N10-009 exam dumps

N10-009 practice question 204 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 204

Single answerMethods: SNMP (Traps, Management information base (MIB), Versions (v2c, v3), Community strings, Authentication)

A network administrator is deploying centralized monitoring for branch-office routers across an untrusted WAN. The monitoring platform must receive immediate alerts when an interface goes down, and the security team has required that management traffic use authentication and encryption. During testing, the administrator can poll basic device statistics, but link-down alerts are not arriving at the monitoring server. Which action should the administrator take NEXT to meet the requirements and resolve the alerting issue?

  1. A

    Configure SNMPv3 notifications on the routers to send traps to the monitoring server with the correct user and authentication/privacy settings

  2. B

    Change the routers to SNMPv2c and configure a read-write community string so traps can be encrypted

  3. C

    Update the MIB files on the routers so the devices can authenticate to the monitoring server before sending traps

  4. D

    Enable NetFlow export on the routers because interface-down events are delivered through flow records instead of SNMP traps

Show answer and explanation

Correct answer: A

Explanation

This question tests the candidate's ability to distinguish among SNMP polling, traps, MIB usage, and version/security capabilities in a realistic monitoring deployment. Immediate event-driven alerts are handled by SNMP traps (or informs), not by periodic polling alone. Because the requirement includes both authentication and encryption over an untrusted WAN, SNMPv3 is the correct choice; SNMPv1 and SNMPv2c rely on community strings and do not provide cryptographic security. The MIB is important for understanding and decoding monitored data, but it does not provide authentication or trigger alert transmission. In practice, best practice is to use SNMPv3 with authPriv when confidentiality is required, configure the NMS as the trap receiver, and ensure the proper user/security parameters match on both ends. These behaviors align with standard SNMP operational guidance and common vendor documentation for secure network monitoring.

  • A. Correct.

    Correct. The scenario requires immediate alerts, which are best handled with SNMP traps/notifications rather than relying only on polling. Because the security requirement specifies authentication and encryption across an untrusted WAN, SNMPv3 is the appropriate version. The administrator should configure the routers to send traps to the monitoring server using the correct SNMPv3 security parameters, including the user, authentication method, and privacy (encryption) settings. Polling can work separately, but traps must be explicitly configured and directed to the manager.

  • B. Incorrect.

    Incorrect. SNMPv2c uses community strings, but those community strings are essentially shared clear-text credentials and do not provide encryption or strong authentication. A read-write community string would also be unnecessarily risky for monitoring. This option reflects a common misconception that community strings provide secure authentication and that SNMPv2c traps can be encrypted; they cannot.

  • C. Incorrect.

    Incorrect. MIB files define the structure and meaning of managed objects so that the management station can interpret OIDs and values. Updating a MIB does not enable authentication between devices and a monitoring server, nor does it by itself make a router send traps. This distractor targets the misconception that the MIB is an authentication or connectivity mechanism rather than a database/schema for SNMP-managed objects.

  • D. Incorrect.

    Incorrect. NetFlow is used for traffic-flow analysis, accounting, and visibility into conversations and bandwidth usage. It does not replace SNMP traps for standard interface link-up/link-down event notifications. While NetFlow may complement monitoring, it does not solve the immediate problem of authenticated, encrypted alert delivery for interface status changes.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam