300-410 Infrastructure Security Practice Question
A network engineer is configuring a Cisco IOS XE router to authenticate OSPFv3 neighbors. The engineer applies the following configuration under the OSPFv3 process: `area 0 authentication ipsec spi 256 sha1 0123456789ABCDEF0123456789ABCDEF01234567`. The engineer then verifies the neighbor relationship and sees that it remains in EXSTART state. Which action should the engineer take to resolve the issue?
⚠ Common exam trap
The trap here is assuming that OSPFv3 authentication can be configured per interface like OSPFv2, when it actually requires process-level IPsec parameters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the same IPsec SPI and key on the neighboring router under its OSPFv3 process.
OSPFv3 authentication uses IPsec to secure protocol packets. The configuration requires an SPI and a key to be manually set under the OSPFv3 process on both routers. When the peer lacks the matching SPI and key, authentication fails, and the adjacency cannot progress beyond EXSTART. Configuring the identical IPsec parameters on the neighbor resolves the issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a key chain with the same key ID and key string on both routers.
Why it's wrong here
Key chains are used for OSPFv2 authentication, not OSPFv3. OSPFv3 authentication relies on IPsec security associations defined by SPI and key. While key chains can be used for other protocols, they do not apply here. The neighbor must have the same SPI and key configured under its OSPFv3 process to establish the IPsec session.
- ✗
Enable OSPFv3 authentication globally with the `ipv6 ospf authentication` command on all interfaces.
Why it's wrong here
OSPFv3 authentication is configured under the OSPFv3 routing process, not per interface, because it relies on IPsec which is applied at the process level. Using interface-level commands would not create the required security association. The correct method is to define the IPsec SPI and key within the `router ospf` configuration, ensuring both routers share identical parameters.
- ✓
Configure the same IPsec SPI and key on the neighboring router under its OSPFv3 process.
Why this is correct
OSPFv3 authentication uses IPsec AH or ESP with a manually configured SPI and key. Both neighbors must have matching SPI values and identical keys for the security association to be established. Without the same SPI and key on the peer, IPsec authentication fails, preventing OSPFv3 packets from being accepted and leaving the adjacency stuck in EXSTART.
- ✗
Change the authentication algorithm to MD5 to match the neighbor's configuration.
Why it's wrong here
OSPFv3 does not support MD5 authentication; it uses IPsec AH or ESP. MD5 is available for OSPFv2 but not OSPFv3. Changing the algorithm to MD5 would be ineffective and would not resolve the EXSTART state. The issue is the missing matching IPsec configuration on the neighbor, not the choice of algorithm.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.