked as usual" https://www.ciscopress.com/articles/article.asp?p=174313&seqNum=4
A 3
Selected Answer: A A is correct. Note the keyword "output"
A 2
Selected Answer: A would choose A
A 2
Selected Answer: A I think the correct answer is A because the output says "Service-policy output: CoPP," so traffic will be policed
A 2
Selected Answer: A A is correct. Because the service policy is applied to the control plane. So the router generates the traffic. Control plane is the key word why Choose A.
2
The system-cpp-policy policy map is a system-default policy map. The policy map mentioned in the question is a manual policy map named CoPP
2
Can confirm, the input output reads: “Service-policy input:”
2
B is correct. A is not true. CoPP policies do not apply to traffic generated by the router itself, but rather to incoming traffic to the control plane
2
A. Traffic generated by R1 that matches access list SNMP is policed. This option is incorrect because CoPP does not police traffic generated by the router itself (R1). B. Traffic coming to R1 that matches access list SNMP is policed. This is the correct answer. CoPP polices traffic coming to the router (R1) that matches the specified access list (SNMP). C. Traffic passing through R1 that matches access list SNMP is policed. CoPP does not police transit traffic passing through the router; it only affects traffic destined for the router. D. Traffic coming to R1 that does not match access list SNMP is dropped. CoPP does not drop traffic that does not match the specified access list; it only polices it. Therefore, option B is the correct answer.
A 2
Selected Answer: A From oficial book, " CoPP supports inbound and outbound policies; however, outbound policies are not commonly used." So, I believe A is ok.
B 2
Selected Answer: B The CoPP policies limit known traffic to a specific rate while protecting the CPU from unexpectedly high traffic rates that might threaten the router's stability.
A 2
Selected Answer: A "the Control Plane Policing feature treats the CP as a separate entity with its own interface for ingress (input) and egress (output) traffic. " https://www.cisco.com/c/en/us/td/docs/ios/ios_xe/sec_control_plane/configuration/guide/2_xe/cps_xe_book/ctrl_plane_policng_xe.html#wp1082901
2
"To protect the CP on a router from DoS attacks and to provide fine-control over the traffic to or from the CP, the Control Plane Policing feature treats the CP as a separate entity with its own interface for ingress (input) and egress (output) traffic"
B 2
Selected Answer: B B - why would we police traffic generated by the router itself? We should police the traffic coming to the CP using CoPP There is no evidence in the output for answer A to support the theory of policing traffic generated by the router?
1
Answer A I think A is the correct one. https://www.cisco.com/c/en/us/td/docs/ios/ios_xe/sec_control_plane/configuration/guide/2_xe/cps_xe_book/ctrl_plane_policng_xe.html
1
When the service policy is applied to the control plane, only the input direction is supported. https://www.cisco.com/en/US/docs/general/Test/dwerblo/broken_guide/copp.html
A 1
Selected Answer: A Egress CoPP: Policy is accepted on some platforms, but it is not enforced, so it is really informational only, showing counters but doing nothing to packets. A is the most accurate answer
1
ACL's applied on an interface only filter transit traffic, not traffic generated by the router itself. However, ACL's applied to CoPP filter traffic generated or destined to the router.