PCNSA Device Management and Services Practice Question
A network administrator needs to configure SNMPv3 on a Palo Alto Networks firewall to allow a monitoring server to query interface statistics. The administrator wants to ensure that SNMP queries are authenticated and encrypted. Which SNMPv3 configuration is required to meet these requirements?
⚠ Common exam trap
The trap here is assuming that a priv password alone provides authentication, when it only provides encryption; both auth and priv passwords are needed for secure SNMPv3.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an SNMPv3 user with auth password and priv password, and assign a view that includes the interface statistics OIDs.
SNMPv3 requires both authentication and encryption to secure queries. This is achieved by configuring an SNMPv3 user with both an auth password and a priv password. Additionally, the user must be associated with a view that permits access to the specific OIDs needed, such as interface statistics. Using the default view with all OIDs is overly permissive and not recommended.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an SNMPv3 user with auth and priv passwords, and assign the default view that includes all OIDs.
Why it's wrong here
Assigning the default view that includes all OIDs would grant excessive access beyond just interface statistics. While it would technically allow the queries, it violates the principle of least privilege. The requirement is to allow queries for interface statistics, not all OIDs. Therefore, this option is not the best practice and is considered incorrect in this context.
- ✗
Create an SNMPv3 user with only an auth password, and assign a view that includes the interface statistics OIDs.
Why it's wrong here
While authentication is provided with an auth password, encryption is not enabled unless a priv password is also configured. The requirement states that queries must be authenticated and encrypted, so this option fails to meet the encryption requirement. Therefore, it is incorrect.
- ✓
Create an SNMPv3 user with auth password and priv password, and assign a view that includes the interface statistics OIDs.
Why this is correct
SNMPv3 provides authentication and encryption through the use of auth and priv passwords. To allow queries for interface statistics, you must create a user with these credentials and assign a view that grants access to the relevant MIB objects. This configuration ensures both security and access to the required data.
- ✗
Create an SNMPv3 user with only a priv password, and assign a view that includes the interface statistics OIDs.
Why it's wrong here
A priv password alone does not provide authentication; it only provides encryption. SNMPv3 requires both authentication and encryption for secure queries. Without an auth password, the user cannot authenticate, and the queries will fail. Thus, this option does not meet the requirements.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.