nerdexam
HP

HPE6-A84 · Question #49

Several AOS-CX switches are responding to SNMPv2 GET requests for the public community. The customer only permits SNMPv3. You have asked a network admin to fix this problem. The admin says, "I tried…

The correct answer is B. Setting the snmp-server settings to "snmpv3-only". This is because SNMPv3 is a secure version of SNMP that provides authentication, encryption, and access control for network management. SNMPv3-only is a configuration option on AOS-CX switches that disables SNMPv1 and SNMPv2c, which are insecure versions of SNMP that use plain…

Troubleshooting Advanced Network Security

Question

Several AOS-CX switches are responding to SNMPv2 GET requests for the public community. The customer only permits SNMPv3. You have asked a network admin to fix this problem. The admin says, "I tried to remove the community, but the CLI output an error." What should you recommend to remediate the vulnerability and meet the customer's requirements?

Options

  • AEnabling control plane policing to automatically drop SNMP GET requests
  • BSetting the snmp-server settings to "snmpv3-only"
  • CAdding an SNMP community with a long random name
  • DEnabling SNMPv3, which implicitly disables SNMPv1/v2

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    74% (14)
  • C
    16% (3)
  • D
    5% (1)

Explanation

This is because SNMPv3 is a secure version of SNMP that provides authentication, encryption, and access control for network management. SNMPv3-only is a configuration option on AOS-CX switches that disables SNMPv1 and SNMPv2c, which are insecure versions of SNMP that use plain text community strings for authentication. By setting the snmp-server settings to "snmpv3- only", the switch will only respond to SNMPv3 requests and reject any SNMPv1 or SNMPv2c requests, thus remedying the vulnerability and meeting the customer's requirements. A. Enabling control plane policing to automatically drop SNMP GET requests. This is not a valid recommendation because control plane policing is a feature that protects the switch from denial- of- service (DoS) attacks by limiting the rate of traffic sent to the CPU. Control plane policing does not disable SNMPv1 or SNMPv2c, but rather applies a rate limit to all SNMP requests, regardless of the version. Moreover, control plane policing might also drop legitimate SNMP requests if they exceed the rate limit, which could affect the network management.

Topics

#SNMPv3#AOS-CX#SNMP security#vulnerability remediation

Community Discussion

No community discussion yet for this question.

Full HPE6-A84 Practice