mediumMultiple Choice
300-410 Practice Question: The default SNMPv3 security level for a user…
What is the default SNMPv3 security level for a user configured with the "snmp-server user username groupname v3 auth sha password" command?
⚠ Common exam trap
It's easy for candidates to assume the command is invalid or that the security level must be explicitly stated, but Cisco's CLI defaults to `authNoPriv` when only authentication is configured, and the command is perfectly valid without the `priv` keyword.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
authNoPriv
When you configure an SNMPv3 user with the `snmp-server user username groupname v3 auth sha password` command without explicitly specifying a privacy (encryption) password or the `priv` keyword, the default security level is `authNoPriv`. This means authentication is enabled using SHA, but no encryption is applied to the SNMP packets. The security level is implicitly set to `authNoPriv` because the command includes an authentication password but omits the privacy password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
noAuthNoPriv
Why it's wrong here
The command specifies `auth sha`, which sets authentication but omits the `priv` keyword, so the resulting security level is authNoPriv, not noAuthNoPriv. noAuthNoPriv applies only when neither authentication nor encryption is configured, such as `snmp-server user username groupname v3` with no `auth` or `priv` parameters.
- ✓
authNoPriv
Why this is correct
Specifying auth sha without a priv keyword selects authentication without encryption, which is the authNoPriv security level. The user is authenticated by HMAC-SHA but SNMP payloads travel unencrypted, unlike authPriv which adds DES or AES privacy.
- ✗
authPriv
Why it's wrong here
Configuring only `auth sha` sets authentication without encryption, so the resulting level is authNoPriv, not authPriv. Choosing authPriv is tempting because it is the strongest SNMPv3 level, and it would be correct had the command also included a `priv aes` or `priv des` keyword with a privacy password.
- ✗
The command is invalid without specifying a security level.
Why it's wrong here
The syntax is valid; omitting the priv keyword simply leaves the user at authNoPriv, so no security-level argument is mandatory. It tempts candidates who assume every SNMPv3 user needs explicit priv configuration, but that applies only when authPriv or authNoPriv must be forced.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.