400-007 · Question #151
A healthcare customer requested that SNMP traps must be sent over the MPLS Layer 3 VPN service. Which protocol must be enabled?
The correct answer is A. SNMPv3. For a healthcare environment requiring SNMP traps over an MPLS Layer 3 VPN, SNMPv3 must be enabled because it is the only SNMP version that provides the authentication and encryption required for regulated industries.
Question
A healthcare customer requested that SNMP traps must be sent over the MPLS Layer 3 VPN service. Which protocol must be enabled?
Options
- ASNMPv3
- BSyslog
- CSyslog TLS
- DSNMPv2
- ESSH
How the community answered
(59 responses)- A92% (54)
- B2% (1)
- C5% (3)
- E2% (1)
Why each option
For a healthcare environment requiring SNMP traps over an MPLS Layer 3 VPN, SNMPv3 must be enabled because it is the only SNMP version that provides the authentication and encryption required for regulated industries.
SNMPv3 introduces the User-based Security Model (USM), which provides message integrity, authentication (HMAC-MD5 or HMAC-SHA), and optional privacy encryption (DES or AES) for SNMP trap traffic. In a healthcare context, these security features are required to meet compliance standards such as HIPAA, which mandate protection of network management data. SNMPv2c relies on plaintext community strings with no encryption, making it unsuitable for sensitive healthcare environments.
Syslog is a log-forwarding protocol used for system event messages and is entirely unrelated to SNMP trap transmission.
Syslog over TLS secures syslog messages in transit but has no involvement in the transmission or security of SNMP traps.
SNMPv2c authenticates only via plaintext community strings with no support for encryption, making it insufficient for a healthcare environment that requires secure SNMP trap transport.
SSH provides encrypted remote command-line access to devices but is not a protocol used for transmitting SNMP traps.
Concept tested: SNMPv3 security features for regulated industry environments
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/snmp/configuration/xe-16/snmp-xe-16-book/nm-snmp-cfg-snmp-support.html
Topics
Community Discussion
No community discussion yet for this question.