hardMultiple Choice
300-410 Practice Question: Configures SNMPv3 with authentication only (no…
A network engineer configures SNMPv3 with authentication only (no privacy) on a router. The NMS can poll the router successfully. Later, the engineer adds the 'priv' option to the user configuration. The NMS now fails to poll the router. Which is the most likely explanation?
⚠ Common exam trap
Cisco often tests the misconception that changing an SNMPv3 user's security level only requires a change on the router, but the trap is that the NMS must also be updated with the matching privacy protocol and key, otherwise the mismatch in security levels causes the polling to fail.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The NMS is still configured with the old credentials that do not include the privacy protocol and key.
When the engineer adds the 'priv' option to the SNMPv3 user configuration on the router, the security level changes from authNoPriv to authPriv. The NMS must be updated with the matching privacy protocol (e.g., AES or DES) and the corresponding privacy key. If the NMS still uses the old credentials without the privacy parameters, the authentication will succeed but the privacy decryption will fail, causing the NMS to reject the response and report a polling failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The NMS is still configured with the old credentials that do not include the privacy protocol and key.
Why this is correct
Adding `priv` forces authPriv, so every packet is encrypted with the privacy protocol and key. The NMS still runs authNoPriv, sending unencrypted requests the router now rejects. Mismatched security levels, not credentials, break polling — both ends must specify the same level and matching privacy protocol and key.
- ✗
The router's SNMP engine ID changed when the user was modified.
Why it's wrong here
Adding priv does not regenerate the SNMP engine ID; that identifier persists unless the engine is reconfigured or the device reloads. It tempts because engine ID mismatches do break SNMPv3 authentication, and would be correct if the engine ID had actually been changed or recreated.
- ✗
The privacy protocol (e.g., AES) is not supported on the router.
Why it's wrong here
Adding priv requires the NMS user to be reconfigured with matching privacy protocol and passphrase; the router's AES support is irrelevant since polling worked before. AES is genuinely the right choice when SNMPv3 must encrypt payloads, but here the mismatch lies in the NMS configuration, not router capability.
- ✗
The NMS must restart to recognize the new security level.
Why it's wrong here
SNMPv3 security level is negotiated per request, so the NMS does not need restarting to recognise authPriv; the failure stems from a configuration mismatch such as the NMS still using authNoPriv or a wrong privacy protocol or passphrase. Restarting would be relevant after local service or credential changes.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Device Management and Network Monitoring (SNMP, Syslog, NetFlow)
Key term
SNMPv3 Configuration
SNMPv3 configuration is the process of setting up the third version of the Simple Network Management Protocol on network devices to securely monitor and manage them using authentication and encryption.
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.