hardMultiple Choice
300-410 Practice Question: A large enterprise network is experiencing…
A large enterprise network is experiencing intermittent SNMP polling failures from the NMS to router R2. R1 and R2 are connected via a serial link running OSPF. R1 has the following relevant configuration: snmp-server community public RO, snmp-server community private RW, snmp-server trap-source Loopback0, snmp-server enable traps ospf. R2 shows: debug ip packet shows packets from NMS (10.1.1.100) to R2's Loopback0 (10.2.2.2) being dropped with 'access-list violation'. No ACL is applied to any interface on R2. What is the root cause?
⚠ Common exam trap
Cisco often tests the concept that ACLs can be applied to SNMP community strings (not just interfaces), and candidates mistakenly assume 'no ACL on interfaces' means no ACL is dropping traffic, overlooking the community-string-level ACL as the root cause.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An ACL is applied to the SNMP community string that does not permit the NMS IP address.
The debug output on R2 shows packets from the NMS (10.1.1.100) to R2's Loopback0 (10.2.2.2) being dropped with 'access-list violation'. Since no ACL is applied to any interface on R2, the only remaining ACL that could cause this is an SNMP community ACL. The SNMP community string 'public' or 'private' can have an optional ACL applied via the 'snmp-server community <string> [view <view-name>] [ro|rw] [acl-number]' command. If that ACL does not permit the NMS IP address (10.1.1.100), the router will silently drop SNMP packets from that source, even though no interface ACL exists. This matches the symptom exactly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
An ACL is applied to the SNMP community string that does not permit the NMS IP address.
Why this is correct
When the `snmp-server community` command includes an access-list, the router filters incoming SNMP requests by source IP before processing them. The debug output showing 'access-list violation' (or similar) indicates the SNMP packet from the NMS arrived at R2 but was dropped because the NMS's address is not permitted by that ACL. This directly prevents SNMP polling, even though IP connectivity is intact, making the ACL the root cause.
- ✗
OSPF network type mismatch between R1 and R2 causes routing blackhole.
Why it's wrong here
An OSPF network type mismatch (e.g., broadcast vs point-to-point) prevents adjacency formation, but the symptom here is SNMP polling failure, not a routing blackhole. The debug explicitly shows an ACL violation, meaning the packet was received and evaluated by the SNMP process, so routing from the NMS to R2 is functioning. If OSPF had created a blackhole, the SNMP request would never reach R2, and the debug would show no SNMP activity at all.
- ✗
The NMS is using SNMPv3 with incorrect credentials, causing authentication failure.
Why it's wrong here
SNMPv3 uses user-based security with authentication and encryption, and a credentials mismatch yields debug messages such as 'SNMPv3 authentication failure' or 'wrong digest', not 'access-list violation'. The presence of an ACL violation indicates the packet was accepted by the SNMP engine and then denied by IP filtering, so the issue is not authentication. Additionally, community strings are a feature of SNMPv1/v2c; the SNMPv3 claim is inconsistent with the debug evidence.
- ✗
R2's loopback interface is not advertised into OSPF, making it unreachable.
Why it's wrong here
If R2's loopback were not advertised into OSPF, the NMS would likely lack a route to that IP, causing timeouts with no SNMP packet arriving at R2. Here, the debug shows the packet reaching R2 and being dropped by an ACL, proving that routing to the loopback IP is working. Even if the loopback were external to OSPF, the poll would fail at the network layer, not at the SNMP ACL layer, so this is not the cause.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.