Courseiva
Question 147 of 464
Network OperationsmediumMultiple ChoiceObjective-mapped

SNMP for Network Monitoring and Alerting

A network administrator wants to collect performance data from network devices over time and receive alerts when thresholds are exceeded. Which protocol should be used?

Quick Answer

The answer is SNMP, or Simple Network Management Protocol. This protocol is the correct choice because it is specifically designed to collect performance data from network devices by polling objects stored in the Management Information Base (MIB), and it can generate traps or inform requests to send alerts when predefined thresholds are exceeded. On the CompTIA Network+ N10-009 exam, this question tests your understanding of how SNMP enables proactive monitoring and threshold-based alerting, often appearing alongside distractors like ICMP (used for reachability, not data collection) or Syslog (used for log aggregation, not polling). A common trap is confusing SNMP traps with Syslog messages—remember that SNMP traps are alert-driven and tied to MIB thresholds, while Syslog is a separate logging standard. For a quick memory tip: think of SNMP as the "Snoop" that polls and pings for performance, then "Traps" the threshold.

⚠ Common exam trap

Watch out — candidates often confuse syslog (which can also send alerts via log messages) with SNMP's dedicated alerting mechanism (traps/informs), but syslog lacks the structured polling and MIB-based threshold monitoring that SNMP provides for performance data collection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SNMP

SNMP (Simple Network Management Protocol) is designed to collect performance data from network devices by polling MIB (Management Information Base) objects and can generate traps or inform requests to send alerts when thresholds are exceeded. This makes it the correct choice for proactive monitoring and threshold-based alerting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • syslog

    Why it's wrong here

    Syslog is used for collecting log messages, not for performance metrics or alert thresholds.

    When this WOULD be correct

    A network administrator needs to centralize log messages from multiple devices for security auditing and troubleshooting. In that scenario, syslog is the correct protocol because it is designed for log collection and forwarding.

  • SNMP

    Why this is correct

    SNMP allows polling of MIB objects and sending traps when thresholds are exceeded.

  • NetFlow

    Why it's wrong here

    NetFlow provides traffic flow statistics but is not typically used for threshold-based alerts.

    When this WOULD be correct

    A network administrator wants to analyze traffic patterns, identify top talkers, or troubleshoot bandwidth utilization over time. NetFlow would be the correct choice for flow-level traffic data collection.

  • ICMP

    Why it's wrong here

    ICMP is used for ping and traceroute, not for continuous monitoring and alerts.

    When this WOULD be correct

    A question asking which protocol is used to test basic connectivity or measure round-trip time between devices would make ICMP correct, e.g., 'Which protocol does the ping command use?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

SNMPCorrect answer

Why this is correct

SNMP allows polling of MIB objects and sending traps when thresholds are exceeded.

syslogWrong answer — click to see why

Why this is wrong here

Syslog is used for collecting and forwarding log messages from network devices, not for polling performance metrics or setting threshold-based alerts. It lacks the structured data retrieval and alerting mechanisms that SNMP provides.

★ When this WOULD be the correct answer

A network administrator needs to centralize log messages from multiple devices for security auditing and troubleshooting. In that scenario, syslog is the correct protocol because it is designed for log collection and forwarding.

Why candidates choose this

Candidates may confuse syslog with SNMP because both are used for network monitoring, but syslog focuses on event logs while SNMP handles performance data and alerts.

NetFlowWrong answer — click to see why

Why this is wrong here

NetFlow is designed for traffic flow analysis and bandwidth monitoring, not for collecting performance metrics like CPU/memory usage or setting threshold-based alerts.

★ When this WOULD be the correct answer

A network administrator wants to analyze traffic patterns, identify top talkers, or troubleshoot bandwidth utilization over time. NetFlow would be the correct choice for flow-level traffic data collection.

Why candidates choose this

Candidates may confuse NetFlow's monitoring capabilities with general performance monitoring, or think it can generate alerts based on traffic thresholds, which is not its primary function.

ICMPWrong answer — click to see why

Why this is wrong here

ICMP is used for network diagnostics like ping and traceroute, not for collecting performance data over time or setting threshold-based alerts.

★ When this WOULD be the correct answer

A question asking which protocol is used to test basic connectivity or measure round-trip time between devices would make ICMP correct, e.g., 'Which protocol does the ping command use?'

Why candidates choose this

Candidates may confuse ICMP's role in network monitoring (e.g., ping for reachability) with the broader performance data collection and alerting capabilities of SNMP.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on N10-009

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A network administrator wants to be notified immediately when any interface on a core router goes down. The administrator has already configured SNMP community strings on the router. What additional configuration is necessary to receive these notifications?

medium
  • A.Enable SNMP polling from the NMS at regular intervals.
  • B.Configure an SNMP trap receiver on the NMS and set the router to send traps to that receiver.
  • C.Set up syslog to forward log messages to a centralized server.
  • D.Configure an access control list to allow the NMS to poll the router.

Why B: SNMP traps are unsolicited notifications sent from a managed device (the router) to a Network Management System (NMS) when a specific event occurs, such as an interface going down. Since the administrator already configured SNMP community strings (which provide authentication for SNMP messages), the missing piece is configuring the router to send traps to a specific trap receiver (the NMS) and ensuring the NMS is set up to listen for those traps. Without this trap receiver configuration, the router will not generate or forward the event-driven alerts.

Variation 2. A network administrator needs to be notified immediately when the CPU utilization on a core router exceeds 90%. Which SNMP mechanism should be configured on the router?

medium
  • A.SNMP get
  • B.SNMP trap
  • C.SNMP walk
  • D.SNMP set

Why B: B is correct because SNMP traps are unsolicited notifications sent from an SNMP agent (the router) to the manager when a predefined condition occurs, such as CPU utilization exceeding 90%. This allows immediate notification without waiting for the manager to poll, which is essential for urgent alerts.

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.