Courseiva
Security →hardMultiple Choice

350-401 Security Practice Question

A network engineer is deploying MACsec on a Cisco Catalyst 9300 switch to secure a point-to-point link between two access switches. The engineer configures the switchport with the macsec command and a pre-shared key. After applying the configuration, the link comes up but MACsec is not encrypting traffic. Which action should the engineer take to resolve the issue?

⚠ Common exam trap

The trap here is assuming that enabling MACsec on the interface is sufficient, without ensuring MKA parameters match on both ends of the link.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the key server protocol (MKA) with a matching connectivity association key (CAK) on both switches and ensure the key server priority is set.

MACsec relies on MKA to establish a secure channel between two directly connected devices. For MKA to succeed, both peers must share the same connectivity association key and agree on the key server. If these parameters are missing or mismatched, the link remains up but MACsec encryption does not activate. Verifying and matching the MKA configuration on both switches is the correct troubleshooting step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply the macsec command under the VLAN interface instead of the physical interface.

    Why it's wrong here

    MACsec is configured on the physical switchport, not on a VLAN interface (SVI). Applying it to an SVI is not supported and would not encrypt traffic on the point-to-point link. The physical interface is where the MACsec encryption and MKA negotiation occur. Moving the configuration to an SVI would not resolve the lack of encryption.

  • ✗

    Change the switchport mode to trunk to allow MACsec frames to pass.

    Why it's wrong here

    MACsec operates at Layer 2 and does not depend on the switchport mode being trunk or access. The encryption is applied to the physical link regardless of VLAN tagging. Changing to trunk mode would not enable MACsec encryption and could alter VLAN behavior unnecessarily. The issue is with MKA negotiation, not the port mode.

  • ✗

    Enable MACsec globally using the macsec command in global configuration mode.

    Why it's wrong here

    MACsec on Cisco switches is enabled per interface, not globally. There is no global macsec command that enables the feature across all ports. The configuration must be applied under the specific interface that will carry the secured link. Enabling it globally would not resolve the issue and is not a valid configuration step for MACsec on Catalyst platforms.

  • ✓

    Configure the key server protocol (MKA) with a matching connectivity association key (CAK) on both switches and ensure the key server priority is set.

    Why this is correct

    MACsec requires MKA to negotiate session keys between peers. If the CAK or key server priority does not match on both ends, MKA will not establish a secure association, and MACsec will not encrypt traffic even though the link is up. Configuring a matching CAK and designating a key server on both switches allows MKA to complete negotiation, after which MACsec encryption begins.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.