Courseiva
Infrastructure →mediumMultiple Choice

CCNP Infrastructure Practice Question

A network engineer is configuring a new Cisco IOS router and wants to ensure that OSPFv2 adjacencies form only on the interface that connects to the trusted internal network. The router has three interfaces: GigabitEthernet0/0 (internal), GigabitEthernet0/1 (DMZ), and GigabitEthernet0/2 (Internet). The engineer enables OSPF process 1 and wants to advertise the internal network 10.1.1.0/24 while preventing OSPF from sending or receiving hello packets on the other interfaces. Which configuration accomplishes this goal?

⚠ Common exam trap

The trap here is assuming that the network command alone controls which interfaces run OSPF, when in fact OSPF can run on any interface whose IP matches the network statement, and passive-interface is needed to suppress hellos on specific interfaces.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

router ospf 1 network 10.1.1.0 0.0.0.255 area 0 passive-interface default no passive-interface GigabitEthernet0/0

The requirement is to allow OSPF adjacencies only on the internal interface while suppressing them on all others. Setting 'passive-interface default' disables OSPF hello processing on every interface, and then 'no passive-interface GigabitEthernet0/0' re-enables it only on the internal interface. This ensures that OSPF runs exclusively where intended and prevents unintended adjacencies on the DMZ and Internet links.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    router ospf 1 network 10.1.1.0 0.0.0.255 area 0 passive-interface default no passive-interface GigabitEthernet0/0

    Why this is correct

    This configuration enables OSPF on the router, advertises the internal subnet, and sets all interfaces to passive by default. The 'no passive-interface GigabitEthernet0/0' command re-enables OSPF hello processing only on the internal interface, allowing adjacencies to form there while suppressing them on the DMZ and Internet interfaces. This matches the requirement exactly.

  • ✗

    router ospf 1 network 10.1.1.0 0.0.0.255 area 0 passive-interface GigabitEthernet0/1 passive-interface GigabitEthernet0/2

    Why it's wrong here

    This configuration advertises the internal network and makes the DMZ and Internet interfaces passive, but it leaves GigabitEthernet0/0 active. However, because the network command includes only 10.1.1.0/24, OSPF will still run on any interface whose IP falls within that range. If the DMZ or Internet interfaces have IPs in different subnets, they will not form adjacencies, but the configuration does not explicitly prevent OSPF from running on them if they later get addresses in the same range. It also does not suppress OSPF on all non-internal interfaces by default, so it is less precise and could allow unintended adjacencies if addressing changes.

  • ✗

    router ospf 1 network 10.1.1.0 0.0.0.255 area 0 ip ospf passive-interface GigabitEthernet0/1 ip ospf passive-interface GigabitEthernet0/2

    Why it's wrong here

    The command 'ip ospf passive-interface' is not valid Cisco IOS syntax. Passive interfaces are configured under the OSPF routing process using the 'passive-interface' command, not as an interface-level command. This configuration would be rejected by the router, and OSPF would not be properly configured on the intended interfaces, so the goal would not be met.

  • ✗

    router ospf 1 network 10.1.1.0 0.0.0.255 area 0 passive-interface GigabitEthernet0/0

    Why it's wrong here

    This configuration makes the internal interface passive, which prevents OSPF hellos from being sent or received on GigabitEthernet0/0. As a result, no OSPF adjacency can form on the trusted internal network, directly contradicting the requirement. The DMZ and Internet interfaces remain active and could form adjacencies if they are included in the network statement or if OSPF is enabled on them, which is the opposite of what is needed.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.