nerdexam
Cisco

400-007 · Question #151

A healthcare customer requested that SNMP traps must be sent over the MPLS Layer 3 VPN service. Which protocol must be enabled?

The correct answer is A. SNMPv3. For a healthcare environment requiring SNMP traps over an MPLS Layer 3 VPN, SNMPv3 must be enabled because it is the only SNMP version that provides the authentication and encryption required for regulated industries.

Designing Management and Operations

Question

A healthcare customer requested that SNMP traps must be sent over the MPLS Layer 3 VPN service. Which protocol must be enabled?

Options

  • ASNMPv3
  • BSyslog
  • CSyslog TLS
  • DSNMPv2
  • ESSH

How the community answered

(59 responses)
  • A
    92% (54)
  • B
    2% (1)
  • C
    5% (3)
  • E
    2% (1)

Why each option

For a healthcare environment requiring SNMP traps over an MPLS Layer 3 VPN, SNMPv3 must be enabled because it is the only SNMP version that provides the authentication and encryption required for regulated industries.

ASNMPv3Correct

SNMPv3 introduces the User-based Security Model (USM), which provides message integrity, authentication (HMAC-MD5 or HMAC-SHA), and optional privacy encryption (DES or AES) for SNMP trap traffic. In a healthcare context, these security features are required to meet compliance standards such as HIPAA, which mandate protection of network management data. SNMPv2c relies on plaintext community strings with no encryption, making it unsuitable for sensitive healthcare environments.

BSyslog

Syslog is a log-forwarding protocol used for system event messages and is entirely unrelated to SNMP trap transmission.

CSyslog TLS

Syslog over TLS secures syslog messages in transit but has no involvement in the transmission or security of SNMP traps.

DSNMPv2

SNMPv2c authenticates only via plaintext community strings with no support for encryption, making it insufficient for a healthcare environment that requires secure SNMP trap transport.

ESSH

SSH provides encrypted remote command-line access to devices but is not a protocol used for transmitting SNMP traps.

Concept tested: SNMPv3 security features for regulated industry environments

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/snmp/configuration/xe-16/snmp-xe-16-book/nm-snmp-cfg-snmp-support.html

Topics

#SNMPv3#MPLS L3 VPN#SNMP traps#network management

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice