N10-009 exam dumps

N10-009 practice question 69 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 69

Single answerSNMP: 161/162

A network administrator deploys a monitoring server to collect interface statistics and receive immediate alerts from managed switches across the LAN. After a firewall change, the monitoring server can still poll switch counters successfully, but it no longer receives link-down notifications when a switch port fails. Which firewall change is the MOST likely needed to restore the missing alerts?

  1. A

    Allow inbound UDP 162 to the monitoring server from the switches

  2. B

    Allow inbound TCP 161 to the monitoring server from the switches

  3. C

    Allow outbound UDP 162 from the monitoring server to the switches

  4. D

    Allow inbound UDP 161 to the monitoring server from the switches

Show answer and explanation

Correct answer: A

Explanation

SNMP commonly uses UDP port 161 for polling operations between a network management station and managed devices, and UDP port 162 for asynchronous notifications such as traps and informs sent from devices to the management station. In the scenario, the monitoring server can still collect interface statistics, which indicates SNMP polling on port 161 is operational. However, link-down notifications are event-driven alerts, so the likely cause is that UDP 162 inbound to the monitoring server is blocked. This aligns with standard SNMP behavior documented in networking references and vendor best practices for network monitoring deployments.

  • A. Correct.

    Correct. SNMP traps and informs are sent from managed devices to the network management system on UDP port 162. In this scenario, polling still works, which indicates SNMP queries on port 161 are functioning. The missing link-down notifications point specifically to blocked trap traffic destined for the monitoring server on UDP 162.

  • B. Incorrect.

    Incorrect. Standard SNMP polling uses UDP, not TCP, and the common polling port is 161 rather than 162. Choosing this option reflects the misconception that SNMP management traffic uses TCP like many application protocols.

  • C. Incorrect.

    Incorrect. The problem is that the monitoring server is not receiving unsolicited alerts from switches. Traps are initiated by the switches and sent to the server, so the key requirement is inbound access to the server on UDP 162, not outbound access from the server.

  • D. Incorrect.

    Incorrect. UDP 161 is used for SNMP queries and responses, typically when the monitoring server polls devices for statistics. Since polling already works, port 161 is evidently not the issue. This option confuses polling traffic with trap traffic.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam