Courseiva
Infrastructure →hardMultiple Choice

CCNP Infrastructure Practice Question

A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The engineer wants to ensure that only routers with the correct key can form adjacencies, and that the key is not sent in clear text. Which command sequence correctly enables MD5 authentication on an interface?

⚠ Common exam trap

Test-takers frequently confuse plaintext authentication with MD5, or using area-wide authentication when interface-level is required, which can leave other interfaces unprotected or misconfigured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ip ospf authentication message-digest and ip ospf message-digest-key 1 md5 <key>

To enable MD5 authentication on a specific OSPF interface, you use the interface command ip ospf authentication message-digest and then define the key with ip ospf message-digest-key. This ensures that OSPF packets are authenticated with MD5 and the key is not transmitted in clear text, meeting the scenario's security requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ip ospf authentication-key <key> and ip ospf authentication

    Why it's wrong here

    The ip ospf authentication-key command configures a plaintext authentication key, and ip ospf authentication enables plaintext authentication. This sends the key in clear text, which violates the requirement. It does not use MD5, so it is incorrect for this scenario.

  • ✓

    ip ospf authentication message-digest and ip ospf message-digest-key 1 md5 <key>

    Why this is correct

    The interface-level command ip ospf authentication message-digest enables MD5 authentication for OSPF on that interface. The ip ospf message-digest-key command defines the key ID and MD5 key. Together, they satisfy the requirement to authenticate neighbors using MD5 without sending the key in clear text.

  • ✗

    area 0 authentication message-digest and ip ospf message-digest-key 1 md5 <key>

    Why it's wrong here

    The area 0 authentication message-digest command enables MD5 authentication for the entire area, not per interface. While it can work, it does not specifically target the interface and may affect other interfaces in the area. The scenario asks for interface-level configuration, so this is not the best answer.

  • ✗

    ip ospf authentication null and ip ospf message-digest-key 1 md5 <key>

    Why it's wrong here

    The ip ospf authentication null command disables authentication on the interface, which contradicts the requirement. Even with the message-digest-key command present, authentication would not be enforced. This option would allow unauthorized routers to form adjacencies, so it is incorrect.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.