Courseiva
hardMultiple Choice

300-410 Practice Question: A large enterprise network is experiencing…

A large enterprise network is experiencing intermittent SNMP polling failures from the NMS to router R2. R1 and R2 are connected via a serial link running OSPF. R1 has the following relevant configuration: snmp-server community public RO, snmp-server community private RW, snmp-server trap-source Loopback0, snmp-server enable traps ospf. R2 shows: debug ip packet shows packets from NMS (10.1.1.100) to R2's Loopback0 (10.2.2.2) being dropped with 'access-list violation'. No ACL is applied to any interface on R2. What is the root cause?

⚠ Common exam trap

Cisco often tests the concept that ACLs can be applied to SNMP community strings (not just interfaces), and candidates mistakenly assume 'no ACL on interfaces' means no ACL is dropping traffic, overlooking the community-string-level ACL as the root cause.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An ACL is applied to the SNMP community string that does not permit the NMS IP address.

The debug output on R2 shows packets from the NMS (10.1.1.100) to R2's Loopback0 (10.2.2.2) being dropped with 'access-list violation'. Since no ACL is applied to any interface on R2, the only remaining ACL that could cause this is an SNMP community ACL. The SNMP community string 'public' or 'private' can have an optional ACL applied via the 'snmp-server community <string> [view <view-name>] [ro|rw] [acl-number]' command. If that ACL does not permit the NMS IP address (10.1.1.100), the router will silently drop SNMP packets from that source, even though no interface ACL exists. This matches the symptom exactly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    An ACL is applied to the SNMP community string that does not permit the NMS IP address.

    Why this is correct

    When the `snmp-server community` command includes an access-list, the router filters incoming SNMP requests by source IP before processing them. The debug output showing 'access-list violation' (or similar) indicates the SNMP packet from the NMS arrived at R2 but was dropped because the NMS's address is not permitted by that ACL. This directly prevents SNMP polling, even though IP connectivity is intact, making the ACL the root cause.

  • ✗

    OSPF network type mismatch between R1 and R2 causes routing blackhole.

    Why it's wrong here

    An OSPF network type mismatch (e.g., broadcast vs point-to-point) prevents adjacency formation, but the symptom here is SNMP polling failure, not a routing blackhole. The debug explicitly shows an ACL violation, meaning the packet was received and evaluated by the SNMP process, so routing from the NMS to R2 is functioning. If OSPF had created a blackhole, the SNMP request would never reach R2, and the debug would show no SNMP activity at all.

  • ✗

    The NMS is using SNMPv3 with incorrect credentials, causing authentication failure.

    Why it's wrong here

    SNMPv3 uses user-based security with authentication and encryption, and a credentials mismatch yields debug messages such as 'SNMPv3 authentication failure' or 'wrong digest', not 'access-list violation'. The presence of an ACL violation indicates the packet was accepted by the SNMP engine and then denied by IP filtering, so the issue is not authentication. Additionally, community strings are a feature of SNMPv1/v2c; the SNMPv3 claim is inconsistent with the debug evidence.

  • ✗

    R2's loopback interface is not advertised into OSPF, making it unreachable.

    Why it's wrong here

    If R2's loopback were not advertised into OSPF, the NMS would likely lack a route to that IP, causing timeouts with no SNMP packet arriving at R2. Here, the debug shows the packet reaching R2 and being dropped by an ACL, proving that routing to the loopback IP is working. Even if the loopback were external to OSPF, the poll would fail at the network layer, not at the SNMP ACL layer, so this is not the cause.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.