mediumMultiple Choice
CCNP Practice Question: Given the following SNMPv3 configuration on a…
Given the following SNMPv3 configuration on a Cisco IOS-XE router:
snmp-server group ADMIN v3 priv write ADMINVIEW snmp-server user admin ADMIN v3 auth sha cisco123 priv aes 128 cisco456 snmp-server view ADMINVIEW iso included
What is missing or incorrect in this configuration?
⚠ Common exam trap
Cisco often tests the misconception that a write view must be paired with a read view, or that engine IDs are always required for user creation, but the real trap here is overlooking that including the entire ISO tree makes the write view too permissive for a restricted administrative group.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The view 'ADMINVIEW' includes the entire ISO tree, which might be too permissive for a restricted write view.
The view 'ADMINVIEW' is configured with 'iso included', which includes the entire ISO OID tree. This grants write access to all MIB objects, which is overly permissive for a restricted write view. In SNMPv3, a write view should be limited to specific OIDs or subtrees to enforce least privilege, and including the entire ISO tree violates that principle. Option D is incorrect because a read view is not required if the group is only intended for write operations. The configuration as shown only specifies a write view, which is sufficient for SNMP set operations. Adding a read view is optional and not a mandatory missing piece.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The SNMPv3 user 'admin' must also specify an engine ID for the router.
Why it's wrong here
In SNMPv3, the engine ID is used to identify the SNMP engine for key derivation, but the user configuration does not require an explicit engine ID. Cisco IOS automatically associates the user with the router's local engine ID when none is specified. An engine ID is only mandatory when creating a user for a remote engine (e.g., for proxy) or when matching a user to a non-default engine. Therefore, the statement that 'admin' must specify an engine ID is incorrect.
- ✓
The view 'ADMINVIEW' includes the entire ISO tree, which might be too permissive for a restricted write view.
Why this is correct
The view command 'iso included' in Cisco IOS SNMP configuration includes the entire ISO OID subtree (1.3.6.1), which covers all MIB objects accessible via SNMP. For a write view intended to be restricted, this is overly permissive because it grants write access to virtually any managed object, including critical system parameters. This defeats the purpose of VACM (View-Based Access Control Model) restriction, making it a security flaw. Hence, the configuration should use a more specific subtree, such as 'system' or 'interfaces', to limit the write scope.
- ✗
The privacy password 'cisco456' must be at least 8 characters long.
Why it's wrong here
Cisco IOS SNMPv3 does not enforce a minimum password length for the privacy (encryption) password; it accepts passwords of any length, including short ones. Although security best practices recommend a minimum of eight characters to prevent brute-force attacks, there is no such hard requirement in the CLI. The router will not reject 'cisco456' on the basis of length alone, so the statement is false. Note that some Cisco documentation suggests a minimum of 8 for stronger security, but it is not enforced.
- ✗
The group 'ADMIN' must be configured with a read view to allow SNMP get operations.
Why it's wrong here
Incorrect. A read view is not required for this configuration. The group 'ADMIN' is configured with a write view only, which is sufficient for SNMP set operations. If SNMP get operations are needed, a read view would be necessary, but it is not a mandatory missing piece in the current setup.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.