Courseiva
hardMultiple Choice

350-401 Practice Question: Configures SNMPv3 on a Cisco router for secure…

A network engineer configures SNMPv3 on a Cisco router for secure monitoring. The configuration includes 'snmp-server group ADMIN v3 priv', 'snmp-server user admin ADMIN v3 auth sha cisco123 priv aes 128 cisco456', and 'snmp-server host 10.1.1.2 version 3 priv admin'. The NMS is configured with the same credentials. However, the NMS cannot poll the router. The engineer verifies that the router's SNMP agent is enabled. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the subtle requirement that SNMPv3 key derivation depends on the engine ID, leading candidates to overlook this and incorrectly focus on user-group association, security level keywords, or key length restrictions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The NMS must be configured with the router's SNMP engine ID.

The most likely cause is that the NMS must be configured with the router's SNMP engine ID. In SNMPv3, the engine ID is used to derive authentication and encryption keys. Even if the username and passwords match, if the NMS does not know the router's engine ID, it will compute different keys and fail to authenticate or decrypt responses, preventing polling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The SNMPv3 user is not associated with the group correctly.

    Why it's wrong here

    This fault is not the cause because the configuration explicitly associates user 'admin' with the SNMPv3 group 'ADMIN' using the 'snmp-server user admin ADMIN v3' command, and that group is defined with the 'priv' security level to permit both authentication and encryption. The group-to-user mapping therefore provides the exact auth (SHA) and privacy (AES) privileges that the host command is requesting, so the user linkage is correct. The failure would still occur even with a perfectly valid group association, pointing to a different root cause.

  • ✓

    The NMS must be configured with the router's SNMP engine ID.

    Why this is correct

    The NMS must be provisioned with the router's local SNMP engine ID because SNMPv3 user-based authentication (USM) derives each user's authentication and privacy keys by hashing the passphrase together with the authoritative engine ID. Without the correct engine ID, the NMS calculates a different localized key than the router, so the HMAC validation fails and the router silently discards the request after sending it with 'noAuth' or the NMS sees an authentication failure. Even if the username, passwords, and AES settings are identical, a mismatched engine ID always breaks SNMPv3 authentication, making this the necessary corrective action.

  • ✗

    The 'priv' keyword in the host command should be 'auth' instead.

    Why it's wrong here

    The keyword 'priv' in the 'snmp-server host' command is actually correct because the SNMPv3 user 'admin' is configured with both authentication and privacy (AES), and 'priv' tells the router to send notifications that are both authenticated and encrypted. Replacing it with 'auth' would only request authentication without encryption, which would not align with the user's security level and could even cause the NMS to reject the notification as having the wrong security level. Thus this change would be a regression, not a fix.

  • ✗

    The AES encryption key must be exactly 16 characters.

    Why it's wrong here

    This is not the reason for the problem because SNMPv3 AES key lengths are flexible: RFC 3826 defines AES-128 with a 128-bit (16-byte) key, while later standards support AES-192 and AES-256, so a 16-character limit is not mandatory. Furthermore, the configured 'priv aes 128' cipher in the user command specifies AES-128, and the actual key is derived from the passphrase using a key derivation function that includes the engine ID, not from the literal length of a typed key. The authentication failure persists regardless of the passphrase or key length, confirming that the engine ID mismatch is the issue.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.