CCNP Security Practice Question
A network engineer is deploying MACsec on a Catalyst switch uplink between two buildings to protect Layer 2 traffic. Which two statements about MACsec operation on Cisco Catalyst switches are true? (Choose two.)
⚠ Common exam trap
The trap here is treating MACsec as end-to-end encryption when it actually protects each Layer 2 hop independently.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MACsec requires an MKA session and a connectivity association key to establish secure associations between peers.
MACsec secures individual Ethernet links using 802.1AE encryption and integrity, and it relies on MKA with a connectivity association key to negotiate secure associations between peers. Because it operates hop by hop, each device along the path must participate, and it does not replace 802.1X or provide end-to-end encryption across a routed network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MACsec encrypts traffic end to end from the originating host to the final destination host across all intermediate routers.
Why it's wrong here
MACsec is a link-layer technology that protects frames only between directly connected devices. Each intermediate router or switch decrypts and re-encrypts the frame, so it is not end-to-end encryption. For host-to-host protection across a routed path, technologies such as IPsec or TLS are required instead of MACsec.
- ✓
MACsec requires an MKA session and a connectivity association key to establish secure associations between peers.
Why this is correct
The MACsec Key Agreement protocol negotiates session keys between peers using a connectivity association key, which can be provided statically or derived through 802.1X. Without a successful MKA session, the link will not pass protected traffic. This key management layer distinguishes MACsec from simple link encryption and ensures both ends agree on cipher suites and key material.
- ✗
MACsec replaces 802.1X and removes the need for any authentication server in the network.
Why it's wrong here
MACsec and 802.1X are complementary, not mutually exclusive. 802.1X can authenticate endpoints and derive keys used by MKA, while MACsec protects the link. Deployments often use Cisco ISE as the authentication server to distribute keys, so MACsec does not eliminate the need for an authentication framework or server in managed environments.
- ✓
MACsec provides hop-by-hop encryption and integrity for Ethernet frames using the 802.1AE standard.
Why this is correct
MACsec, defined by IEEE 802.1AE, secures the Layer 2 link by encrypting and authenticating each frame between directly connected devices. It operates per physical link, so each hop must support and negotiate MACsec independently. This hop-by-hop model protects traffic on the wire between switches while leaving the frames decrypted inside each device for normal forwarding decisions.
- ✗
MACsec can be deployed only on routed ports and is incompatible with switch access ports.
Why it's wrong here
MACsec is commonly deployed on switch-to-switch links and can also protect host-facing access ports when the endpoint supports it. It is not limited to routed ports. In fact, many campus designs use MACsec on trunk or access switch links, and some Catalyst platforms support MACsec on uplinks and downlinks depending on hardware and licensing.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.