exam questions

Exam 350-401 All Questions

View all questions & answers for the 350-401 exam

Exam 350-401 topic 1 question 520 discussion

Actual exam question from Cisco's 350-401
Question #: 520
Topic #: 1
[All 350-401 Questions]


Refer to the exhibit. Which configuration set implements Control Plane Policing for SSH and Telnet?
A.

B.

C.

D.

Show Suggested Answer Hide Answer
Suggested Answer: A

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Caledonia
Highly Voted 2 years, 5 months ago
The right answer is D
upvoted 34 times
...
onkel_andi
Highly Voted 2 years, 4 months ago
Correct answer is D
upvoted 10 times
...
matass_md
Most Recent 2 days, 8 hours ago
Right answer is D , but even D is wrong because POLICING a CoPP means #police 1000000 conform-action transmit EXCEED-ACTION DROP or violate-action DROP without the last part of the command this CoPP does nothing . There is NO IMPLIED DROP of traffic , you need to specify it .
upvoted 1 times
...
Var_Venk
3 months ago
The Answer says option A, but B is the correct one. The COPP policy is applied inbound and class map is matched on "Match Any".
upvoted 2 times
...
BT22
4 months, 4 weeks ago
Correct answer is D
upvoted 2 times
...
IgorLVG
8 months ago
this question is Tricky, the requirement is telnet and ssh conrol, but you use or telnet or ssh so you need mach-any
upvoted 1 times
...
[Removed]
9 months ago
D is correct
upvoted 3 times
[Removed]
8 months, 3 weeks ago
keywords: class-map match-any class-control service-policy input CoPP
upvoted 2 times
...
...
KZM
11 months, 2 weeks ago
It is D. Control Plane Policing (CoPP) is configured to control traffic entering the router, so the service-policy should be applied to the input direction. So, think out option A and B. Option C is incorrect because the class-map "class-telnet-ssh" has not been defined, only "class-telnet" and "class-ssh" have been configured. Therefore, the policy will not have any effect on the router. Hence, the correct answer is option D, which makes sense in the configuration.
upvoted 6 times
hodi
5 months, 3 weeks ago
give some credit to chatgpt
upvoted 1 times
...
...
slacker_at_work
1 year ago
Answer D CSR01(config)#ip access-list extended 100 CSR01(config-ext-nacl)#10 permit tcp any any eq telnet CSR01(config-ext-nacl)#ip access-list extended 101 CSR01(config-ext-nacl)#10 permit tcp any any eq 22 CSR01(config-ext-nacl)#exit CSR01(config)#class-map match-any class-control CSR01(config-cmap)#match access-group 100 CSR01(config-cmap)#match access-group 101 CSR01(config-cmap)#exit CSR01(config)#policy-map CoPP CSR01(config-pmap)#class class-control CSR01(config-pmap-c)#police 1000000 conform-action transmit CSR01(config-pmap-c-police)#exit CSR01(config-pmap-c)#exit CSR01(config-pmap)#exit CSR01(config)#control-plane CSR01(config-cp)#service-policy input CoPP CSR01(config-cp)#^Z CSR01# CSR01#show policy-map CoPP Policy Map CoPP Class class-control police cir 1000000 bc 31250 conform-action transmit exceed-action drop CSR01#
upvoted 3 times
...
AMK2ENG
1 year, 2 months ago
The right answer is D
upvoted 1 times
...
CCNPWILL
1 year, 4 months ago
D is the correct answer folks.
upvoted 1 times
...
CKL_SG
1 year, 7 months ago
Answer is D R8(config)#class-map type ? control Configure a control policy class-map inspect Configure Firewall Class Map Inspect is to configure firewall class map R8(config)#class-map ? WORD class-map name match-all Logical-AND all matching statements under this classmap match-any Logical-OR all matching statements under this classmap https://community.cisco.com/t5/switching/class-map-match-all-or-match-any-exact-difference/td-p/783620 match-all (Optional) Matches all match criteria in the class map. match-any (Optional) Matches one or more match criteria.
upvoted 5 times
...
j8fx
1 year, 8 months ago
Definitely D
upvoted 1 times
...
HarwinderSekhon
1 year, 8 months ago
class map type-inspect is used in Zone Based firewall config for IOS. D is the answer.
upvoted 1 times
...
massimp
1 year, 8 months ago
Don't know why i can't choose the answer here, but it is D for sure.
upvoted 1 times
...
olaniyijt
1 year, 10 months ago
D is the right answer
upvoted 2 times
...
xuanluo
1 year, 10 months ago
if u select A, the warning XXX type inspect is not allowed in policy-map copp of type default; if u select D, match-any means OR not AND The B sounds better, because match-all means logical AND
upvoted 1 times
JackDRipper
1 year, 10 months ago
For answer B, every packet needs to be both telnet and SSH to go through CoPP, which is improbable, if not impossible. D is correct. CoPP is triggered when either a telnet or SSH packet comes in, which is what I take the question is talking about.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago