350-401 Virtualization Practice Question
A network engineer is configuring NTP authentication on a Cisco IOS-XE router. The goal is to ensure the router only synchronizes with a trusted NTP server and that the server's keys are validated. Which sequence of configuration steps correctly enforces authenticated NTP peering?
⚠ Common exam trap
The trap here is thinking that referencing a key on the `ntp server` command is sufficient, when the global `ntp authenticate` command and a trusted-key statement are also mandatory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable `ntp authenticate`, define the key with `ntp authentication-key 1 md5 <key>`, mark it trusted with `ntp trusted-key 1`, then add `ntp server <ip> key 1`.
Enforcing authenticated NTP requires four coordinated elements: the global `ntp authenticate` command, a defined authentication key with its MD5 value, a `ntp trusted-key` statement for that key number, and the key reference on the `ntp server` command. Missing any one element breaks the chain, either by leaving authentication disabled, by rejecting valid packets, or by failing to associate the key with the specific peer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Define the key with `ntp authentication-key 1 md5 <key>` and add `ntp server <ip> key 1`, omitting `ntp authenticate` because the server command implies authentication.
Why it's wrong here
Configuring a key and referencing it on the server command does not enable authentication on its own. IOS-XE requires the global `ntp authenticate` command before it will validate any NTP packet. Without it, the router accepts NTP replies regardless of key, so an unauthenticated or spoofed server could still be used. The omission leaves the intended security control inactive.
- ✗
Enable `ntp authenticate` and mark the key trusted with `ntp trusted-key 1`, but do not configure the key value itself, relying on the server to supply it.
Why it's wrong here
A trusted key must have an actual key value defined locally; the router cannot derive the MD5 secret from the server. Marking a nonexistent key as trusted leaves authentication unable to succeed, so the router rejects the server's authenticated packets. The key value must match on both peers. Trust alone does not create the credential, so synchronization fails.
- ✗
Configure `ntp master 1` on the router and add `ntp server <ip>`, because a stratum 1 master enforces authentication automatically.
Why it's wrong here
The `ntp master` command makes the router act as an authoritative time source at the given stratum; it does not enable or require authentication. Adding a server alongside a master configuration does not validate that server's keys. This approach changes the router's role rather than securing the peering, and the server could still be accepted without any cryptographic check.
- ✓
Enable `ntp authenticate`, define the key with `ntp authentication-key 1 md5 <key>`, mark it trusted with `ntp trusted-key 1`, then add `ntp server <ip> key 1`.
Why this is correct
This sequence turns on authentication globally, creates the MD5 key, marks that key as trusted so the router accepts it, and associates the key with the server. Each step is required: without `ntp authenticate` the router ignores authentication, without a trusted key it rejects valid packets, and without the key number on the server command it will not use the key for that peer. Together they enforce authenticated peering.
Visual reference
Go deeper
Related to this question
Learn chapter
Spine-Leaf and Software-Defined Network Architectures
Key term
Network Time Protocol
Network Time Protocol (NTP) is a networking protocol that synchronizes the clocks of computers and devices over a network to a common reference time source, typically Coordinated Universal Time (UTC).
Key term
NTP Authentication
NTP Authentication is a security feature that ensures a network device only synchronizes its clock with trusted time servers by using encrypted keys to verify the identity of the time source.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.