mediumMultiple Select
350-401 Practice Question: Which two statements about SNMPv3 security…
Which two statements about SNMPv3 security features are true? (Choose two.)
⚠ Common exam trap
350-401 often tests the misconception that SNMPv3 still uses community strings or that noAuthNoPriv offers any security, when in fact SNMPv3 replaces communities with USM users and engine IDs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The authNoPriv security level provides authentication using MD5 or SHA, but no encryption.
Option A is correct because the authNoPriv security level in SNMPv3 performs message authentication and integrity checking using either HMAC-MD5-96 or HMAC-SHA-96, but it deliberately does not provide data encryption (privacy). Option C is correct because authPriv combines authentication via MD5 or SHA with encryption, using DES or AES (with AES-128 being common) to protect the payload. Option B is wrong because noAuthNoPriv provides neither authentication nor encryption, relying only on a username match. Option D is wrong because SNMPv3 replaces community strings with the User-based Security Model (USM), where users are identified by a userName combined with an authoritative SNMP engine ID. Option E is wrong because the SNMP engine ID is mandatory and uniquely identifies the SNMP engine for each device; it is used for key localization and discovery, not merely debugging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The authNoPriv security level provides authentication using MD5 or SHA, but no encryption.
Why this is correct
authNoPriv sits between noAuthNoPriv and authPriv on the SNMPv3 security ladder: packets carry a message authentication code computed with HMAC-MD5 or HMAC-SHA, verifying origin and integrity, yet the payload remains cleartext because no privacy protocol is negotiated.
- ✗
The noAuthNoPriv security level provides both authentication and encryption.
Why it's wrong here
noAuthNoPriv performs neither authentication nor encryption, providing only a username for identification. The name is tempting because it sounds like a security tier, but authNoPriv supplies authentication without encryption, while authPriv adds both authentication and encryption.
- ✓
The authPriv security level provides authentication using MD5 or SHA, and encryption using DES or AES.
Why this is correct
authPriv is SNMPv3's strongest level, combining HMAC-MD5 or HMAC-SHA authentication with encryption of the scoped PDU using CBC-DES or AES. Both integrity and confidentiality are enforced, unlike authNoPriv, which authenticates but transmits data in cleartext.
- ✗
SNMPv3 users are identified solely by the community string, similar to SNMPv2c.
Why it's wrong here
SNMPv3 identifies users by a unique username combined with the engine ID, and authentication and privacy are handled by the User-based Security Model; community strings belong to SNMPv1 and v2c. Community-string identification is tempting from prior SNMP experience, but v3 replaced it.
- ✗
The SNMP engine ID is optional and only used for debugging purposes.
Why it's wrong here
The SNMP engine ID is mandatory, uniquely identifying each SNMPv3 engine and seeding key localisation for authenticated users; it is not a debugging aid. It is tempting because engine IDs appear in verbose diagnostic output, yet they are fundamental to user and key derivation.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.