mediumMultiple Choice
300-410 Practice Question: Which SNMP version introduced the use of a…
Which SNMP version introduced the use of a User-based Security Model (USM) and View-based Access Control Model (VACM)?
⚠ Common exam trap
Cisco often tests the distinction between SNMPv2u (which introduced user-based security but not VACM) and SNMPv3 (which combined USM and VACM), leading candidates to mistakenly select SNMPv2u as the version that introduced both models.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SNMPv3
SNMPv3 introduced the User-based Security Model (USM) for authentication and encryption, and the View-based Access Control Model (VACM) for granular access control. These models provide message integrity, authentication, and encryption, addressing the security deficiencies of earlier SNMP versions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SNMPv1
Why it's wrong here
SNMPv1 defines only community-string authentication and simple MIB views, with no USM or VACM framework. It is tempting because v1 introduced the basic manager-agent model and community access, which suits legacy read-only monitoring, but it cannot provide per-user authentication or granular view-based access control.
- ✗
SNMPv2c
Why it's wrong here
SNMPv2c retains community-string authentication with no USM or VACM; its additions were bulk retrieval and 64-bit counters. It is tempting because v2c is the common production version, but it would be correct only where plaintext community-based access is acceptable, not where per-user authentication and view-based authorisation are required.
- ✓
SNMPv3
Why this is correct
SNMPv3 added the User-based Security Model for authentication and encryption plus the View-based Access Control Model for granular access, neither of which exists in SNMPv1 or v2c. That cryptographic and access-control architecture is the defining change.
- ✗
SNMPv2u
Why it's wrong here
SNMPv2u proposed user-based security as an interim experimental design, but it was never ratified as a standard and defines no VACM. It is tempting because its name implies user-based security, yet it would only suit experimental v2 deployments, not the standardised USM and VACM combination.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.