nerdexam
Cisco

350-501 · Question #24

Refer to the exhibit. A network administrator wants to enhance the security for SNMP for this configuration. Which action can the network administrator implement?

The correct answer is C. Re-configure to use SNMPv3. To enhance SNMP security beyond basic community strings, re-configuring to use SNMPv3 is the most effective action.

Services

Question

Refer to the exhibit. A network administrator wants to enhance the security for SNMP for this configuration. Which action can the network administrator implement?

Options

  • ARe-configure to use SNMPv2 with MD5 authentication
  • BAdd a community string to the existing entry
  • CRe-configure to use SNMPv3.
  • DMaintain the configuration but switch to an encrypted password for device access through SSH

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    94% (45)

Why each option

To enhance SNMP security beyond basic community strings, re-configuring to use SNMPv3 is the most effective action.

ARe-configure to use SNMPv2 with MD5 authentication

While SNMPv2 with MD5 authentication provides message integrity and authentication, it does not offer encryption (privacy) for the SNMP data itself, making it less secure than SNMPv3.

BAdd a community string to the existing entry

Adding a community string to an existing entry is part of the basic configuration for SNMPv1/v2c and does not enhance security beyond what these versions inherently provide, which is sending community strings in clear text or with minimal security.

CRe-configure to use SNMPv3.Correct

SNMPv3 offers significant security enhancements over SNMPv1 and SNMPv2c by providing message integrity, authentication, and encryption (privacy). It uses usernames with authentication protocols (like MD5 or SHA) and encryption protocols (like DES or AES) to secure SNMP communications, making it the most secure option for SNMP management.

DMaintain the configuration but switch to an encrypted password for device access through SSH

Switching to an encrypted password for device access through SSH enhances the security of management access to the device but does not improve the security of SNMP communication itself.

Concept tested: SNMPv3 security features

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/snmp/configuration/xe-3s/snmp-xe-3s-book/nm-snmp-snmpv3.html

Topics

#SNMP#Network Security#Management Protocols#SNMPv3

Community Discussion

No community discussion yet for this question.

Full 350-501 Practice