easyMultiple Choice
350-401 The default SNMP trap port number? Practice Question
What is the default SNMP trap port number?
⚠ Common exam trap
Cisco often tests the distinction between SNMP query ports (UDP 161) and trap ports (UDP 162), and candidates frequently confuse them or incorrectly assume TCP is used for SNMP traps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
UDP 162
SNMP traps are unsolicited notifications sent from an SNMP agent to a network management system (NMS) to alert about significant events. By default, these trap messages are sent over UDP port 162, as defined in RFC 1157. UDP is used because traps are connectionless and do not require acknowledgment, making them efficient for event-driven notifications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
UDP 161
Why it's wrong here
This option correctly identifies UDP as the transport protocol, but the port number is wrong for traps. UDP port 161 is used for SNMP manager-to-agent requests (get, get-next, get-bulk, and set), and the agent listens on this port for those requests. In contrast, SNMP notifications—traps and informs—are sent by the agent to the manager's UDP port 162. Therefore, directing traps to port 161 would cause them to be received by the wrong service and not processed as notifications.
- ✓
UDP 162
Why this is correct
The correct answer. SNMP traps and informs are sent from the SNMP agent to the network management station (NMS) using UDP as the transport protocol, with a destination port of 162. This is the well-known port assigned by IANA for SNMP notifications. UDP is preferred because it is lightweight and connectionless, ensuring that traps can be transmitted quickly even in unhealthy network conditions, although it also means traps may be lost; SNMPv2 introduces informs to provide acknowledgment.
- ✗
TCP 161
Why it's wrong here
SNMP does not use TCP as its transport protocol; it is designed to operate over UDP, which is connectionless and lightweight, making it suitable for network management even under degraded conditions. Furthermore, port 161 is reserved for SNMP queries such as get, get-next, get-bulk, and set operations sent from the manager to the agent, not for traps that originate from the agent. Thus, this option fails on both the transport layer and the port assignment, as SNMP traps are never sent to port 161 over any protocol.
- ✗
TCP 162
Why it's wrong here
Although port 162 is indeed the standard destination for SNMP traps and informs, the transport protocol is UDP, not TCP. SNMP relies on UDP's stateless datagram service to avoid the overhead and connection-establishment delays of TCP, which would be undesirable for high-frequency network monitoring. TCP would introduce reliability and ordering mechanisms that are not required for the simple notification delivery of traps, so this option is incorrect because it specifies TCP as the transport.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.