Courseiva
mediumMultiple Choice

CCNP Practice Question: Given the following SNMPv3 configuration on a…

Given the following SNMPv3 configuration on a Cisco IOS-XE router:

snmp-server group ADMIN v3 priv write ADMINVIEW
snmp-server user admin ADMIN v3 auth sha cisco123 priv aes 128 cisco456
snmp-server view ADMINVIEW iso included

What is missing or incorrect in this configuration?

⚠ Common exam trap

Cisco often tests the misconception that a write view must be paired with a read view, or that engine IDs are always required for user creation, but the real trap here is overlooking that including the entire ISO tree makes the write view too permissive for a restricted administrative group.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The view 'ADMINVIEW' includes the entire ISO tree, which might be too permissive for a restricted write view.

The view 'ADMINVIEW' is configured with 'iso included', which includes the entire ISO OID tree. This grants write access to all MIB objects, which is overly permissive for a restricted write view. In SNMPv3, a write view should be limited to specific OIDs or subtrees to enforce least privilege, and including the entire ISO tree violates that principle. Option D is incorrect because a read view is not required if the group is only intended for write operations. The configuration as shown only specifies a write view, which is sufficient for SNMP set operations. Adding a read view is optional and not a mandatory missing piece.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The SNMPv3 user 'admin' must also specify an engine ID for the router.

    Why it's wrong here

    In SNMPv3, the engine ID is used to identify the SNMP engine for key derivation, but the user configuration does not require an explicit engine ID. Cisco IOS automatically associates the user with the router's local engine ID when none is specified. An engine ID is only mandatory when creating a user for a remote engine (e.g., for proxy) or when matching a user to a non-default engine. Therefore, the statement that 'admin' must specify an engine ID is incorrect.

  • ✓

    The view 'ADMINVIEW' includes the entire ISO tree, which might be too permissive for a restricted write view.

    Why this is correct

    The view command 'iso included' in Cisco IOS SNMP configuration includes the entire ISO OID subtree (1.3.6.1), which covers all MIB objects accessible via SNMP. For a write view intended to be restricted, this is overly permissive because it grants write access to virtually any managed object, including critical system parameters. This defeats the purpose of VACM (View-Based Access Control Model) restriction, making it a security flaw. Hence, the configuration should use a more specific subtree, such as 'system' or 'interfaces', to limit the write scope.

  • ✗

    The privacy password 'cisco456' must be at least 8 characters long.

    Why it's wrong here

    Cisco IOS SNMPv3 does not enforce a minimum password length for the privacy (encryption) password; it accepts passwords of any length, including short ones. Although security best practices recommend a minimum of eight characters to prevent brute-force attacks, there is no such hard requirement in the CLI. The router will not reject 'cisco456' on the basis of length alone, so the statement is false. Note that some Cisco documentation suggests a minimum of 8 for stronger security, but it is not enforced.

  • ✗

    The group 'ADMIN' must be configured with a read view to allow SNMP get operations.

    Why it's wrong here

    Incorrect. A read view is not required for this configuration. The group 'ADMIN' is configured with a write view only, which is sufficient for SNMP set operations. If SNMP get operations are needed, a read view would be necessary, but it is not a mandatory missing piece in the current setup.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.