Courseiva
easyMultiple Choice

CCNP Practice Question: Is troubleshooting an EIGRP issue where two…

A network engineer is troubleshooting an EIGRP issue where two routers, R1 and R2, are directly connected. Neither router shows an EIGRP adjacency with the other. The engineer checks the interface configurations and finds that R1 has 'ip authentication mode eigrp 1 md5' and 'ip authentication key-chain eigrp 1 MYKEY' configured, while R2 has no authentication configured. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the misconception that authentication is optional or that a router can learn keys dynamically; the trap here is assuming that an adjacency can form unidirectionally when authentication is mismatched, when in fact EIGRP requires matching authentication parameters for bidirectional neighbor discovery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

R1 has authentication configured, but R2 does not, so R1 will reject R2's hello packets, and no adjacency forms.

R1 has authentication configured, so it includes MD5 authentication data in its hello packets and expects authenticated hellos from neighbors. R2 does not have authentication configured, so it sends unauthenticated hellos. R1 drops R2's unauthenticated hellos, and R2 does not process R1's authenticated hellos (or the mismatch prevents a bidirectional relationship), resulting in no EIGRP adjacency being formed on either router.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    R1 has authentication configured, but R2 does not, so R1 will reject R2's hello packets, and no adjacency forms.

    Why this is correct

    EIGRP supports MD5 or HMAC-SHA-256 authentication, which must be configured with a matching key on both neighbors. When R1 has authentication enabled, it inspects the EIGRP authentication TLV in every incoming hello packet; R2's hellos lack this TLV because R2 has no authentication configured, so R1 silently discards them. Because R1 never accepts R2's hellos, the two-way neighbor discovery process fails, and no adjacency is ever established.

  • ✗

    R2 will automatically learn the authentication key from R1 and form an adjacency.

    Why it's wrong here

    EIGRP authentication relies on a pre-shared key that is statically configured on each router; there is no dynamic key exchange or learning mechanism in the protocol. The authentication data in EIGRP packets is a one-way hash (or MAC) computed from the key and packet contents, which does not reveal the key itself, so R2 cannot derive it from R1's hellos. Even if R1 uses a key chain with lifetime rotation, the keys themselves must still be manually entered on every router, so R2 cannot automatically learn anything.

  • ✗

    R1 will form an adjacency with R2 because authentication is optional.

    Why it's wrong here

    EIGRP authentication is an interface-level security feature that, once enabled, is mandatory for all EIGRP packets received on that interface. The 'optional' nature of authentication refers only to the decision to enable it during configuration, not to whether it can be bypassed at runtime. If R1 has authentication configured, it will enforce strict validation on every incoming packet from R2, and an unauthenticated hello from R2 will be rejected; there is no mode where EIGRP accepts both authenticated and unauthenticated neighbors simultaneously.

  • ✗

    The adjacency will form but only for routes that are not authenticated.

    Why it's wrong here

    EIGRP authentication applies to all protocol packets—hellos, updates, queries, replies, and ACKs—before any route processing occurs. Since the adjacency itself is built on successfully authenticated hellos, a failure to authenticate prevents the neighbor relationship from forming entirely. Routing information is never exchanged until after the adjacency is up, so the notion of forming an adjacency for only 'unauthenticated routes' is nonsensical; there are no separate categories of routes in the EIGRP process.

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.