N10-009 Network Operations Practice Question
A network administrator is setting up SNMPv3 on a router for secure monitoring. Which of the following is required for SNMPv3 authentication?
⚠ Common exam trap
Test-takers frequently confuse the community string (SNMPv1/v2c) with SNMPv3's username/password model, or they mistakenly think an encryption key alone satisfies authentication requirements, when in fact authentication and privacy are configured independently.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Username and password
SNMPv3 introduces a security model that requires a username and password (authentication passphrase) for authentication, moving away from the community-string-based model of SNMPv1/v2c. The password is used with an authentication protocol like MD5 or SHA to verify the identity of the manager before allowing access. Without a valid username and password combination, SNMPv3 will reject the request.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Community string
Why it's wrong here
Community strings serve as a rudimentary form of authentication in SNMPv1 and SNMPv2c, acting like a shared secret plaintext password for read-only or read-write access to MIB objects. However, they offer no encryption and are transmitted unencrypted over the network, making them highly insecure and susceptible to eavesdropping. SNMPv3 completely abandons community strings in favor of robust user-based security models.
When this WOULD be correct
In a question about configuring SNMPv2c for read-only access on a legacy device, the community string would be the correct authentication method.
- ✓
Username and password
Why this is correct
SNMPv3 significantly enhances security over previous versions by introducing user-based security. For authentication, it mandates the configuration of a unique username along with an authentication password (or passphrase). This password is not transmitted directly but is used to generate a cryptographic hash, such as MD5 or SHA, which verifies the integrity and origin of the SNMP message, preventing unauthorized access and tampering.
- ✗
Encryption key
Why it's wrong here
An encryption key in SNMPv3 is specifically utilized for privacy, which involves encrypting the payload of SNMP messages to protect sensitive data from being read by unauthorized parties during transmission. While crucial for data confidentiality, this key is distinct from the authentication mechanism. Authentication, which uses a password to generate a hash, ensures message integrity and origin verification, operating independently of the encryption process.
When this WOULD be correct
A question asking 'Which of the following is required for SNMPv3 privacy?' would make encryption key the correct answer, as privacy ensures data encryption using a separate key.
- ✗
Public key
Why it's wrong here
SNMPv3 authentication relies on symmetric-key cryptography, specifically using a shared secret (derived from the password) to generate a hash for message integrity and origin verification. It does not employ public-key cryptography, which involves a pair of mathematically linked public and private keys, for its authentication mechanism. Public-key infrastructure (PKI) is not integrated into the standard SNMPv3 security model for user authentication.
When this WOULD be correct
A question about configuring SSH or TLS for secure device management, where public key authentication is required (e.g., 'Which of the following is needed for SSH key-based authentication?').
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓Username and passwordCorrect answer▾
Why this is correct
SNMPv3 significantly enhances security over previous versions by introducing user-based security. For authentication, it mandates the configuration of a unique username along with an authentication password (or passphrase). This password is not transmitted directly but is used to generate a cryptographic hash, such as MD5 or SHA, which verifies the integrity and origin of the SNMP message, preventing unauthorized access and tampering.
✗Community stringWrong answer — click to see why▾
Why this is wrong here
SNMPv3 uses a username and password for authentication, not a community string. Community strings are used in SNMPv1 and v2c, which lack security.
★ When this WOULD be the correct answer
In a question about configuring SNMPv2c for read-only access on a legacy device, the community string would be the correct authentication method.
Why candidates choose this
Candidates often confuse SNMPv3 with earlier versions, mistakenly thinking community strings are still used for authentication in v3.
✗Encryption keyWrong answer — click to see why▾
Why this is wrong here
SNMPv3 authentication uses a username and password (or passphrase), not an encryption key. Encryption keys are used for SNMPv3 privacy (encryption), not authentication.
★ When this WOULD be the correct answer
A question asking 'Which of the following is required for SNMPv3 privacy?' would make encryption key the correct answer, as privacy ensures data encryption using a separate key.
Why candidates choose this
Candidates may confuse authentication with encryption, thinking that a key is needed for both, or they may associate 'security' with encryption keys rather than authentication credentials.
✗Public keyWrong answer — click to see why▾
Why this is wrong here
SNMPv3 authentication uses a username and password (or passphrase) via HMAC-MD5 or HMAC-SHA, not a public key. Public keys are used in asymmetric cryptography, which is not part of SNMPv3's authentication mechanism.
★ When this WOULD be the correct answer
A question about configuring SSH or TLS for secure device management, where public key authentication is required (e.g., 'Which of the following is needed for SSH key-based authentication?').
Why candidates choose this
Candidates may confuse SNMPv3's security features with other secure protocols that use public key cryptography, or assume that 'secure' always implies asymmetric encryption.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Network Documentation and Diagrams
Key term
PSK
A pre-shared key (PSK) is a secret string of characters shared in advance between two parties to authenticate and encrypt wireless or VPN communications.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.