PrepAway - Latest Free Exam Questions & Answers

Which security measures can protect the control plane o…

Which security measures can protect the control plane of a Cisco router? (Choose two.)

PrepAway - Latest Free Exam Questions & Answers

A.
CCPr

B.
Parser views

C.
Access control lists

D.
Port security

E.
CoPP

Explanation:
Table 10-3 Three Ways to Secure the Control Plane
Using CoPP or CPPr, you can specify which types of management traffic are acceptable at
which levels.
For example, you could decide and configure the router to believe that SSH is acceptable at
100 packets per second, syslog is acceptable at 200 packets per second, and so on. Traffic
that exceeds the thresholds can be safely dropped if it is not from one of your specific
management stations.
You can specify all those details in the policy.
You learn more about control plane security in Chapter 13, “Securing Routing Protocols and
the Control Plane.”
Selective Packet Discard (SPD) provides the ability to
Although not necessarily a security feature,
prioritize certain types of packets (for example, routing protocol packets and Layer 2
keepalive messages, route processor [RP]). SPD provides priority of critical control plane
traffic which are received by the
over traffic that is less important or, worse yet, is being sent maliciously to starve the CPU of
resources required for the RP.

One Comment on “Which security measures can protect the control plane o…


Leave a Reply