CCNP Security Practice Question
A network security team is deploying MACsec on a Cisco Catalyst 9300 switch connecting to a partner's Catalyst 9200 over a metro Ethernet link. The team wants to encrypt all traffic on the link and ensure that the switches mutually authenticate before any frames are forwarded. Which IEEE standard defines the key agreement and encryption used by MACsec, and which component performs the key exchange?
⚠ Common exam trap
The trap here is assuming that 802.1X itself provides MACsec encryption, when in fact 802.1X-2010 contributes the MKA key agreement and 802.1AE provides the actual frame encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IEEE 802.1AE for encryption and IEEE 802.1X-2010 with MKA for key agreement
MACsec encryption is standardized in IEEE 802.1AE, while the key agreement and mutual authentication between peers are handled by MACsec Key Agreement as defined in IEEE 802.1X-2010. Together they ensure that the Catalyst 9300 and 9200 mutually authenticate and encrypt every frame before any user traffic is forwarded across the metro Ethernet link.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IEEE 802.1AE for encryption and IKEv2 for key agreement
Why it's wrong here
IKEv2 is the key exchange protocol used by IPsec, not MACsec. MACsec operates at Layer 2 and uses MKA, defined in IEEE 802.1X-2010, to derive and distribute secure association keys between directly connected switches. Although IKEv2 provides strong mutual authentication, it is the wrong protocol for a MACsec deployment and would not interoperate with standard MACsec implementations.
- ✗
IEEE 802.1X for encryption and IEEE 802.1AE for key agreement
Why it's wrong here
IEEE 802.1X is a port-based network access control framework, not an encryption standard. It is often used to authenticate supplicants to a RADIUS server, but it does not encrypt data frames. The encryption of MACsec frames is defined by IEEE 802.1AE, and the key agreement is provided by MKA, which is an extension within the 802.1X-2010 family of standards.
- ✓
IEEE 802.1AE for encryption and IEEE 802.1X-2010 with MKA for key agreement
Why this is correct
MACsec encryption is defined by IEEE 802.1AE, which specifies hop-by-hop encryption of Ethernet frames. Key agreement and mutual authentication are provided by MACsec Key Agreement (MKA), which is defined in IEEE 802.1X-2010. The two switches exchange MKPDUs to negotiate a secure association key, so no frames are forwarded in the clear before the session is established, satisfying the mutual authentication requirement.
- ✗
IEEE 802.1Q for tagging and IEEE 802.1AE for key agreement
Why it's wrong here
IEEE 802.1Q defines VLAN tagging and does not provide any cryptographic protection or key agreement. IEEE 802.1AE defines the MACsec frame format and encryption, but it relies on MKA from IEEE 802.1X-2010 to negotiate keys. Confusing 802.1Q with the key agreement mechanism would leave the link without the mutual authentication the team requires.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.