350-401 Infrastructure Practice Question
A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using SHA-256 HMAC cryptographic authentication on an interface. Which command sequence correctly enables this authentication?
⚠ Common exam trap
The trap here is assuming that MD5 message-digest authentication is equivalent to SHA-256 HMAC, when MD5 uses a different and weaker algorithm.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ip ospf authentication key-chain <name> and configure a key chain with key 1 using cryptographic-algorithm hmac-sha-256
OSPFv2 supports SHA-256 HMAC authentication through key chains. The interface command ip ospf authentication key-chain <name> references a key chain configured with key 1 and cryptographic-algorithm hmac-sha-256. This provides cryptographic authentication with stronger hashing than MD5. Simple authentication and MD5 do not meet the SHA-256 requirement, and null disables authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ip ospf authentication key-chain <name> and configure a key chain with key 1 using cryptographic-algorithm hmac-sha-256
Why this is correct
This sequence correctly enables OSPFv2 SHA-256 HMAC authentication. The interface command ip ospf authentication key-chain references a key chain, which must be defined globally with a key that specifies the cryptographic algorithm hmac-sha-256 and a password. This provides stronger security than MD5. The key chain allows for key rollover and multiple keys with different lifetimes, which is essential for operational flexibility.
- ✗
ip ospf authentication followed by ip ospf authentication-key <password>
Why it's wrong here
This sequence enables simple password authentication, which sends the password in clear text. It does not provide cryptographic authentication or HMAC. Simple authentication is insecure and does not meet the requirement for SHA-256. The ip ospf authentication command without additional keywords defaults to simple authentication. Thus, this option is incorrect.
- ✗
ip ospf authentication null
Why it's wrong here
The ip ospf authentication null command disables authentication on the interface, overriding any area-level authentication. It does not enable SHA-256 or any authentication. This would leave the OSPF neighbor relationship unauthenticated, which is the opposite of the requirement. Therefore, this option is incorrect.
- ✗
ip ospf authentication message-digest followed by ip ospf message-digest-key 1 md5 <key>
Why it's wrong here
This sequence enables MD5 authentication, not SHA-256 HMAC. The message-digest-key command with md5 specifies MD5 hashing. While MD5 is a cryptographic authentication method, it does not meet the requirement for SHA-256. The engineer must use key chain-based authentication to achieve SHA-256 HMAC. Therefore, this option fails to provide the required security strength.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.