Courseiva
mediumMultiple Choice

300-410 Practice Question: Configures BGP on router R4: router bgp 65004 bgp…

A network engineer configures BGP on router R4:

router bgp 65004

bgp router-id 4.4.4.4

neighbor 10.4.4.3 remote-as 65003
 neighbor 10.4.4.3 password BGPsecret

!

What is the effect of the password command?

⚠ Common exam trap

300-410 often tests the misconception that the BGP password encrypts routing updates, so candidates must remember it only provides MD5 TCP session authentication, not payload encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It enables MD5 authentication for the TCP session; the neighbor must also have the same password.

The 'neighbor ... password' command in Cisco IOS BGP enables MD5 authentication for the TCP session between BGP peers. The password is used to generate an MD5 hash that is included in TCP segments, and both neighbors must be configured with the same password for the session to establish. This prevents unauthorized BGP peering and protects against TCP reset attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It encrypts the BGP updates using the password as a key.

    Why it's wrong here

    The password command enables TCP MD5 signature authentication on the BGP session; it does not encrypt update payloads. Updates remain unencrypted. It is tempting because the word password suggests cryptographic protection, but MD5 only authenticates the TCP segment, preventing session establishment with peers lacking the matching key.

  • ✓

    It enables MD5 authentication for the TCP session; the neighbor must also have the same password.

    Why this is correct

    The password command enables TCP MD5 signature authentication for the BGP session, protecting against spoofed TCP segments. Both peers must configure the identical password, otherwise the MD5 digest mismatches and the session fails to establish.

  • ✗

    It sets a simple password that is sent in clear text with each BGP update.

    Why it's wrong here

    The password command triggers TCP MD5 authentication, which hashes the TCP header and payload with the key; the password itself is never transmitted. It is tempting because plaintext protocols like OSPF do send simple passwords, but BGP uses MD5 digest, not clear-text transmission.

  • ✗

    It has no effect unless the neighbor is configured with the same password.

    Why it's wrong here

    The password command does take effect immediately: it enables TCP MD5 signature authentication on the peering session, and the neighbour must match it or the session never establishes. It is tempting because MD5 is only verified mutually, so a matching peer is required, but that is a precondition, not a nullifying condition.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.