Courseiva
Infrastructure Services →mediumMultiple Choice

300-410 Infrastructure Services Practice Question

A network engineer is configuring SNMPv3 on a Cisco IOS router. The requirement is to authenticate and encrypt SNMP messages using the user 'admin' with SHA authentication and AES encryption. Which command correctly configures the SNMPv3 user?

⚠ Common exam trap

The trap here is mixing up authentication and encryption algorithms, such as using a hash function like SHA for privacy, which is not a valid encryption method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

snmp-server user admin group auth sha authpass priv aes 128 privpass

The snmp-server user command with 'auth sha' and 'priv aes 128' correctly configures SNMPv3 with SHA authentication and AES encryption. This provides both message integrity and confidentiality, meeting the security requirements for the SNMPv3 user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    snmp-server user admin group auth sha authpass priv sha privpass

    Why it's wrong here

    This command attempts to use SHA for both authentication and encryption. However, SHA is a hash function used for authentication, not encryption. The 'priv' keyword requires an encryption algorithm such as AES or DES. This command is invalid and will be rejected by the router.

  • ✗

    snmp-server user admin group auth md5 authpass priv des privpass

    Why it's wrong here

    This command uses MD5 for authentication and DES for encryption, which are weaker algorithms than required. The requirement specifies SHA and AES, so this configuration does not meet the security standards. MD5 and DES are considered less secure and should be avoided when stronger options are available.

  • ✓

    snmp-server user admin group auth sha authpass priv aes 128 privpass

    Why this is correct

    This command creates an SNMPv3 user 'admin' with SHA authentication and AES 128-bit encryption. The 'auth sha' specifies SHA authentication, and 'priv aes 128' specifies AES encryption with a 128-bit key. This meets the requirement for both authentication and encryption.

  • ✗

    snmp-server user admin group auth sha authpass priv 3des privpass

    Why it's wrong here

    This command uses SHA for authentication but 3DES for encryption. The requirement is AES encryption, not 3DES. While 3DES is more secure than DES, it is not the specified algorithm. AES is preferred for its stronger security and efficiency.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.