mediumMultiple Select
CCNP Practice Question: Which two statements about SNMPv3 security models…
Which two statements about SNMPv3 security models are true? (Choose two.)
⚠ Common exam trap
350-401 often tests the security-level naming — candidates misread 'noAuthNoPriv' as requiring a password, or assume authPriv mandates AES-256, when the model actually supports multiple cipher suites and noAuthNoPriv uses no credentials at all.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The authNoPriv security model provides authentication but no encryption.
Option A is correct because the authNoPriv security level in SNMPv3 authenticates messages using HMAC with MD5 or SHA (verifying integrity and origin) but does not encrypt the payload, so data travels in cleartext. Option C is correct because authPriv combines authentication with encryption, using a privacy protocol such as DES, 3DES, or AES to protect the PDU contents. Option B is wrong because noAuthNoPriv performs no authentication at all, relying only on a username (security name) with no password or HMAC verification. Option D is wrong because SNMPv3 does not require a separate engine ID per manager and agent; each SNMP engine has one unique engine ID, and managers can communicate with multiple agents using their respective IDs. Option E is wrong because authPriv supports multiple encryption algorithms (DES, 3DES, AES-128/192/256 depending on implementation), not only AES-256.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The authNoPriv security model provides authentication but no encryption.
Why this is correct
authNoPriv pairs HMAC authentication (MD5 or SHA) with no payload encryption, so messages are verified as genuine but remain readable in transit. This satisfies the stem's requirement for a true SNMPv3 security-level statement, distinguishing it from authPriv, which adds DES or AES confidentiality.
- ✗
The noAuthNoPriv security model uses both a username and a password for authentication.
Why it's wrong here
noAuthNoPriv performs no authentication and no encryption, so no password is exchanged; the username alone identifies the principal. It is tempting because usernames do appear in SNMPv3 messages, but credential-based authentication belongs to authNoPriv and authPriv, which add HMAC verification and, for authPriv, encryption.
- ✓
The authPriv security model provides both authentication and encryption.
Why this is correct
authPriv combines HMAC authentication with AES or DES encryption, satisfying the stem's requirement for confidentiality alongside integrity verification. Unlike authNoPriv, which authenticates without encrypting payloads, authPriv protects SNMP PDUs from eavesdropping. This directly addresses scenarios demanding both verified origin and private data transmission.
- ✗
SNMPv3 requires the use of a separate engine ID for each SNMP manager and agent.
Why it's wrong here
Each SNMP engine has one authoritative engine ID; managers and agents do not each require a separate one, and discovery learns the peer's ID automatically. It is tempting because engine IDs are unique per device and are central to SNMPv3's authoritative-engine model, so the uniqueness is easily mistaken for a per-role requirement.
- ✗
The authPriv model supports only AES-256 for encryption.
Why it's wrong here
authPriv pairs authentication with encryption, and the security level permits DES, 3DES, AES-128, AES-192 and AES-256 depending on the configured privacy protocol, so AES-256 is not the sole cipher. It is tempting because AES-256 is the strongest available option, which suits hardening requirements, not a factual description of the model.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on 350-401
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which two statements about SNMPv3 security features are true? (Choose two.)
medium- ✓ A.The authNoPriv security level provides authentication using MD5 or SHA, but no encryption.
- B.The noAuthNoPriv security level provides both authentication and encryption.
- ✓ C.The authPriv security level provides authentication using MD5 or SHA, and encryption using DES or AES.
- D.SNMPv3 users are identified solely by the community string, similar to SNMPv2c.
- E.The SNMP engine ID is optional and only used for debugging purposes.
Why A: Option A is correct because the authNoPriv security level in SNMPv3 performs message authentication and integrity checking using either HMAC-MD5-96 or HMAC-SHA-96, but it deliberately does not provide data encryption (privacy). Option C is correct because authPriv combines authentication via MD5 or SHA with encryption, using DES or AES (with AES-128 being common) to protect the payload. Option B is wrong because noAuthNoPriv provides neither authentication nor encryption, relying only on a username match. Option D is wrong because SNMPv3 replaces community strings with the User-based Security Model (USM), where users are identified by a userName combined with an authoritative SNMP engine ID. Option E is wrong because the SNMP engine ID is mandatory and uniquely identifies the SNMP engine for each device; it is used for key localization and discovery, not merely debugging.
Variation 2. Which SNMP version introduced the use of a username and authentication/password framework, without encryption?
easy- A.SNMPv1
- B.SNMPv2c
- ✓ C.SNMPv3
- D.SNMPv2u
Why C: SNMPv3 introduced a security model that provides both authentication and privacy (encryption), but the question specifically asks for the version that introduced a username and authentication/password framework without encryption. SNMPv3's User-based Security Model (USM) allows for authentication-only mode (authNoPriv), which uses a username and password (or key) for authentication but does not encrypt the payload. This distinguishes it from earlier versions that relied on community strings (SNMPv1 and SNMPv2c) or offered no standardized security framework.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.