mediumMultiple Choice
350-401 Practice Question: Given the following SNMP configuration on a Cisco…
Given the following SNMP configuration on a Cisco IOS-XE router:
snmp-server community public RO snmp-server community private RW snmp-server location Building-A snmp-server contact admin@example.com snmp-server enable traps snmp linkdown linkup snmp-server host 192.168.1.100 version 2c public
What is the effect of this configuration?
⚠ Common exam trap
Cisco often tests the fact that the community string in the `snmp-server host` command explicitly overrides the default trap community, and that only the traps listed in the `enable traps` command are sent, not all possible traps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The router will send SNMP traps to 192.168.1.100 using community string 'public' for linkdown and linkup events.
The `snmp-server host` command specifies the destination for SNMP notifications, and the community string 'public' is explicitly included in the command, overriding the default behavior of using the first configured RW community. The `snmp-server enable traps snmp linkdown linkup` command enables only linkdown and linkup traps. Therefore, the router sends only those two trap types to 192.168.1.100 using the 'public' community string.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The router will send SNMP traps to 192.168.1.100 using community string 'public' for linkdown and linkup events.
Why this is correct
The command `snmp-server enable traps snmp linkdown linkup` explicitly enables only the linkDown and linkUp notifications, and `snmp-server host 192.168.1.100 public` designates 192.168.1.100 as the trap receiver using the community string 'public'. Because version 2c is the default for this command, the traps are sent as SNMPv2c with 'public' as the community string. This is the intended behavior described in the question, so this option is correct.
- ✗
The router will send SNMP traps to 192.168.1.100 using community string 'private' for all SNMP traps.
Why it's wrong here
The community string in the `snmp-server host` command is 'public', not 'private' — the command `snmp-server host 192.168.1.100 public` explicitly sets 'public' as the community for sending traps. Additionally, only linkdown and linkup traps are enabled via the `snmp-server enable traps snmp linkdown linkup` command; no 'all' traps are configured. The string 'private' would only be relevant if it were used as a read-write community in other commands, but it is not used for trap generation here.
- ✗
The router will only accept SNMP read requests using community 'public' and write requests using community 'private'.
Why it's wrong here
This option describes the typical RO/RW community configuration (e.g., `snmp-server community public RO` and `snmp-server community private RW`), which might exist in the same router. However, the question asks about the effect of the entire configuration shown, which specifically includes trap generation directives. Even if the router does accept read requests with 'public' and writes with 'private', the config also sends traps, and this option ignores that trap behavior entirely, making it an incomplete and incorrect answer.
- ✗
The router will send SNMPv3 traps to 192.168.1.100 using authentication.
Why it's wrong here
The configuration in the scenario uses `snmp-server host 192.168.1.100 public`, which defaults to SNMP version 2c (or v1 if the version is explicitly set), not SNMPv3. SNMPv3 traps require a user with an authentication protocol (like MD5/SHA) and would be configured via `snmp-server host ... version 3 auth <user>` plus an `snmp-server user` command. Since no such user or version 3 parameter is present, the router will not send SNMPv3 traps; it sends v2c traps with the community string 'public'.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.