Courseiva
hardMultiple Choice

300-410 Practice Question: Configures SNMPv3 with authentication and privacy…

A network engineer configures SNMPv3 with authentication and privacy on a router. The NMS polls the router via the management interface. The engineer then adds a loopback interface and configures the router to send SNMP traps sourced from the loopback IP. The NMS stops receiving traps. Which is the most likely explanation?

⚠ Common exam trap

Cisco often tests the misconception that SNMPv3 security (auth/priv) is the cause of trap delivery failure, when in fact the issue is a source IP mismatch due to the 'snmp-server trap-source' command overriding the default source address.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The NMS is configured to accept traps only from the management interface IP address, not the loopback IP.

The NMS is likely configured with an ACL or trap receiver filter that only accepts SNMP traps from the management interface IP address. When the engineer configures 'snmp-server trap-source loopback0', the router changes the source IP of all outgoing traps to the loopback IP. If the NMS is not expecting traps from that IP, it will drop them, even though SNMPv3 authentication and privacy are correctly configured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The NMS is configured to accept traps only from the management interface IP address, not the loopback IP.

    Why this is correct

    SNMPv3 trap receivers filter by source IP. Changing the trap source to the loopback address alters the packet's source IP, so the NMS discards traps arriving from an address it does not recognise, satisfying the stem's constraint that traps stopped after the source change.

  • ✗

    The loopback interface does not support SNMP trap generation.

    Why it's wrong here

    Loopback interfaces are software interfaces that fully support sourcing SNMP traps; the router can transmit from them. The NMS drops the traps because their source address no longer matches the management interface it polls. Loopback sourcing is correct when the NMS is configured to accept traps from that address.

  • ✗

    The SNMP engine ID changed when the loopback interface was added.

    Why it's wrong here

    Adding a loopback does not regenerate the SNMP engine ID, which derives from the enterprise number and a fixed identifier, not interface inventory. Traps fail because the NMS rejects packets whose source address differs from the polled management interface. Engine ID changes matter when a device is replaced or its engine ID is manually reconfigured.

  • ✗

    The 'snmp-server trap-source' command requires a specific interface type.

    Why it's wrong here

    The snmp-server trap-source command accepts a loopback interface, so interface type is not the constraint. Traps stop because the NMS matches the trap source address against the configured SNMPv3 engine or host entry. Trap-source restrictions apply when binding traps to a specific routable address for ACL filtering.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.