easyMultiple Choice
CCNP Practice Question: Is troubleshooting an EIGRP issue where two…
A network engineer is troubleshooting an EIGRP issue where two routers, R1 and R2, are directly connected. Neither router shows an EIGRP adjacency with the other. The engineer checks the interface configurations and finds that R1 has 'ip authentication mode eigrp 1 md5' and 'ip authentication key-chain eigrp 1 MYKEY' configured, while R2 has no authentication configured. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the misconception that authentication is optional or that a router can learn keys dynamically; the trap here is assuming that an adjacency can form unidirectionally when authentication is mismatched, when in fact EIGRP requires matching authentication parameters for bidirectional neighbor discovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
R1 has authentication configured, but R2 does not, so R1 will reject R2's hello packets, and no adjacency forms.
R1 has authentication configured, so it includes MD5 authentication data in its hello packets and expects authenticated hellos from neighbors. R2 does not have authentication configured, so it sends unauthenticated hellos. R1 drops R2's unauthenticated hellos, and R2 does not process R1's authenticated hellos (or the mismatch prevents a bidirectional relationship), resulting in no EIGRP adjacency being formed on either router.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
R1 has authentication configured, but R2 does not, so R1 will reject R2's hello packets, and no adjacency forms.
Why this is correct
EIGRP supports MD5 or HMAC-SHA-256 authentication, which must be configured with a matching key on both neighbors. When R1 has authentication enabled, it inspects the EIGRP authentication TLV in every incoming hello packet; R2's hellos lack this TLV because R2 has no authentication configured, so R1 silently discards them. Because R1 never accepts R2's hellos, the two-way neighbor discovery process fails, and no adjacency is ever established.
- ✗
R2 will automatically learn the authentication key from R1 and form an adjacency.
Why it's wrong here
EIGRP authentication relies on a pre-shared key that is statically configured on each router; there is no dynamic key exchange or learning mechanism in the protocol. The authentication data in EIGRP packets is a one-way hash (or MAC) computed from the key and packet contents, which does not reveal the key itself, so R2 cannot derive it from R1's hellos. Even if R1 uses a key chain with lifetime rotation, the keys themselves must still be manually entered on every router, so R2 cannot automatically learn anything.
- ✗
R1 will form an adjacency with R2 because authentication is optional.
Why it's wrong here
EIGRP authentication is an interface-level security feature that, once enabled, is mandatory for all EIGRP packets received on that interface. The 'optional' nature of authentication refers only to the decision to enable it during configuration, not to whether it can be bypassed at runtime. If R1 has authentication configured, it will enforce strict validation on every incoming packet from R2, and an unauthenticated hello from R2 will be rejected; there is no mode where EIGRP accepts both authenticated and unauthenticated neighbors simultaneously.
- ✗
The adjacency will form but only for routes that are not authenticated.
Why it's wrong here
EIGRP authentication applies to all protocol packets—hellos, updates, queries, replies, and ACKs—before any route processing occurs. Since the adjacency itself is built on successfully authenticated hellos, a failure to authenticate prevents the neighbor relationship from forming entirely. Routing information is never exchanged until after the adjacency is up, so the notion of forming an adjacency for only 'unauthenticated routes' is nonsensical; there are no separate categories of routes in the EIGRP process.
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.