350-401 Security Practice Question
A network engineer is deploying MACsec on a Cisco Catalyst switch to secure point-to-point links between the access and distribution layers. The design must ensure data confidentiality and integrity on the wire, and must use a key agreement mechanism that supports dynamic key exchange. Which TWO of the following are required to meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is treating 802.1X as the key agreement for MACsec, when MKA is the protocol that negotiates and rotates MACsec keys.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure MACsec (802.1AE) on the point-to-point interfaces to provide data confidentiality and integrity.
MACsec (802.1AE) supplies Layer 2 encryption and integrity, while MKA provides the dynamic key agreement, peer discovery, and key rotation. Both must be configured on the point-to-point links to meet the confidentiality, integrity, and dynamic key exchange requirements. IPsec, 802.1X, and private VLANs do not deliver Layer 2 link encryption with MKA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure MACsec (802.1AE) on the point-to-point interfaces to provide data confidentiality and integrity.
Why this is correct
MACsec, defined in IEEE 802.1AE, provides hop-by-hop encryption and integrity checking at Layer 2 using GCM-AES. Enabling MACsec on the interfaces is what actually secures the wire between access and distribution. MKA alone negotiates keys but does not encrypt frames, so MACsec must be configured to satisfy the confidentiality and integrity requirement.
- ✗
Configure a private VLAN between the access and distribution switches to isolate traffic.
Why it's wrong here
Private VLANs provide Layer 2 isolation between ports within the same VLAN but do not encrypt traffic or provide integrity protection. An attacker capturing frames on the link could still read them. Since the requirement is confidentiality and integrity on the wire with dynamic key exchange, private VLANs are irrelevant and do not satisfy the design.
- ✓
Configure MKA (MACsec Key Agreement) on the participating interfaces to negotiate and rotate keys.
Why this is correct
MKA is the control protocol that discovers peers, elects a key server, and negotiates secure association keys used by MACsec. Without MKA, static keys can be used but dynamic key exchange and rotation are not supported. The requirement for dynamic key agreement makes MKA mandatory on the point-to-point links, so this is a required element of the design.
- ✗
Configure 802.1X with EAP-TLS on the inter-switch links to establish the encryption keys.
Why it's wrong here
802.1X authenticates supplicants to a network and can derive keys for link encryption in some wireless contexts, but it is not the key agreement mechanism for MACsec on wired point-to-point links. MKA handles key negotiation for MACsec. Relying on 802.1X with EAP-TLS would not enable MACsec encryption between the switches and does not meet the design.
- ✗
Configure IPsec transport mode between the switches to encrypt all Layer 2 traffic.
Why it's wrong here
IPsec operates at Layer 3 and cannot encrypt Layer 2 frames such as those carrying VLAN tags. Using IPsec transport mode between switches would require routed interfaces and would not protect the Ethernet frame header or non-IP traffic. The scenario calls for Layer 2 link security, which IPsec does not provide, so this option fails.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
Key term
MACsec
MACsec (Media Access Control Security) is a security protocol that encrypts and authenticates data at the Ethernet frame level to protect traffic on local area networks.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.