hardMultiple Choice
200-201 Practice Question: A security auditor reviews the SNMP configuration
Network Topology
A security auditor reviews the SNMP configuration. Which security concern should be reported?
⚠ Common exam trap
Cisco often tests the distinction between the existence of a default community string (a critical vulnerability) versus the access level (read-only vs. read-write) or the exposure of non-sensitive MIB objects like sysLocation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The community strings are set to default values
Default SNMP community strings (e.g., 'public' for read-only, 'private' for read-write) are well-known and widely documented. An attacker who discovers these defaults can query or modify the device's MIB, leading to information disclosure or unauthorized configuration changes. This is a critical security concern that must be reported.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The location and contact information is exposed
Why it's wrong here
SNMP sysLocation and sysContact fields are administrative metadata, not a vulnerability; exposure alone reveals nothing exploitable. It is tempting because information disclosure is a recognised SNMP weakness, and would be correct if the community string were default or readable, allowing device enumeration and reconfiguration.
- ✗
SNMP is disabled on the router
Why it's wrong here
Disabling SNMP removes the attack surface entirely, so it is a hardening measure rather than a finding. It is tempting to flag any disabled management service, but the auditor's concern is an enabled service using default or weak community strings; disabled SNMP would be the correct, secure state.
- ✓
The community strings are set to default values
Why this is correct
Default community strings such as "public" and "private" are effectively shared passwords sent in cleartext by SNMPv1 and SNMPv2c, so any host on the management network can read or alter device data. This directly satisfies the auditor's concern about weak SNMP authentication, unlike SNMPv3, which provides hashing and encryption.
- ✗
The private community string is read-only
Why it's wrong here
A read-only private community string is the secure configuration, so it raises no concern; write access is what auditors flag. It is tempting because read-only sounds restrictive, but SNMP community strings transmit in cleartext regardless of access level, and the real risk is a writable string permitting configuration changes.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.