Courseiva
Infrastructure →hardMultiple Choice

350-401 Infrastructure Practice Question

A network engineer is configuring a Cisco IOS router to authenticate OSPFv2 neighbors using SHA-256 HMAC cryptographic authentication on an interface. Which command sequence correctly enables this authentication?

⚠ Common exam trap

The trap here is assuming that MD5 message-digest authentication is equivalent to SHA-256 HMAC, when MD5 uses a different and weaker algorithm.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ip ospf authentication key-chain <name> and configure a key chain with key 1 using cryptographic-algorithm hmac-sha-256

OSPFv2 supports SHA-256 HMAC authentication through key chains. The interface command ip ospf authentication key-chain <name> references a key chain configured with key 1 and cryptographic-algorithm hmac-sha-256. This provides cryptographic authentication with stronger hashing than MD5. Simple authentication and MD5 do not meet the SHA-256 requirement, and null disables authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ip ospf authentication key-chain <name> and configure a key chain with key 1 using cryptographic-algorithm hmac-sha-256

    Why this is correct

    This sequence correctly enables OSPFv2 SHA-256 HMAC authentication. The interface command ip ospf authentication key-chain references a key chain, which must be defined globally with a key that specifies the cryptographic algorithm hmac-sha-256 and a password. This provides stronger security than MD5. The key chain allows for key rollover and multiple keys with different lifetimes, which is essential for operational flexibility.

  • ✗

    ip ospf authentication followed by ip ospf authentication-key <password>

    Why it's wrong here

    This sequence enables simple password authentication, which sends the password in clear text. It does not provide cryptographic authentication or HMAC. Simple authentication is insecure and does not meet the requirement for SHA-256. The ip ospf authentication command without additional keywords defaults to simple authentication. Thus, this option is incorrect.

  • ✗

    ip ospf authentication null

    Why it's wrong here

    The ip ospf authentication null command disables authentication on the interface, overriding any area-level authentication. It does not enable SHA-256 or any authentication. This would leave the OSPF neighbor relationship unauthenticated, which is the opposite of the requirement. Therefore, this option is incorrect.

  • ✗

    ip ospf authentication message-digest followed by ip ospf message-digest-key 1 md5 <key>

    Why it's wrong here

    This sequence enables MD5 authentication, not SHA-256 HMAC. The message-digest-key command with md5 specifies MD5 hashing. While MD5 is a cryptographic authentication method, it does not meet the requirement for SHA-256. The engineer must use key chain-based authentication to achieve SHA-256 HMAC. Therefore, this option fails to provide the required security strength.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.