Soru

Zorluk: ZorNetwork Performance Monitoring and Metrics

A network security administrator is tasked with updating the network management baseline across all edge routers. The monitoring platform must collect hardware health parameters, such as CPU utilization and temperature metrics, while strictly enforcing packet payload encryption and cryptographic user authentication across the wire. Which configuration choice best satisfies these security and operational requirements?

  1. Configure SNMPv3 on all routers using the authPriv security level with USM enabled.Cevap
  2. B
    Configure SNMPv3 on all routers using the authNoPriv security level with community strings.
  3. C
    Configure SNMPv2c using read-only community strings protected by transport-layer SSL/TLS.
  4. D
    Configure NetFlow v9 to stream device environmental metrics using TCP port 161.

Cevap

Configure SNMPv3 on all routers using the authPriv security level with USM enabled.
SNMPv3 with the authPriv security level implements the User-based Security Model (USM), providing both strong HMAC-based user authentication and payload encryption (such as AES) for device health and performance monitoring.

Adım Adım Çözüm

1
Identify required performance monitoring features
The requirements call for polling device metrics (CPU utilization and temperature) with user authentication and payload encryption.
Determines protocol capabilities necessary for device status polling vs flow analysis.
2
Evaluate SNMP version capabilities
SNMPv1 and SNMPv2c use cleartext community strings. SNMPv3 introduces User-based Security Model (USM).
Eliminates legacy SNMP protocols that lack strong cryptographic security.
3
Determine the correct SNMPv3 security level
The authPriv level guarantees both cryptographic user authentication (HMAC-SHA/MD5) and encryption of packet contents (AES/DES).
Fulfills both security mandates (authentication + privacy/encryption).

Anahtar Kavram

SNMPv3 Security Levels and Network Telemetry
Bu soruyu puanla