Simple Network Management Protocol (SNMP)
A protocol for monitoring and configuring network devices: managers query agents for values and agents send alerts. Versions 1 and 2c authenticate only with cleartext community strings.
The Simple Network Management Protocol (SNMP) lets a management station monitor and adjust network devices. Each device runs an agent that exposes values, such as interface counters, in a Management Information Base. The manager polls agents for these values, usually on UDP port 161, can write new values where write access is allowed, and receives unsolicited alerts, called traps or notifications, when something changes.
Security depends on the version. SNMPv1 and SNMPv2c identify the caller only by a community string, a shared value sent in clear text with every request, often left at well-known defaults. Anyone who captures or guesses a community string with write access can reconfigure the device. SNMPv3, whose framework is defined in RFC 3411 to RFC 3418, adds a User-based Security Model (RFC 3414) with message authentication and encryption. Because some replies are much larger than the request, exposed agents have also been abused for reflection and amplification attacks. Good practice is to use SNMPv3, restrict agents to a dedicated management network or out-of-band management path, and disable write access where it is not needed.
Exam relevance: a scenario about securing device monitoring, or one in which an attacker read device configuration from a default community string, is likely to turn on SNMP versions. Candidates are expected to know that, of the versions in common use, only SNMPv3 offers authentication and encryption.