exam questions

Exam N10-008 All Questions

View all questions & answers for the N10-008 exam

Exam N10-008 topic 1 question 440 discussion

Actual exam question from CompTIA's N10-008
Question #: 440
Topic #: 1
[All N10-008 Questions]

A network administrator views a network pcap and sees a packet containing the following:



Which of the following are the BEST ways for the administrator to secure this type of traffic? (Choose two.)

  • A. Migrate the network to IPv6.
  • B. Implement 802.1 X authentication.
  • C. Set a private community string.
  • D. Use SNMPv3.
  • E. Incorporate SSL encryption.
  • F. Utilize IPSec tunneling.
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DumbTIA
Highly Voted 1 year, 1 month ago
Selected Answer: CD
This is not encrypted SNMP packet. Needs SNMPv3 & community string.
upvoted 8 times
...
Hchfyvggjg
Most Recent 8 months ago
Selected Answer: CD
C. Set a private community string. D. Use SNMPv3. C. Set a private community string: The "community: public" line indicates that the default community string "public" is being used for SNMP requests. This is a well-known community string that is often used for testing but should not be used in production environments. Changing the community string to a private, unique value is essential to prevent unauthorized access. Only devices with the correct community string can access SNMP data. D. SNMPv3: SNMPv3 is the most secure version of SNMP. It provides authentication, data integrity, and encryption features to protect SNMP traffic. By using SNMPv3, the administrator can ensure that SNMP traffic is secure and protected from unauthorized access and data tampering.
upvoted 4 times
...
ja1092m
8 months, 2 weeks ago
D and E snmpv3 dosent use community string V1 and v2 do. "Transport Layer Security is the next generation of Secure Sockets Layer (SSL) and has been added to the SNMPv3 architecture."
upvoted 1 times
...
Selected Answer: DF
Correct answers are D "Use SNMPv3" and F "Utilize IPSec tunneling". This is from CertMaster's The Official CompTIA Network+ Student Guide (p. 464): "For example, the original versions of SNMP are unencrypted. To implement secure SNMP, either configure SNMPv3, which supports encryption, or use an encapsulation protocol such as IPSec to encrypt SNMP traffic." The community (option C) is just like a password for SNMP, which in this case is the word "public". Setting a private community string does not make much sense.
upvoted 1 times
famco
1 year ago
Community string can be Private in SNMPv3
upvoted 1 times
famco
1 year ago
I apologize for the mistake in my previous comment. SNMPv3 does not use community string and therefore should bot be used along with SNMPv3 as option. I will go for SSL in addition to SNMPv3.
upvoted 5 times
...
...
...
StellarSteve
1 year, 1 month ago
C. Set a private community string and D. Use SNMPv3. the packet contains a community string of "public," which is the default community string for SNMPv1 and SNMPv2c. The administrator should set a private community string, which is a custom string used for SNMP authentication and authorization, to replace the default string.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago