350-601 Security • Set 7
350-601 Security Practice Test 7 — 15 questions with explanations. Free, no signup.
Two Cisco Nexus 9000 switches are connected via Ethernet interface 1/1. The engineer wishes to secure the link using MACsec (IEEE 802.1ae) with a pre-shared key for connectivity association key (CAK) protection. Both switches have the same hardware and software version supporting MACsec. The engineer configures the following on both switches:
feature macsec macsec policy MACSEC_POLICY cipher-suite gcm-aes-128 security-mode no-encrypt mka sak-rekey-time 30
interface ethernet 1/1macsec policy MACSEC_POLICY
However, the link comes up without MACsec encryption (the port counter shows MACsec frames dropped). The engineer checks that the pre-shared key is configured correctly via 'macsec key-chain' but notices it was not explicitly applied. What is the most likely reason for MACsec failing to establish?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.