300-410 Layer 3 Technologies Practice Question
A network engineer is configuring a Cisco router to authenticate OSPF neighbors using MD5. The router is connected to two OSPF neighbors on the same subnet. The engineer wants to enable MD5 authentication on the interface with a key ID of 1 and a password of 'Cisco123'. Which command sequence correctly accomplishes this?
⚠ Common exam trap
Test-takers frequently confuse interface-level MD5 authentication commands with area-level authentication commands, and misplacing the key configuration under router ospf mode instead of interface mode.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 Cisco123
To enable OSPF MD5 authentication on a specific interface, you must enter interface configuration mode and issue both 'ip ospf authentication message-digest' to turn on MD5 authentication and 'ip ospf message-digest-key 1 md5 Cisco123' to define the key. This method allows per-interface authentication, which is suitable when only certain interfaces require MD5. The other options either misplace the key command, use plaintext authentication, or configure area-wide authentication incorrectly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
router ospf 1 area 0 authentication ip ospf message-digest-key 1 md5 Cisco123
Why it's wrong here
This sequence enables simple password authentication for area 0 with 'area 0 authentication' and then attempts to configure an MD5 key under router configuration mode, which is invalid. The 'area 0 authentication' command enables plaintext authentication, not MD5. To enable MD5 area authentication, the command is 'area 0 authentication message-digest'. Furthermore, the key must be configured on the interface. This configuration would not achieve MD5 authentication and may cause authentication mismatches.
- ✗
router ospf 1 area 0 authentication message-digest ip ospf message-digest-key 1 md5 Cisco123
Why it's wrong here
This sequence attempts to enable MD5 authentication for area 0 and then configure the key, but the key command is entered under router ospf configuration mode, which is invalid. The 'ip ospf message-digest-key' command must be configured on the interface, not under the OSPF routing process. Additionally, area authentication enables authentication for the entire area, which may not be desired if only one interface requires it. This configuration would result in a syntax error or ineffective key configuration.
- ✗
interface GigabitEthernet0/0 ip ospf authentication-key Cisco123 ip ospf authentication message-digest
Why it's wrong here
This sequence configures a plaintext authentication key using 'ip ospf authentication-key' and then enables MD5 authentication. However, the 'ip ospf authentication-key' command is used for simple password authentication, not MD5. When MD5 is enabled, the plaintext key is ignored. To use MD5, you must configure the key with 'ip ospf message-digest-key'. Therefore, this configuration would not enable MD5 authentication correctly; it would either fail or use simple authentication if MD5 is not properly set.
- ✓
interface GigabitEthernet0/0 ip ospf authentication message-digest ip ospf message-digest-key 1 md5 Cisco123
Why this is correct
This sequence enables OSPF MD5 authentication on the interface and configures the key ID and password. The 'ip ospf authentication message-digest' command activates MD5 authentication for OSPF on that interface, and 'ip ospf message-digest-key 1 md5 Cisco123' defines the key. This is the correct method to enable MD5 authentication per interface. Both commands are required; without the first, the key is configured but authentication is not enabled.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
Learn chapter
OSPF Route Summarization and Filtering
Key term
OSPF and EIGRP Authentication
OSPF and EIGRP authentication is a security feature that verifies the identity of routers exchanging routing updates, ensuring only trusted devices can participate in the network.
Key term
OSPF authentication
OSPF authentication is a security mechanism that verifies the identity of routers exchanging routing information within an OSPF network, preventing unauthorized or malicious routing updates.
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.