Courseiva
Virtualization →mediumMultiple Choice

350-401 Virtualization Practice Question

A network engineer is configuring NTP authentication on a Cisco IOS-XE router. The goal is to ensure the router only synchronizes with a trusted NTP server and that the server's keys are validated. Which sequence of configuration steps correctly enforces authenticated NTP peering?

⚠ Common exam trap

The trap here is thinking that referencing a key on the `ntp server` command is sufficient, when the global `ntp authenticate` command and a trusted-key statement are also mandatory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable `ntp authenticate`, define the key with `ntp authentication-key 1 md5 <key>`, mark it trusted with `ntp trusted-key 1`, then add `ntp server <ip> key 1`.

Enforcing authenticated NTP requires four coordinated elements: the global `ntp authenticate` command, a defined authentication key with its MD5 value, a `ntp trusted-key` statement for that key number, and the key reference on the `ntp server` command. Missing any one element breaks the chain, either by leaving authentication disabled, by rejecting valid packets, or by failing to associate the key with the specific peer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Define the key with `ntp authentication-key 1 md5 <key>` and add `ntp server <ip> key 1`, omitting `ntp authenticate` because the server command implies authentication.

    Why it's wrong here

    Configuring a key and referencing it on the server command does not enable authentication on its own. IOS-XE requires the global `ntp authenticate` command before it will validate any NTP packet. Without it, the router accepts NTP replies regardless of key, so an unauthenticated or spoofed server could still be used. The omission leaves the intended security control inactive.

  • ✗

    Enable `ntp authenticate` and mark the key trusted with `ntp trusted-key 1`, but do not configure the key value itself, relying on the server to supply it.

    Why it's wrong here

    A trusted key must have an actual key value defined locally; the router cannot derive the MD5 secret from the server. Marking a nonexistent key as trusted leaves authentication unable to succeed, so the router rejects the server's authenticated packets. The key value must match on both peers. Trust alone does not create the credential, so synchronization fails.

  • ✗

    Configure `ntp master 1` on the router and add `ntp server <ip>`, because a stratum 1 master enforces authentication automatically.

    Why it's wrong here

    The `ntp master` command makes the router act as an authoritative time source at the given stratum; it does not enable or require authentication. Adding a server alongside a master configuration does not validate that server's keys. This approach changes the router's role rather than securing the peering, and the server could still be accepted without any cryptographic check.

  • ✓

    Enable `ntp authenticate`, define the key with `ntp authentication-key 1 md5 <key>`, mark it trusted with `ntp trusted-key 1`, then add `ntp server <ip> key 1`.

    Why this is correct

    This sequence turns on authentication globally, creates the MD5 key, marks that key as trusted so the router accepts it, and associates the key with the server. Each step is required: without `ntp authenticate` the router ignores authentication, without a trusted key it rejects valid packets, and without the key number on the server command it will not use the key for that peer. Together they enforce authenticated peering.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

Go deeper

Related to this question

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.