Question 1
Network administrators at a medical facility cannot log in to network devices because of excessive resource consumption and high CPU utilization. The situation has led to delays in routine maintenance and troubleshooting, which affects overall network performance. An engineer must optimize the handling of traffic to reduce the impact and maintain consistent access and operational efficiency. Which approach must be implemented to meet the requirement?
The scenario described---where high CPU utilization prevents administrators from accessing device management interfaces---is a classic indication that the device's Control Plane is being overwhelmed by malicious or malformed traffic (such as a DoS attack or a routing loop). To protect the 'brains' of the network device, Control Plane Policing (CoPP) must be implemented.
CoPP allows an engineer to define filter and rate-limit policies specifically for traffic destined for the CPU. By categorizing traffic into different classes (e.g., routing protocols, management traffic like SSH, and 'catch-all' untrusted traffic), CoPP ensures that critical management and control traffic is prioritized while excessive or suspicious traffic is dropped before it can impact the device's performance. This maintains operational efficiency even during a traffic spike or attack. While AAA (Option B) handles authentication and RBAC (Option D) manages permissions once a user is logged in, neither can prevent the CPU exhaustion that blocks the login attempt in the first place. SNMP (Option C) is used for monitoring but does not provide active traffic policing. Within the Cisco SDSI framework, CoPP is a fundamental 'Self-Defending Network' feature required to ensure the availability and resilience of the core infrastructure.