mediumMultiple Choice
300-410 Practice Question: Configures BGP on router R4: router bgp 65004 bgp…
A network engineer configures BGP on router R4:
router bgp 65004
bgp router-id 4.4.4.4
neighbor 10.4.4.3 remote-as 65003 neighbor 10.4.4.3 password BGPsecret
!
What is the effect of the password command?
⚠ Common exam trap
300-410 often tests the misconception that the BGP password encrypts routing updates, so candidates must remember it only provides MD5 TCP session authentication, not payload encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It enables MD5 authentication for the TCP session; the neighbor must also have the same password.
The 'neighbor ... password' command in Cisco IOS BGP enables MD5 authentication for the TCP session between BGP peers. The password is used to generate an MD5 hash that is included in TCP segments, and both neighbors must be configured with the same password for the session to establish. This prevents unauthorized BGP peering and protects against TCP reset attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It encrypts the BGP updates using the password as a key.
Why it's wrong here
The password command enables TCP MD5 signature authentication on the BGP session; it does not encrypt update payloads. Updates remain unencrypted. It is tempting because the word password suggests cryptographic protection, but MD5 only authenticates the TCP segment, preventing session establishment with peers lacking the matching key.
- ✓
It enables MD5 authentication for the TCP session; the neighbor must also have the same password.
Why this is correct
The password command enables TCP MD5 signature authentication for the BGP session, protecting against spoofed TCP segments. Both peers must configure the identical password, otherwise the MD5 digest mismatches and the session fails to establish.
- ✗
It sets a simple password that is sent in clear text with each BGP update.
Why it's wrong here
The password command triggers TCP MD5 authentication, which hashes the TCP header and payload with the key; the password itself is never transmitted. It is tempting because plaintext protocols like OSPF do send simple passwords, but BGP uses MD5 digest, not clear-text transmission.
- ✗
It has no effect unless the neighbor is configured with the same password.
Why it's wrong here
The password command does take effect immediately: it enables TCP MD5 signature authentication on the peering session, and the neighbour must match it or the session never establishes. It is tempting because MD5 is only verified mutually, so a matching peer is required, but that is a precondition, not a nullifying condition.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.