300-410 Infrastructure Security Practice Question
A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The engineer enters the following commands:
interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 C1sco123
After applying the configuration, the OSPF neighbor relationship fails to form. Which action must the engineer take to resolve the issue?
⚠ Common exam trap
The trap here is assuming that enabling OSPF authentication on one side is sufficient, when in fact both neighbors must have matching credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the same MD5 key and key ID on the neighboring router's interface.
OSPF MD5 authentication requires that both neighbors have the same key ID and key string configured on their interfaces. The local router is correctly configured for MD5, but the neighbor lacks the matching key, causing authentication to fail. Configuring the identical key on the neighbor's interface will allow the adjacency to form.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the ip ospf authentication-key command with the same password.
Why it's wrong here
The ip ospf authentication-key command is used for plaintext authentication, not MD5. Since the interface is configured for message-digest authentication, using the plaintext key command would not satisfy the MD5 requirement. The neighbor must have the matching MD5 key, not a plaintext key.
- ✗
Change the key ID to 0 on both routers to match the default key.
Why it's wrong here
There is no default key ID of 0 for OSPF MD5 authentication; key IDs are manually configured and must match between neighbors. Changing the key ID to 0 is not a valid solution and would not resolve the authentication failure. The correct action is to ensure both routers use the same key ID and key string.
- ✓
Configure the same MD5 key and key ID on the neighboring router's interface.
Why this is correct
OSPF MD5 authentication requires that both neighbors use the same key ID and key string on their interfaces. The local configuration is correct, but without matching credentials on the neighbor, authentication fails and the adjacency will not form. Therefore, configuring the matching key on the neighboring router's interface resolves the issue.
- ✗
Enable OSPF authentication globally using the area authentication command.
Why it's wrong here
Area authentication would enforce authentication for all interfaces in the area, but it is not required if interface-level authentication is already configured. The problem is not the authentication mode but the missing matching key on the neighbor. Enabling area authentication would not supply the missing key and could disrupt other interfaces.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
Learn chapter
Device Management and Network Monitoring (SNMP, Syslog, NetFlow)
Key term
OSPF authentication
OSPF authentication is a security mechanism that verifies the identity of routers exchanging routing information within an OSPF network, preventing unauthorized or malicious routing updates.
Key term
OSPF and EIGRP Authentication
OSPF and EIGRP authentication is a security feature that verifies the identity of routers exchanging routing updates, ensuring only trusted devices can participate in the network.
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.