SNMP Enumeration Countermeasures
Which TWO of the following are effective countermeasures against SNMP enumeration attacks? (Select 2)
Quick Answer
The answer is to change default community strings to strong, unique values and restrict SNMP access to trusted IP addresses using ACLs. These two countermeasures directly address the core vulnerability in SNMP enumeration attacks: the use of default “public” and “private” community strings, which act as weak passwords that attackers can guess to query device information. By setting complex, unique strings, you prevent brute-force guessing, while ACLs limit which hosts can even send those queries, effectively shrinking the attack surface. On the Certified Ethical Hacker CEH exam, this topic tests your understanding of network reconnaissance defenses, often appearing in questions that contrast secure configuration with insecure defaults. A common trap is assuming encryption alone suffices—SNMPv3 encryption does not help if weak community strings are still accepted. Remember the mnemonic “Strong Strings, Strict Sources” to recall that both the authentication credential and the network access control must be hardened together.
⚠ Common exam trap
Candidates often select 'Disable SNMP' (option B) as a universal solution, but the CEH exam expects recognition that SNMP is often necessary for monitoring; realistic countermeasures are restrictive ACLs and strong community strings. Also, avoid confusing 'changing community strings' alone as sufficient—ACLs are equally important.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restrict SNMP access to trusted IP addresses using ACLs
Option A is correct because applying ACLs to restrict SNMP access to trusted IP addresses limits who can query the SNMP agent, preventing unauthorized enumeration from untrusted hosts. Option C is correct because changing default community strings (such as 'public' and 'private') to strong, unique values removes the easily guessed credentials that attackers use to enumerate SNMP data. Option B is not the best countermeasure because disabling SNMP entirely is impractical in environments where it is needed for legitimate monitoring and management. Option D is incorrect because enabling SNMPv3 with default passwords still leaves weak, guessable credentials that undermine SNMPv3's security features. Option E is incorrect because SNMPv1 with the community string 'private' uses a well-known default credential and lacks encryption and strong authentication, making enumeration easier.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Restrict SNMP access to trusted IP addresses using ACLs
Why this is correct
ACLs limit which source addresses may query the SNMP agent, so unauthorised hosts cannot reach UDP port 161 to harvest community strings, device details or routing tables. This directly satisfies the stem's requirement to block enumeration by restricting access to trusted management stations only.
- ✗
Disable SNMP on all devices
Why it's wrong here
Disabling SNMP outright removes the enumeration vector, but the scenario requires countermeasures that retain monitoring capability, so it fails the operational requirement. It is tempting because decommissioning the service is genuinely the strongest hardening step where no management platform depends on it — for example, on isolated hosts with no SNMP-based monitoring.
- ✓
Change default community strings to strong, unique values
Why this is correct
Replacing default community strings with strong, unique values defeats SNMP enumeration because attackers rely on well-known defaults such as "public" and "private" to query MIB objects and harvest device, user and network data. This directly satisfies the stem's countermeasure requirement by removing the predictable read credential that makes enumeration trivial.
- ✗
Enable SNMPv3 with default passwords
Why it's wrong here
SNMPv3 with default passwords leaves the community-string weakness intact, since default credentials are publicly known and trivially guessed. SNMPv3 is tempting because it adds authentication and encryption, but only when strong, unique credentials are configured; leaving defaults enabled defeats the entire purpose of the upgrade.
- ✗
Use SNMPv1 with community string 'private'
Why it's wrong here
Incorrect: Using SNMPv1 with the community string 'private' is a default configuration that attackers know; it offers no security and actually facilitates enumeration.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CEH question from scratch — 913 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security auditor runs SNMPwalk against a network device using the default community string 'public' and obtains extensive system information. Which THREE of the following are effective countermeasures to prevent unauthorized SNMP enumeration?
hard- A.Disable SNMP entirely on all devices
- ✓ B.Implement an access control list (ACL) limiting SNMP access to management hosts
- C.Set the community string to 'private' for read-only access
- ✓ D.Change the community string from 'public' to a complex string
- ✓ E.Upgrade SNMP to version 3 with authentication and encryption
Why B: Option B is correct because an ACL restricting SNMP access to specific management host IP addresses prevents unauthorized hosts from querying the SNMP agent, blocking enumeration from untrusted sources. Option D is correct because changing the default 'public' community string to a complex, non-guessable value removes the trivially known credential that allowed the auditor's SNMPwalk to succeed. Option E is correct because SNMPv3 with authentication (authNoPriv/authPriv) and encryption (priv) eliminates cleartext community-string authentication and provides cryptographic verification of users, preventing unauthorized enumeration. Option A, while it would stop SNMP enumeration, is not an effective general countermeasure since it disables legitimate management/monitoring functionality rather than securing it. Option C is incorrect because 'private' is itself a well-known default community string and using it for read-only access still leaves the device vulnerable to trivial enumeration.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.