Your group is up, R1 is Active, R2 is Standby, and you know how the roles move when one of them fails. One door is still open: any router can join the group. Time to close it.
A rogue router can join an HSRP group and even promote itself to Active, taking down the default gateway.
Look at the figure below:
Figure 1 – Without authentication, any router can join the group
HSRP authentication closes that gap by requiring every Hello to carry a shared secret.

Figure 2 – With MD5 authentication, the rogue router's Hello is rejected
Here, R1 and R2 share an MD5 key.
The rogue router has no way to guess it, so its Hello is rejected before it can influence the election.Answer the question below
What must every Hello carry for a router to join an authenticated group?
IOS supports plaintext and MD5 authentication.
Plaintext is visible to anyone capturing the Hellos, so always configure MD5 in production.40 % Complete: you’re making great progress
Ready to pass your CCNP exam?