Courseiva
Infrastructure Security →mediumMultiple Choice

300-410 Infrastructure Security Practice Question

A network engineer is configuring a Cisco IOS XE router to authenticate OSPFv3 neighbors. The engineer applies the following configuration under the OSPFv3 process: `area 0 authentication ipsec spi 256 sha1 0123456789ABCDEF0123456789ABCDEF01234567`. The engineer then verifies the neighbor relationship and sees that it remains in EXSTART state. Which action should the engineer take to resolve the issue?

⚠ Common exam trap

The trap here is assuming that OSPFv3 authentication can be configured per interface like OSPFv2, when it actually requires process-level IPsec parameters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the same IPsec SPI and key on the neighboring router under its OSPFv3 process.

OSPFv3 authentication uses IPsec to secure protocol packets. The configuration requires an SPI and a key to be manually set under the OSPFv3 process on both routers. When the peer lacks the matching SPI and key, authentication fails, and the adjacency cannot progress beyond EXSTART. Configuring the identical IPsec parameters on the neighbor resolves the issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a key chain with the same key ID and key string on both routers.

    Why it's wrong here

    Key chains are used for OSPFv2 authentication, not OSPFv3. OSPFv3 authentication relies on IPsec security associations defined by SPI and key. While key chains can be used for other protocols, they do not apply here. The neighbor must have the same SPI and key configured under its OSPFv3 process to establish the IPsec session.

  • ✗

    Enable OSPFv3 authentication globally with the `ipv6 ospf authentication` command on all interfaces.

    Why it's wrong here

    OSPFv3 authentication is configured under the OSPFv3 routing process, not per interface, because it relies on IPsec which is applied at the process level. Using interface-level commands would not create the required security association. The correct method is to define the IPsec SPI and key within the `router ospf` configuration, ensuring both routers share identical parameters.

  • ✓

    Configure the same IPsec SPI and key on the neighboring router under its OSPFv3 process.

    Why this is correct

    OSPFv3 authentication uses IPsec AH or ESP with a manually configured SPI and key. Both neighbors must have matching SPI values and identical keys for the security association to be established. Without the same SPI and key on the peer, IPsec authentication fails, preventing OSPFv3 packets from being accepted and leaving the adjacency stuck in EXSTART.

  • ✗

    Change the authentication algorithm to MD5 to match the neighbor's configuration.

    Why it's wrong here

    OSPFv3 does not support MD5 authentication; it uses IPsec AH or ESP. MD5 is available for OSPFv2 but not OSPFv3. Changing the algorithm to MD5 would be ineffective and would not resolve the EXSTART state. The issue is the missing matching IPsec configuration on the neighbor, not the choice of algorithm.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.