Courseiva
mediumMultiple Choice

300-410 Practice Question: Runs the following command to troubleshoot SNMP…

A network engineer runs the following command to troubleshoot SNMP access lists:

R1# show snmp access
Access-list: 10

Community: public View: v1default

Access-list: 20

Community: private View: v1default

What does this output indicate?

⚠ Common exam trap

Cisco often tests the distinction between what 'show snmp access' reveals (ACL-to-community mapping) versus what it does not reveal (read-write permissions), leading candidates to incorrectly assume that the 'public' community has read-write access or that no ACLs are applied.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SNMP access is controlled by ACLs: ACL 10 for 'public' and ACL 20 for 'private'.

The 'show snmp access' output displays the configured SNMP access control entries, which map community strings to access control lists (ACLs). In this case, ACL 10 is associated with the 'public' community and ACL 20 with the 'private' community, meaning SNMP access is restricted based on these ACLs. This is the standard method for controlling SNMPv1/v2c access, as the router uses the ACL to permit or deny SNMP requests from specific source IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SNMP access is controlled by ACLs: ACL 10 for 'public' and ACL 20 for 'private'.

    Why this is correct

    The output maps each SNMP community string to an access list: ACL 10 governs 'public' and ACL 20 governs 'private', both using the v1default view. This confirms SNMP access is filtered by those ACLs rather than by views alone.

  • ✗

    No ACLs are applied to SNMP, so all access is allowed.

    Why it's wrong here

    ACLs 10 and 20 are explicitly bound to the 'public' and 'private' communities, so SNMP access is filtered by those lists rather than unrestricted. The output would indicate open access only if no access-list entries appeared. The command confirms ACLs are applied per community.

  • ✗

    The router uses SNMPv3 exclusively.

    Why it's wrong here

    The output lists community strings 'public' and 'private' mapped to ACLs 10 and 20, which is SNMPv1/v2c configuration; SNMPv3 uses users, groups and views instead of community strings. SNMPv3 would be the answer if the output showed 'show snmp user' or group entries, not community-to-ACL mappings.

  • ✗

    The 'public' community has read-write access.

    Why it's wrong here

    The view column shows 'v1default' for both communities, which is the default read-only view; read-write would require a view permitting write operations or an rw community designation. The output would indicate read-write if the view or access entry granted write access, which it does not.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.