Courseiva
Network OperationshardMultiple ChoiceObjective-mapped

N10-009 Network Operations Practice Question

An organization is implementing a network monitoring solution that uses SNMP. The administrator wants to receive traps from all devices but is concerned about the security of SNMPv1/v2c community strings. Which SNMP version should be used to provide authentication and encryption?

⚠ Common exam trap

CompTIA often tests the misconception that SNMPv2c offers improved security over SNMPv1, but in reality, both v1 and v2c are equally insecure because they use plaintext community strings, while SNMPv3 is the only version that provides authentication and encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SNMPv3

SNMPv3 is the correct choice because it is the only version of SNMP that provides both authentication and encryption, addressing the security concerns with SNMPv1/v2c community strings. SNMPv3 supports user-based security models (USM) with features like message integrity, authentication, and encryption (e.g., using SHA/MD5 for auth and AES/DES for privacy). This ensures that traps are sent securely, preventing unauthorized access or tampering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • SNMPv1

    Why it's wrong here

    SNMPv1 is fundamentally insecure for network monitoring as it transmits all information, including community strings (passwords), in plaintext over the network. It offers no mechanisms for authentication, data integrity, or encryption, making it highly susceptible to eavesdropping, unauthorized access, and tampering. Using SNMPv1 in any production environment poses significant security risks, as network devices can be easily queried or controlled by malicious actors.

    When this WOULD be correct

    When the question asks for the most basic SNMP version for simple monitoring on a trusted, isolated network with no security requirements.

  • SNMPv2c

    Why it's wrong here

    SNMPv2c, while an improvement over SNMPv1 in terms of data types and operations, still relies on plaintext community strings for authentication. These community strings function as unencrypted passwords, making SNMP traffic vulnerable to eavesdropping and unauthorized access if intercepted. Consequently, SNMPv2c lacks the strong security mechanisms necessary to protect sensitive network information in untrusted network segments.

    When this WOULD be correct

    A question asking for a simple, low-overhead SNMP version for read-only monitoring on a trusted internal network where security is not a concern and compatibility with older devices is required.

  • SNMPv3

    Why this is correct

    SNMPv3 is the correct choice for secure network monitoring because it incorporates robust security features, including authentication, integrity, and encryption. It utilizes a User-based Security Model (USM) to provide message integrity, data origin authentication, replay protection, and privacy through encryption. This version ensures that sensitive network management data is protected from eavesdropping and unauthorized tampering, making it suitable for modern, security-conscious environments.

  • SNMPv4

    Why it's wrong here

    SNMPv4 is not a recognized or standardized version of the Simple Network Management Protocol. After SNMPv3 was introduced with its comprehensive security enhancements, the development efforts shifted towards refining and extending SNMPv3 rather than creating a new major version. Therefore, any reference to SNMPv4 in a practical or certification context is erroneous, as SNMPv3 remains the most current and secure standard.

    When this WOULD be correct

    If the question asked about the latest SNMP version that includes security features, but mistakenly listed SNMPv4 as an option, it would be correct only if the exam accepted a non-existent version. However, in reality, no such scenario exists.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

SNMPv3Correct answer

Why this is correct

SNMPv3 is the correct choice for secure network monitoring because it incorporates robust security features, including authentication, integrity, and encryption. It utilizes a User-based Security Model (USM) to provide message integrity, data origin authentication, replay protection, and privacy through encryption. This version ensures that sensitive network management data is protected from eavesdropping and unauthorized tampering, making it suitable for modern, security-conscious environments.

SNMPv1Wrong answer — click to see why

Why this is wrong here

SNMPv1 does not provide authentication or encryption; it uses plaintext community strings, which does not address the security concern in the question.

★ When this WOULD be the correct answer

When the question asks for the most basic SNMP version for simple monitoring on a trusted, isolated network with no security requirements.

Why candidates choose this

Candidates may think SNMPv1 is sufficient because it is widely known and simple, overlooking the security requirements specified in the question.

SNMPv2cWrong answer — click to see why

Why this is wrong here

SNMPv2c does not provide authentication or encryption; it uses plaintext community strings for access control, which is insecure.

★ When this WOULD be the correct answer

A question asking for a simple, low-overhead SNMP version for read-only monitoring on a trusted internal network where security is not a concern and compatibility with older devices is required.

Why candidates choose this

Candidates may confuse SNMPv2c's improved error handling and bulk retrieval with security enhancements, or they may think 'v2c' is more secure than v1 without realizing it still lacks encryption.

SNMPv4Wrong answer — click to see why

Why this is wrong here

SNMPv4 does not exist as a standard SNMP version; the current secure version is SNMPv3. The question specifically asks for authentication and encryption, which only SNMPv3 provides.

★ When this WOULD be the correct answer

If the question asked about the latest SNMP version that includes security features, but mistakenly listed SNMPv4 as an option, it would be correct only if the exam accepted a non-existent version. However, in reality, no such scenario exists.

Why candidates choose this

Candidates may assume that higher version numbers always mean better security, leading them to choose SNMPv4 without verifying its existence or capabilities.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.