Courseiva
Security →hardMultiple Choice

CCNP Security Practice Question

A network security team is deploying MACsec on a Cisco Catalyst 9000 switch uplink between two buildings to protect Layer 2 traffic. The team wants to ensure that the link encrypts traffic and that the peer is authenticated before secure communication begins. Which configuration approach meets these requirements?

⚠ Common exam trap

Many candidates confuse Layer 3 IPsec with Layer 2 MACsec and assuming a crypto map can be applied to a switch uplink for hop-by-hop encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable MACsec with MKA using a pre-shared key or 802.1X-derived CAK, and set the switchport to macsec desired or must.

MACsec provides Layer 2 hop-by-hop encryption and integrity using 802.1AE, with the MACsec Key Agreement protocol handling key exchange and peer authentication. On Catalyst 9000, the supported design uses MKA with a connectivity association key from a pre-shared key or 802.1X, plus an interface mode of macsec desired or macsec must to enforce encrypted, authenticated links.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable IPsec transport mode on the switch uplink with a crypto map and IKEv2 pre-shared key.

    Why it's wrong here

    Cisco Catalyst switches do not support IPsec transport mode with crypto maps on standard switchports for this purpose; IPsec is a Layer 3 VPN technology typically used on routers or firewalls. Applying a crypto map to a switch uplink does not provide the Layer 2 hop-by-hop encryption and peer authentication that MACsec delivers, so the requirement is not met.

  • ✗

    Enable port security with sticky MAC addresses and storm control on the uplink to secure the connection.

    Why it's wrong here

    Port security and storm control limit MAC addresses and traffic rates but do not encrypt traffic or authenticate the peer device. They provide access control and availability protection at Layer 2, not confidentiality or cryptographic peer authentication. This approach leaves the uplink traffic in cleartext and does not satisfy the encryption and authentication requirements.

  • ✓

    Enable MACsec with MKA using a pre-shared key or 802.1X-derived CAK, and set the switchport to macsec desired or must.

    Why this is correct

    MACsec on Catalyst 9000 uses the MACsec Key Agreement protocol to negotiate secure associations and authenticate peers. Configuring MKA with a connectivity association key either as a pre-shared key or derived from 802.1X, and setting the interface to macsec desired or macsec must, ensures encryption and peer authentication before traffic passes, which matches the stated requirement.

  • ✗

    Enable 802.1AE without MKA and manually configure static secure associations on both ends.

    Why it's wrong here

    While 802.1AE defines the MACsec frame format, Cisco implementations rely on MKA for key management and peer authentication. Manually configuring static secure associations without MKA is not the supported operational model on Catalyst 9000 and does not provide the dynamic peer authentication and rekeying that the requirement implies. This approach would be operationally fragile and unsupported.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.