Courseiva
Security →hardMultiple Select

350-401 Security Practice Question

A network administrator is configuring MACsec on a Cisco Catalyst switch to secure Layer 2 traffic between two switches. Which two statements about MACsec are true? (Choose two.)

⚠ Common exam trap

The trap here is assuming MACsec provides end-to-end encryption or that it relies on IPsec, when it is actually a hop-by-hop Layer 2 technology using MKA.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MACsec provides encryption and integrity for Ethernet frames at Layer 2.

MACsec (802.1AE) provides Layer 2 encryption and integrity for Ethernet frames, and it is commonly deployed with Cisco TrustSec for switch-to-switch links. It uses MKA for key agreement, not IPsec. It does not encrypt MAC addresses, and it is hop-by-hop rather than end-to-end.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MACsec requires IPsec to establish the secure channel.

    Why it's wrong here

    MACsec uses the MACsec Key Agreement (MKA) protocol defined in 802.1X-2010, not IPsec. MKA negotiates keys and manages the secure association. IPsec is a Layer 3 technology and is not used by MACsec. This statement is incorrect.

  • ✗

    MACsec encrypts the entire Ethernet frame including the source and destination MAC addresses.

    Why it's wrong here

    MACsec encrypts the payload but leaves the MAC addresses and some header fields in clear text to allow switching. The SecTAG and ICV are added. The source and destination MAC addresses are not encrypted because they are needed for forwarding. This statement is incorrect.

  • ✗

    MACsec provides end-to-end encryption between any two hosts in a campus network.

    Why it's wrong here

    MACsec is hop-by-hop; it secures the link between two directly connected devices. It does not provide end-to-end encryption across multiple hops unless every hop supports MACsec. Hosts typically do not run MACsec; it is used on switch-to-switch or switch-to-router links. This statement is incorrect.

  • ✓

    MACsec provides encryption and integrity for Ethernet frames at Layer 2.

    Why this is correct

    MACsec (802.1AE) provides hop-by-hop encryption and integrity check for Ethernet frames. It encrypts the payload and adds an integrity check value (ICV) to detect tampering. This is correct: it operates at Layer 2 and secures the data link between two directly connected devices.

  • ✓

    MACsec can be deployed with Cisco TrustSec to provide encryption on switch-to-switch links.

    Why this is correct

    MACsec is often deployed in conjunction with Cisco TrustSec (CTS) for switch-to-switch links. CTS can use MACsec to encrypt traffic between network devices. This is a valid deployment scenario, and Cisco documentation describes MACsec as a component of TrustSec.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.