350-401 Exam QuestionsBrowse all questions from this exam

350-401 Exam - Question 597


Refer to the exhibit. An attacker can advertise OSPF fake routes from 172.16.20.0 network to the OSPF domain and black hole traffic. Which action must be taken to avoid this attack and still be able to advertise this subnet into OSPF?

Show Answer
Correct Answer: C

Configuring a passive interface on R2 toward 172.16.20.0 ensures that OSPF advertisements for this network are still seen in the OSPF domain, but the router will not form OSPF neighbor relationships through that interface. This effectively prevents an attacker from advertising fake OSPF routes into the network via the 172.16.20.0 interface, thus enhancing security while still allowing the network to be advertised in OSPF.

Discussion

14 comments
Sign in to comment
BrandOption: C
Feb 12, 2023

The question itself is the definition of "passive interface"

AndreasThornusOption: C
Dec 9, 2022

We labbed this in EVE-NG and setting the interface facing 172.16.20.0/24 does indeed mean this network remains in OSPF but any relationship between a router on that subnet will fail to establish. C is correct.

civanOption: C
Dec 30, 2022

C. Passive interface means R2 won't form neighbor relationships out that interface, and therefore can't learn routes via that subnet

snarkymarkOption: C
Feb 5, 2023

Agree C, https://study-ccna.com/ospf-passive-interface/#:~:text=The%20%27passive%2Dinterface%27%20command,interface%20is%20to%20increase%20security.

shoo83Option: C
Nov 24, 2022

agree with passive interface I choose C

forccnpOption: C
Dec 7, 2022

C is correct

CCNPWILLOption: C
Oct 8, 2023

C. Gimme question.

testcom680Option: C
Nov 20, 2022

i choose C

DarudeOption: C
Nov 22, 2022

reference: https://networklessons.com/ospf/ospf-passive-interface

DatasetOption: C
Nov 22, 2022

i think is C

milovnik1Option: C
Dec 8, 2022

I choose C

HaidaryOption: C
Dec 13, 2023

C is correct Passive interface

SeMo0o0oOption: C
May 24, 2024

C is correct without reading other options

MegonOption: D
Jul 18, 2024

D is the answer as if you look at the question, it is to stop fake routes from being injected into OSPF but we still need to advertise this subnet so there is OSPF neighborship and passive interface is not relevant. Applying filter to reject other router is more realistic