N10-009 Network Operations Practice Question
An organization is implementing a network monitoring solution that uses SNMP. The administrator wants to receive traps from all devices but is concerned about the security of SNMPv1/v2c community strings. Which SNMP version should be used to provide authentication and encryption?
⚠ Common exam trap
CompTIA often tests the misconception that SNMPv2c offers improved security over SNMPv1, but in reality, both v1 and v2c are equally insecure because they use plaintext community strings, while SNMPv3 is the only version that provides authentication and encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SNMPv3
SNMPv3 is the correct choice because it is the only version of SNMP that provides both authentication and encryption, addressing the security concerns with SNMPv1/v2c community strings. SNMPv3 supports user-based security models (USM) with features like message integrity, authentication, and encryption (e.g., using SHA/MD5 for auth and AES/DES for privacy). This ensures that traps are sent securely, preventing unauthorized access or tampering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SNMPv1
Why it's wrong here
SNMPv1 is fundamentally insecure for network monitoring as it transmits all information, including community strings (passwords), in plaintext over the network. It offers no mechanisms for authentication, data integrity, or encryption, making it highly susceptible to eavesdropping, unauthorized access, and tampering. Using SNMPv1 in any production environment poses significant security risks, as network devices can be easily queried or controlled by malicious actors.
When this WOULD be correct
When the question asks for the most basic SNMP version for simple monitoring on a trusted, isolated network with no security requirements.
- ✗
SNMPv2c
Why it's wrong here
SNMPv2c, while an improvement over SNMPv1 in terms of data types and operations, still relies on plaintext community strings for authentication. These community strings function as unencrypted passwords, making SNMP traffic vulnerable to eavesdropping and unauthorized access if intercepted. Consequently, SNMPv2c lacks the strong security mechanisms necessary to protect sensitive network information in untrusted network segments.
When this WOULD be correct
A question asking for a simple, low-overhead SNMP version for read-only monitoring on a trusted internal network where security is not a concern and compatibility with older devices is required.
- ✓
SNMPv3
Why this is correct
SNMPv3 is the correct choice for secure network monitoring because it incorporates robust security features, including authentication, integrity, and encryption. It utilizes a User-based Security Model (USM) to provide message integrity, data origin authentication, replay protection, and privacy through encryption. This version ensures that sensitive network management data is protected from eavesdropping and unauthorized tampering, making it suitable for modern, security-conscious environments.
- ✗
SNMPv4
Why it's wrong here
SNMPv4 is not a recognized or standardized version of the Simple Network Management Protocol. After SNMPv3 was introduced with its comprehensive security enhancements, the development efforts shifted towards refining and extending SNMPv3 rather than creating a new major version. Therefore, any reference to SNMPv4 in a practical or certification context is erroneous, as SNMPv3 remains the most current and secure standard.
When this WOULD be correct
If the question asked about the latest SNMP version that includes security features, but mistakenly listed SNMPv4 as an option, it would be correct only if the exam accepted a non-existent version. However, in reality, no such scenario exists.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓SNMPv3Correct answer▾
Why this is correct
SNMPv3 is the correct choice for secure network monitoring because it incorporates robust security features, including authentication, integrity, and encryption. It utilizes a User-based Security Model (USM) to provide message integrity, data origin authentication, replay protection, and privacy through encryption. This version ensures that sensitive network management data is protected from eavesdropping and unauthorized tampering, making it suitable for modern, security-conscious environments.
✗SNMPv1Wrong answer — click to see why▾
Why this is wrong here
SNMPv1 does not provide authentication or encryption; it uses plaintext community strings, which does not address the security concern in the question.
★ When this WOULD be the correct answer
When the question asks for the most basic SNMP version for simple monitoring on a trusted, isolated network with no security requirements.
Why candidates choose this
Candidates may think SNMPv1 is sufficient because it is widely known and simple, overlooking the security requirements specified in the question.
✗SNMPv2cWrong answer — click to see why▾
Why this is wrong here
SNMPv2c does not provide authentication or encryption; it uses plaintext community strings for access control, which is insecure.
★ When this WOULD be the correct answer
A question asking for a simple, low-overhead SNMP version for read-only monitoring on a trusted internal network where security is not a concern and compatibility with older devices is required.
Why candidates choose this
Candidates may confuse SNMPv2c's improved error handling and bulk retrieval with security enhancements, or they may think 'v2c' is more secure than v1 without realizing it still lacks encryption.
✗SNMPv4Wrong answer — click to see why▾
Why this is wrong here
SNMPv4 does not exist as a standard SNMP version; the current secure version is SNMPv3. The question specifically asks for authentication and encryption, which only SNMPv3 provides.
★ When this WOULD be the correct answer
If the question asked about the latest SNMP version that includes security features, but mistakenly listed SNMPv4 as an option, it would be correct only if the exam accepted a non-existent version. However, in reality, no such scenario exists.
Why candidates choose this
Candidates may assume that higher version numbers always mean better security, leading them to choose SNMPv4 without verifying its existence or capabilities.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Network Documentation and Diagrams
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
AES
AES is a fast and secure encryption standard used worldwide to protect sensitive data by scrambling it so only authorized parties can read it.
About these practice questions
Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.