nerdexam
HP

HPE7-A02 · Question #26

Refer to the Exhibit. All of the switches in the exhibit are AOS-CX switches. What is the preferred configuration on Switch-2 for preventing rogue OSPF routers in this network?

The correct answer is C. Configure OSPF authentication on Lag 1 in MD5 mode. Explanation:To prevent rogue OSPF routers in the network shown in the exhibit, the preferred configuration on Switch-2 is to configure OSPF authentication on Lag 1 in MD5 mode. This setup enhances security by ensuring that only routers with the correct MD5 authentication…

Implementing Advanced Security Features

Question

Refer to the Exhibit. All of the switches in the exhibit are AOS-CX switches. What is the preferred configuration on Switch-2 for preventing rogue OSPF routers in this network?

Exhibit

HPE7-A02 question #26 exhibit

Options

  • ADisable OSPF entirely on VLANs 10-19.
  • BConfigure OSPF authentication on VLANs 10-19 in password mode.
  • CConfigure OSPF authentication on Lag 1 in MD5 mode.
  • DConfigure passive-interface as the OSPF default and disable OSPF passive on Lag 1.

How the community answered

(19 responses)
  • A
    11% (2)
  • B
    26% (5)
  • C
    53% (10)
  • D
    11% (2)

Explanation

Explanation:To prevent rogue OSPF routers in the network shown in the exhibit, the preferred configuration on Switch-2 is to configure OSPF authentication on Lag 1 in MD5 mode. This setup enhances security by ensuring that only routers with the correct MD5 authentication credentials can participate in the OSPF routing process. This method protects the OSPF sessions against unauthorized devices that might attempt to introduce rogue routing information into the network. 1. OSPF Authentication: Implementing MD5 authentication on Lag 1 ensures that OSPF updates are secured with a cryptographic hash. This prevents unauthorized OSPF routers from establishing peering sessions and injecting potentially malicious routing information. 2. Secure Communication: MD5 authentication provides a higher level of security compared to simple password authentication, as it uses a more robust hashing algorithm. 3. Applicability: Lag 1 is the primary link between Switch-1 and Switch-2, and securing this link helps protect the integrity of the OSPF routing domain.

Topics

#OSPF authentication#MD5#rogue router prevention#AOS-CX routing security

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice