ETExamTower
Q18Network Security

A network engineer configured the command `snmp-server user andy myv3 auth sha cisco priv aes 256 cisc0383320506` and must send SNMP information to a host at `10.255.254.1`. Which command accomplishes this?

← → navigate · a answer
Community votes
D
100% (4)
A
0% (0)
B
0% (0)
C
0% (0)
Discussion · 14
23
Correct answer is D See: https://www.networkstraining.com/how-to-configure-snmp-on-cisco-asa-5500-firewall/ And: https://www.cisco.com/c/en/us/td/docs/security/asa/snmp/snmpv3_tools/snmpv3_1.html
4
You tie the SNMP host config to a user, not a group. D is the correct answer
D 4
Selected Answer: D D is correct
3
Configuration Example of SNMP v3 At present, the most secure SNMP version is v3. To configure it, you first need to create an SNMP group, then an SNMP server, and finally a host (NMS) that will communicate with the firewall for management purposes. Let’s configure SNMP v3 with the example below: ASA(config)# snmp-server enable ASA(config)# snmp-server group snmpgroup v3 auth <- create v3 group with authentication ASA(config)# snmp-server user administrator snmpgroup v3 auth sha strongpass <- create user “administrator” belonging to group “snmpgroup” ASA(config)#snmp-server host inside 10.1.1.1 version 3 administrator <- specify the NMS host Correct answer is D, administrator here is equal to andy
D 3
Selected Answer: D ASA(config)# snmp-server host inside 10.255.254.1 version 3 ? configure mode commands/options: Current available user name(s): ASA(config)# snmp-server host inside 10.255.254.1 version 3 andy it requires "Current available user name(s):" so D is correct
3
** CORRECT answer is D *** snmp-server host interface { hostname | ip_address } [ trap | poll ] [ community community-string ] [ version { 1 | 2c | 3 username }] [ udp-port port ]
2
100% D For community-string, when version 1 or version 2c is specified, enter the password-like community string sent with the notification operation. When version 3 is specified, enter the SNMPv3 username https://www.cisco.com/c/en/us/td/docs/routers/ir910/software/release/1_1/configuration/guide/ir910scg/swsnmp.html
2
The correct answer is D
2
Answer D is correct. snmp-server enable traps ! ! …or instead choose only some traps, for example: ! snmp-server enable traps envmon fan shutdown supply temperature status ospf cpu ! snmp-server group trapgroup v3 priv snmp-server user trapuser trapgroup v3 auth sha AuthPass priv 3des PrivPass snmp-server host 10.1.1.161 traps version 3 priv trapuser
1
B is correct myv3 is the host, Andy is an user on host myv3
1
An attempt to add the SNMP server with the command on the ASA firewall: See what the firewall expects as input fw(config)# snmp-server host inside 172.16.0.94 ver 3 ? configure mode commands/options: Current available user name(s): snmpuser
1
myv3 is the snmp v3 group name. D is the correct answer
D 1
Selected Answer: D D is correct
1
https://www.cisco.com/c/en/us/td/docs/security/asa/asa-cli-reference/S/asa-command-ref-S/m_shox-sn.html#wp1203427780 D