CCNP Security Practice Question
A network security team is deploying MACsec on a Cisco Catalyst 9000 switch uplink between two buildings to protect Layer 2 traffic. The team wants to ensure that the link encrypts traffic and that the peer is authenticated before secure communication begins. Which configuration approach meets these requirements?
⚠ Common exam trap
Many candidates confuse Layer 3 IPsec with Layer 2 MACsec and assuming a crypto map can be applied to a switch uplink for hop-by-hop encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable MACsec with MKA using a pre-shared key or 802.1X-derived CAK, and set the switchport to macsec desired or must.
MACsec provides Layer 2 hop-by-hop encryption and integrity using 802.1AE, with the MACsec Key Agreement protocol handling key exchange and peer authentication. On Catalyst 9000, the supported design uses MKA with a connectivity association key from a pre-shared key or 802.1X, plus an interface mode of macsec desired or macsec must to enforce encrypted, authenticated links.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable IPsec transport mode on the switch uplink with a crypto map and IKEv2 pre-shared key.
Why it's wrong here
Cisco Catalyst switches do not support IPsec transport mode with crypto maps on standard switchports for this purpose; IPsec is a Layer 3 VPN technology typically used on routers or firewalls. Applying a crypto map to a switch uplink does not provide the Layer 2 hop-by-hop encryption and peer authentication that MACsec delivers, so the requirement is not met.
- ✗
Enable port security with sticky MAC addresses and storm control on the uplink to secure the connection.
Why it's wrong here
Port security and storm control limit MAC addresses and traffic rates but do not encrypt traffic or authenticate the peer device. They provide access control and availability protection at Layer 2, not confidentiality or cryptographic peer authentication. This approach leaves the uplink traffic in cleartext and does not satisfy the encryption and authentication requirements.
- ✓
Enable MACsec with MKA using a pre-shared key or 802.1X-derived CAK, and set the switchport to macsec desired or must.
Why this is correct
MACsec on Catalyst 9000 uses the MACsec Key Agreement protocol to negotiate secure associations and authenticate peers. Configuring MKA with a connectivity association key either as a pre-shared key or derived from 802.1X, and setting the interface to macsec desired or macsec must, ensures encryption and peer authentication before traffic passes, which matches the stated requirement.
- ✗
Enable 802.1AE without MKA and manually configure static secure associations on both ends.
Why it's wrong here
While 802.1AE defines the MACsec frame format, Cisco implementations rely on MKA for key management and peer authentication. Manually configuring static secure associations without MKA is not the supported operational model on Catalyst 9000 and does not provide the dynamic peer authentication and rekeying that the requirement implies. This approach would be operationally fragile and unsupported.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.