Courseiva
Infrastructure →mediumMultiple Choice

CCNP Infrastructure Practice Question

A network engineer is configuring a Cisco IOS router to authenticate OSPF neighbors using MD5 cryptographic authentication on an interface. The engineer enters the following commands: interface GigabitEthernet0/0, ip ospf authentication message-digest, ip ospf message-digest-key 1 md5 Cisco123. However, the OSPF adjacency with the neighbor router is not forming. Which additional configuration is required on the neighbor router to establish the adjacency?

⚠ Common exam trap

The trap here is assuming that enabling MD5 authentication on one side is sufficient, or confusing plain text authentication with MD5 authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the same key ID and password on the neighbor's interface with ip ospf message-digest-key 1 md5 Cisco123.

OSPF MD5 authentication requires both neighbors to have the same key ID and password configured on their interfaces. The engineer configured MD5 on one router, so the neighbor must have the identical 'ip ospf message-digest-key' command. Without matching keys, authentication fails and the adjacency does not form.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the neighbor with the command area 0 authentication message-digest.

    Why it's wrong here

    Area authentication enables authentication for all interfaces in the area, but the first router has interface-level authentication configured. If the neighbor uses area authentication, it might still work if the keys match, but it is not the required additional configuration. The question asks for the additional configuration on the neighbor to match the interface-level MD5 authentication.

  • ✗

    Configure the neighbor with the command ip ospf authentication-key Cisco123.

    Why it's wrong here

    The 'ip ospf authentication-key' command is used for plain text (simple password) authentication, not MD5. Since the engineer configured MD5 on the first router, the neighbor must also use MD5 with the same key. Using plain text authentication would cause a mismatch and prevent adjacency.

  • ✓

    Configure the same key ID and password on the neighbor's interface with ip ospf message-digest-key 1 md5 Cisco123.

    Why this is correct

    For OSPF MD5 authentication to succeed, both routers must have the same key ID and password configured on their interfaces. The neighbor must have the identical message-digest-key command with the same key number and MD5 password. Without this matching configuration, authentication will fail, and the adjacency will not form.

  • ✗

    Configure the neighbor with the command ip ospf authentication null.

    Why it's wrong here

    The 'ip ospf authentication null' command disables authentication on the interface. Since the first router is using MD5 authentication, disabling authentication on the neighbor would cause a mismatch and prevent adjacency. The neighbor must use the same authentication type and key.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.