Courseiva
Security →hardMultiple Choice

CCNP Security Practice Question

A network security engineer is deploying MACsec on a Cisco Catalyst 9000 switch. The switch is connected to a Cisco IP phone that does not support MACsec, and a PC is connected to the phone. The engineer wants to encrypt traffic between the switch and the phone, but the phone does not support MACsec. What should the engineer do to secure the link?

⚠ Common exam trap

The trap here is assuming that MACsec can be selectively applied or that it can fall back to clear text, when in reality it requires both endpoints to support it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Replace the phone with a MACsec-capable model or use a different encryption method such as IPsec for the traffic.

MACsec is a link-layer encryption protocol that requires both endpoints to support it. If the IP phone does not support MACsec, the switch cannot encrypt traffic to the phone at Layer 2. The engineer must either replace the phone with a MACsec-capable model or use a higher-layer encryption method such as IPsec to secure the traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Replace the phone with a MACsec-capable model or use a different encryption method such as IPsec for the traffic.

    Why this is correct

    Since the phone does not support MACsec, link-layer encryption cannot be established. The engineer must either upgrade to a MACsec-capable phone or use a higher-layer encryption method like IPsec, which can encrypt traffic end-to-end regardless of link-layer capabilities. This is the only viable way to secure the traffic.

  • ✗

    Use a MACsec-capable switch port and enable `macsec` with `fallback` to allow unencrypted traffic if the phone does not support it.

    Why it's wrong here

    The `macsec` command with fallback is not a valid Cisco IOS configuration for allowing unencrypted traffic. MACsec either negotiates encryption or the link fails. There is no fallback to clear text in standard MACsec configuration. This option is technically incorrect and would not secure the link.

  • ✗

    Configure the switch port to use MACsec for the PC traffic and leave the phone traffic unencrypted.

    Why it's wrong here

    MACsec operates at the link layer and encrypts all traffic on the physical link. It cannot selectively encrypt traffic for one device (the PC) and leave another device (the phone) unencrypted on the same port. This option misunderstands how MACsec works and is not feasible.

  • ✗

    Enable MACsec on the switch port with `macsec` and configure the phone to use 802.1X with MAB.

    Why it's wrong here

    The phone does not support MACsec, so enabling MACsec on the switch port would cause the link to fail or fall back to unencrypted mode. Configuring 802.1X with MAB does not provide encryption. The phone's lack of MACsec support means link encryption cannot be established between the switch and the phone.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.