hardMultiple Choice
CCNP Practice Question: Is implementing MACsec on a Cisco…
A network engineer is implementing MACsec on a Cisco switch-to-switch link to provide encryption. Both switches support MACsec and are configured with the same pre-shared key (PSK). The engineer configures 'mka' and 'macsec' on the interfaces. After configuration, the link does not come up, and the engineer sees 'MKA not operational' in the show macsec status. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the misconception that MACsec always requires a RADIUS server or 802.1X, but the question explicitly states a PSK is configured, so the trap is to overlook that the PSK mismatch is the direct cause of MKA failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The pre-shared key (PSK) configured on both switches does not match.
The 'MKA not operational' error indicates that the MACsec Key Agreement (MKA) protocol cannot establish a secure session. Since both switches are configured with a pre-shared key (PSK), the most likely cause is that the PSK values do not match, preventing MKA from completing the mutual authentication and key derivation process. MKA relies on the Connectivity Association Key (CAK) derived from the PSK; mismatched PSKs result in different CAKs, causing the MKA exchange to fail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The pre-shared key (PSK) configured on both switches does not match.
Why this is correct
MKA (MACsec Key Agreement) requires both peers to derive the same Connectivity Association Key (CAK) from the configured pre-shared key. If the PSKs differ, each switch computes a different CAK, so MKA authentication fails and no secure channel is established. This is the most direct cause of MACsec failing on a point-to-point link when both ends are configured with PSKs.
- ✗
MACsec requires a RADIUS server for key distribution, which is not configured.
Why it's wrong here
MACsec does not mandate RADIUS for key distribution; it supports two modes: PSK-based and EAP-based (which can use RADIUS). With a PSK, the key is locally configured and MKA runs directly over the link, so a missing RADIUS server is irrelevant. Since the scenario mentions a PSK on both switches, the lack of RADIUS cannot be the reason for failure.
- ✗
The interfaces are configured with different VLANs, causing MACsec to fail.
Why it's wrong here
MACsec encrypts frames at Layer 2 after any VLAN tagging or access VLAN decisions are made, so it is completely independent of VLAN membership. Even if the switches are in different VLANs, MKA still runs on the physical link and can establish a secure channel; VLAN mismatch would cause data-plane forwarding issues but not a failure to negotiate MACsec.
- ✗
The interfaces must be configured as trunk ports for MACsec to work.
Why it's wrong here
MACsec is agnostic to the interface mode and works identically on access and trunk ports. The MKA protocol operates on the physical link regardless of VLAN tagging, and the secure channel protects all frames on that link. Requiring trunk ports is a common misconception; access ports support MACsec exactly the same way.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.