Courseiva
Security →hardMultiple Choice

CCNP Security Practice Question

A network security team is deploying MACsec on a Cisco Catalyst 9300 switch connecting to a partner's Catalyst 9200 over a metro Ethernet link. The team wants to encrypt all traffic on the link and ensure that the switches mutually authenticate before any frames are forwarded. Which IEEE standard defines the key agreement and encryption used by MACsec, and which component performs the key exchange?

⚠ Common exam trap

The trap here is assuming that 802.1X itself provides MACsec encryption, when in fact 802.1X-2010 contributes the MKA key agreement and 802.1AE provides the actual frame encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IEEE 802.1AE for encryption and IEEE 802.1X-2010 with MKA for key agreement

MACsec encryption is standardized in IEEE 802.1AE, while the key agreement and mutual authentication between peers are handled by MACsec Key Agreement as defined in IEEE 802.1X-2010. Together they ensure that the Catalyst 9300 and 9200 mutually authenticate and encrypt every frame before any user traffic is forwarded across the metro Ethernet link.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IEEE 802.1AE for encryption and IKEv2 for key agreement

    Why it's wrong here

    IKEv2 is the key exchange protocol used by IPsec, not MACsec. MACsec operates at Layer 2 and uses MKA, defined in IEEE 802.1X-2010, to derive and distribute secure association keys between directly connected switches. Although IKEv2 provides strong mutual authentication, it is the wrong protocol for a MACsec deployment and would not interoperate with standard MACsec implementations.

  • ✗

    IEEE 802.1X for encryption and IEEE 802.1AE for key agreement

    Why it's wrong here

    IEEE 802.1X is a port-based network access control framework, not an encryption standard. It is often used to authenticate supplicants to a RADIUS server, but it does not encrypt data frames. The encryption of MACsec frames is defined by IEEE 802.1AE, and the key agreement is provided by MKA, which is an extension within the 802.1X-2010 family of standards.

  • ✓

    IEEE 802.1AE for encryption and IEEE 802.1X-2010 with MKA for key agreement

    Why this is correct

    MACsec encryption is defined by IEEE 802.1AE, which specifies hop-by-hop encryption of Ethernet frames. Key agreement and mutual authentication are provided by MACsec Key Agreement (MKA), which is defined in IEEE 802.1X-2010. The two switches exchange MKPDUs to negotiate a secure association key, so no frames are forwarded in the clear before the session is established, satisfying the mutual authentication requirement.

  • ✗

    IEEE 802.1Q for tagging and IEEE 802.1AE for key agreement

    Why it's wrong here

    IEEE 802.1Q defines VLAN tagging and does not provide any cryptographic protection or key agreement. IEEE 802.1AE defines the MACsec frame format and encryption, but it relies on MKA from IEEE 802.1X-2010 to negotiate keys. Confusing 802.1Q with the key agreement mechanism would leave the link without the mutual authentication the team requires.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.