Courseiva
Security →mediumMultiple Choice

CCNP Security Practice Question

A network engineer must protect the OSPF adjacency between two Cisco routers from spoofed hello packets injected by a rogue device on the same broadcast segment. The engineer wants to use a cryptographic authentication method that is natively supported by OSPFv2 and does not rely on plain-text key exchange. Which configuration should be applied to the interfaces?

⚠ Common exam trap

The trap here is assuming that any OSPF authentication command provides cryptographic protection, when simple password authentication transmits the key in cleartext and offers no real defense.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ip ospf authentication message-digest and ip ospf message-digest-key 1 md5 <key>

OSPFv2 supports two authentication types: simple password and message-digest (MD5). Only message-digest provides cryptographic protection, because it hashes the packet with a shared key rather than transmitting the key. Enabling ip ospf authentication message-digest on the interface plus defining ip ospf message-digest-key with an MD5 key ensures hellos are authenticated and spoofed packets from a rogue host are rejected before the adjacency can be affected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ip ospf authentication-key <key>

    Why it's wrong here

    The ip ospf authentication-key command enables simple password authentication, which transmits the key in cleartext inside the OSPF header. Anyone capturing traffic on the segment can read the password and forge valid hello packets, so it does not meet the requirement for a cryptographic method. It also requires ip ospf authentication to be enabled separately, and it offers no protection against replay or spoofing by an on-path attacker.

  • ✗

    ip ospf authentication key-chain <name>

    Why it's wrong here

    The key-chain syntax is used with OSPFv3 (ipv6 ospf authentication ipsec) or with EIGRP, not with OSPFv2 message-digest authentication. OSPFv2 cryptographic authentication is configured with ip ospf message-digest-key, not a key chain. Applying this command on an OSPFv2 interface will not produce the intended cryptographic authentication behavior and therefore does not protect the adjacency from spoofed hello packets in this scenario.

  • ✓

    ip ospf authentication message-digest and ip ospf message-digest-key 1 md5 <key>

    Why this is correct

    OSPFv2 message-digest authentication uses MD5 to hash the key and packet contents, so the key is never sent in cleartext. Configuring ip ospf authentication message-digest enables cryptographic authentication on the interface, and ip ospf message-digest-key 1 md5 supplies the key material. Neighbors must share the same key ID and key string for the adjacency to form, which satisfies the requirement to protect against spoofed hellos.

  • ✗

    ip ospf authentication null

    Why it's wrong here

    Setting ip ospf authentication null explicitly disables authentication for OSPF packets on the interface. This is the opposite of what the scenario requires, since it permits any device to send hellos that the router will accept. This command is sometimes used during migration between authentication modes, but it leaves the adjacency fully exposed to spoofed hello injection and would not prevent a rogue device from forming or disrupting an adjacency.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.