CCNP Security Practice Question
A network security engineer is deploying MACsec on a Cisco Catalyst 9000 switch. The switch is connected to a Cisco IP phone that does not support MACsec, and a PC is connected to the phone. The engineer wants to encrypt traffic between the switch and the phone, but the phone does not support MACsec. What should the engineer do to secure the link?
⚠ Common exam trap
The trap here is assuming that MACsec can be selectively applied or that it can fall back to clear text, when in reality it requires both endpoints to support it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Replace the phone with a MACsec-capable model or use a different encryption method such as IPsec for the traffic.
MACsec is a link-layer encryption protocol that requires both endpoints to support it. If the IP phone does not support MACsec, the switch cannot encrypt traffic to the phone at Layer 2. The engineer must either replace the phone with a MACsec-capable model or use a higher-layer encryption method such as IPsec to secure the traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Replace the phone with a MACsec-capable model or use a different encryption method such as IPsec for the traffic.
Why this is correct
Since the phone does not support MACsec, link-layer encryption cannot be established. The engineer must either upgrade to a MACsec-capable phone or use a higher-layer encryption method like IPsec, which can encrypt traffic end-to-end regardless of link-layer capabilities. This is the only viable way to secure the traffic.
- ✗
Use a MACsec-capable switch port and enable `macsec` with `fallback` to allow unencrypted traffic if the phone does not support it.
Why it's wrong here
The `macsec` command with fallback is not a valid Cisco IOS configuration for allowing unencrypted traffic. MACsec either negotiates encryption or the link fails. There is no fallback to clear text in standard MACsec configuration. This option is technically incorrect and would not secure the link.
- ✗
Configure the switch port to use MACsec for the PC traffic and leave the phone traffic unencrypted.
Why it's wrong here
MACsec operates at the link layer and encrypts all traffic on the physical link. It cannot selectively encrypt traffic for one device (the PC) and leave another device (the phone) unencrypted on the same port. This option misunderstands how MACsec works and is not feasible.
- ✗
Enable MACsec on the switch port with `macsec` and configure the phone to use 802.1X with MAB.
Why it's wrong here
The phone does not support MACsec, so enabling MACsec on the switch port would cause the link to fail or fall back to unencrypted mode. Configuring 802.1X with MAB does not provide encryption. The phone's lack of MACsec support means link encryption cannot be established between the switch and the phone.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.