SNMPv3 Configuration: Three Required Items
An administrator is configuring SNMP on a FortiGate for monitoring. Which THREE items are required for SNMPv3 configuration?
Quick Answer
The answer is an SNMP user with a username and authentication password, a security level, and an SNMP community or host access configuration. These three items are required for SNMPv3 configuration on a FortiGate because SNMPv3 shifts from the community-string model of earlier versions to a user-based security model (USM). The security level—whether authNoPriv or authPriv—is mandatory because it dictates whether authentication alone or both authentication and encryption are enforced for that user, directly controlling the integrity and confidentiality of SNMP communications. On the Fortinet NSE 4 Network Security Professional exam, this question tests your grasp of SNMPv3’s mandatory parameters versus optional ones; a common trap is forgetting the security level, as many candidates assume only a user and password suffice. Remember the mnemonic “U-S-C”: User (with credentials), Security level, and Community/host access—all three must be set for SNMPv3 to function.
⚠ Common exam trap
Many exam-takers confuse SNMPv3 with SNMPv2c and incorrectly select the community string option, forgetting that SNMPv3 eliminates community strings in favor of user-based authentication and encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security level (authPriv or authNoPriv)
For SNMPv3 on a FortiGate, the security level (Option A) must be specified because SNMPv3 defines whether messages are authenticated only (authNoPriv) or both authenticated and encrypted (authPriv), which directly determines the security mechanisms applied to the user. Option B is required because SNMPv3 authentication uses a hash protocol such as SHA (or MD5) and privacy uses an encryption protocol such as AES (or DES); these protocol selections must be configured alongside the passwords to build the user's security parameters. Option E is required because SNMPv3 is user-based rather than community-based, so an SNMP user must be created with a username and authentication password (and, when authPriv is used, a privacy password) before the FortiGate can respond to SNMPv3 queries. Option C is not required for basic SNMPv3 configuration because views are optional MIB access restrictions, not mandatory parameters for creating an SNMPv3 user. Option D is incorrect because community strings apply to SNMPv1 and SNMPv2c, not to SNMPv3, which replaces communities with users and security levels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security level (authPriv or authNoPriv)
Why this is correct
SNMPv3 adds USM security levels. Choosing authPriv enforces both authentication and encryption, while authNoPriv enforces authentication only. The security level is mandatory because it determines which credential fields must be supplied for the SNMPv3 user.
- ✓
Authentication protocol (e.g., SHA) and privacy protocol (e.g., AES)
Why this is correct
SNMPv3 requires both an authentication protocol, such as SHA or MD5, to verify the sender's identity, and a privacy protocol, such as AES or DES, to encrypt payloads. These pair with the security level to define how each SNMPv3 user's credentials are applied.
- ✗
SNMP view definition for the user
Why it's wrong here
SNMPv3 authenticates and encrypts per-user with a security level, so a view is optional unless you restrict OIDs; the required trio is user, authentication, and privacy settings. A view would be correct when granular OID access control is needed for that user.
- ✗
SNMP community string (read-only or read-write)
Why it's wrong here
Community strings belong to SNMPv1 and v2c, where they act as the sole shared-secret credential; SNMPv3 replaces them with user-based authentication and privacy. A community string is correct when configuring v1 or v2c monitoring, not v3.
- ✓
SNMP user with username and authentication password
Why this is correct
SNMPv3 requires a defined user with a username and authentication password, satisfying the credential-based security model that distinguishes v3 from v1/v2c community strings. Without this user entry, the FortiGate cannot authenticate polling requests, so the SNMP manager receives no responses.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A network administrator is configuring SNMP on a FortiGate for monitoring. Which three pieces of information are required to complete the SNMPv2c configuration? (Choose THREE.)
medium- A.SNMPv3 authentication protocol (MD5/SHA)
- ✓ B.SNMP manager IP address (allowed hosts)
- C.SNMP trap receiver IP and community
- ✓ D.SNMP community string
- ✓ E.SNMP interface (the interface that will respond to SNMP queries)
Why B: SNMPv2c uses community-based security, so the SNMP community string (Option D) is required for authentication. The SNMP manager IP address (Option B) is needed to define which hosts are allowed to query the FortiGate. The SNMP interface (Option E) specifies which network interface will listen for and respond to SNMP queries. These three pieces are mandatory for SNMPv2c configuration on a FortiGate.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.