CCNP Security Practice Question
A network administrator is configuring MACsec on a Cisco Catalyst switch to secure Layer 2 traffic between two switches. Which two statements about MACsec are true? (Choose two.)
⚠ Common exam trap
The trap here is assuming MACsec provides end-to-end encryption or that it relies on IPsec, when it is actually a hop-by-hop Layer 2 technology using MKA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MACsec provides encryption and integrity for Ethernet frames at Layer 2.
MACsec (802.1AE) provides Layer 2 encryption and integrity for Ethernet frames, and it is commonly deployed with Cisco TrustSec for switch-to-switch links. It uses MKA for key agreement, not IPsec. It does not encrypt MAC addresses, and it is hop-by-hop rather than end-to-end.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MACsec requires IPsec to establish the secure channel.
Why it's wrong here
MACsec uses the MACsec Key Agreement (MKA) protocol defined in 802.1X-2010, not IPsec. MKA negotiates keys and manages the secure association. IPsec is a Layer 3 technology and is not used by MACsec. This statement is incorrect.
- ✗
MACsec encrypts the entire Ethernet frame including the source and destination MAC addresses.
Why it's wrong here
MACsec encrypts the payload but leaves the MAC addresses and some header fields in clear text to allow switching. The SecTAG and ICV are added. The source and destination MAC addresses are not encrypted because they are needed for forwarding. This statement is incorrect.
- ✗
MACsec provides end-to-end encryption between any two hosts in a campus network.
Why it's wrong here
MACsec is hop-by-hop; it secures the link between two directly connected devices. It does not provide end-to-end encryption across multiple hops unless every hop supports MACsec. Hosts typically do not run MACsec; it is used on switch-to-switch or switch-to-router links. This statement is incorrect.
- ✓
MACsec provides encryption and integrity for Ethernet frames at Layer 2.
Why this is correct
MACsec (802.1AE) provides hop-by-hop encryption and integrity check for Ethernet frames. It encrypts the payload and adds an integrity check value (ICV) to detect tampering. This is correct: it operates at Layer 2 and secures the data link between two directly connected devices.
- ✓
MACsec can be deployed with Cisco TrustSec to provide encryption on switch-to-switch links.
Why this is correct
MACsec is often deployed in conjunction with Cisco TrustSec (CTS) for switch-to-switch links. CTS can use MACsec to encrypt traffic between network devices. This is a valid deployment scenario, and Cisco documentation describes MACsec as a component of TrustSec.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.