Courseiva
Layer 3 Technologies →easyMultiple Choice

300-410 Layer 3 Technologies Practice Question

A network technician is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using MD5. The technician enters the following commands:

interface GigabitEthernet0/0
 ip ospf authentication message-digest
 ip ospf message-digest-key 1 md5 cisco

After applying the configuration, the router does not form an adjacency with its neighbor. What is the most likely reason?

⚠ Common exam trap

The trap here is assuming that MD5 authentication only requires enabling it on one side, or that the key string can be different, when in fact both key ID and key string must match on both routers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The neighbor router is not configured with the same MD5 key ID and key string.

OSPF MD5 authentication requires that both neighbors use the same key ID and key string. When the technician configures MD5 on one router but the neighbor has not been configured with the identical key, the MD5 digest in OSPF hellos will not match, and the routers will not form an adjacency. The technician should verify the neighbor's configuration and ensure both key ID and key string match exactly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The neighbor router is not configured with the same MD5 key ID and key string.

    Why this is correct

    OSPF MD5 authentication requires that both routers use the same key ID and identical key string on the interface. If the neighbor has a different key ID or key string, the MD5 digest will not match, and OSPF hellos will be rejected, preventing adjacency formation. The most common cause of failure after enabling MD5 is a mismatch in these parameters.

  • ✗

    The key string must be encrypted using the 'service password-encryption' command.

    Why it's wrong here

    The 'service password-encryption' command encrypts plaintext passwords in the configuration file for security, but it does not affect OSPF MD5 authentication. The key string is used directly in the MD5 hash; encryption of the configuration display does not change the authentication process. The problem is not related to password encryption.

  • ✗

    The 'ip ospf authentication message-digest' command must be configured globally, not on the interface.

    Why it's wrong here

    The 'ip ospf authentication message-digest' command can be configured on an interface to enable MD5 authentication for that interface. It can also be configured under the OSPF routing process to enable authentication for all interfaces in an area. However, interface-level configuration is valid and commonly used. The issue is not the placement of the command but a mismatch in keys.

  • ✗

    The key ID must be the same on both routers, but the key string can differ.

    Why it's wrong here

    For OSPF MD5 authentication, both the key ID and the key string must match on both routers. The key ID identifies which key is used, and the key string is the shared secret. If either differs, authentication fails. This option incorrectly states that the key string can differ, which would cause authentication failure and prevent adjacency formation.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

Go deeper

Related to this question

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.