Cisco CCNA (200-301)IP ServicesEasy

A network administrator needs to enable SNMP on a Cisco router to allow a network management system (NMS) to monitor its performance and status. The NMS should only be able to read system information and should not be able to make configuration changes. Which command snippet correctly configures this requirement?

  1. Asnmp-server community private ro
  2. Bsnmp-server community public ro
  3. Csnmp-server community public rw
  4. Dsnmp-server enable traps
Show answer & explanation

Correct answer: B. snmp-server community public ro

The 'snmp-server community public ro' command configures an SNMP community string named 'public' with read-only (ro) access, which prevents the NMS from making configuration changes while allowing monitoring.

Why the other options are wrong

  • A. This uses 'private' as the community string, which is generally used for read-write access, and while 'ro' is specified, 'public' is a more common read-only string.
  • C. This configures a read-write (rw) community, which allows configuration changes, violating the requirement.
  • D. This command enables SNMP traps, which are notifications sent by the router, but does not configure the community string for NMS polling.

Cisco IOS SNMP Read-Only Community

Configuring a read-only SNMP community string on a Cisco device allows network management systems to retrieve device information without permission to modify its configuration.

  • Community string acts as a password.
  • 'ro' specifies read-only access.
  • 'rw' specifies read-write access (less secure for monitoring).

Memory trick: Community string is like a password, 'ro' is for 'Read Only'.

More IP Services questions