Courseiva
Security →hardMultiple Select

350-401 Security Practice Question

A network engineer is deploying MACsec on a Cisco Catalyst switch to secure point-to-point links between the access and distribution layers. The design must ensure data confidentiality and integrity on the wire, and must use a key agreement mechanism that supports dynamic key exchange. Which TWO of the following are required to meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is treating 802.1X as the key agreement for MACsec, when MKA is the protocol that negotiates and rotates MACsec keys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure MACsec (802.1AE) on the point-to-point interfaces to provide data confidentiality and integrity.

MACsec (802.1AE) supplies Layer 2 encryption and integrity, while MKA provides the dynamic key agreement, peer discovery, and key rotation. Both must be configured on the point-to-point links to meet the confidentiality, integrity, and dynamic key exchange requirements. IPsec, 802.1X, and private VLANs do not deliver Layer 2 link encryption with MKA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure MACsec (802.1AE) on the point-to-point interfaces to provide data confidentiality and integrity.

    Why this is correct

    MACsec, defined in IEEE 802.1AE, provides hop-by-hop encryption and integrity checking at Layer 2 using GCM-AES. Enabling MACsec on the interfaces is what actually secures the wire between access and distribution. MKA alone negotiates keys but does not encrypt frames, so MACsec must be configured to satisfy the confidentiality and integrity requirement.

  • ✗

    Configure a private VLAN between the access and distribution switches to isolate traffic.

    Why it's wrong here

    Private VLANs provide Layer 2 isolation between ports within the same VLAN but do not encrypt traffic or provide integrity protection. An attacker capturing frames on the link could still read them. Since the requirement is confidentiality and integrity on the wire with dynamic key exchange, private VLANs are irrelevant and do not satisfy the design.

  • ✓

    Configure MKA (MACsec Key Agreement) on the participating interfaces to negotiate and rotate keys.

    Why this is correct

    MKA is the control protocol that discovers peers, elects a key server, and negotiates secure association keys used by MACsec. Without MKA, static keys can be used but dynamic key exchange and rotation are not supported. The requirement for dynamic key agreement makes MKA mandatory on the point-to-point links, so this is a required element of the design.

  • ✗

    Configure 802.1X with EAP-TLS on the inter-switch links to establish the encryption keys.

    Why it's wrong here

    802.1X authenticates supplicants to a network and can derive keys for link encryption in some wireless contexts, but it is not the key agreement mechanism for MACsec on wired point-to-point links. MKA handles key negotiation for MACsec. Relying on 802.1X with EAP-TLS would not enable MACsec encryption between the switches and does not meet the design.

  • ✗

    Configure IPsec transport mode between the switches to encrypt all Layer 2 traffic.

    Why it's wrong here

    IPsec operates at Layer 3 and cannot encrypt Layer 2 frames such as those carrying VLAN tags. Using IPsec transport mode between switches would require routed interfaces and would not protect the Ethernet frame header or non-IP traffic. The scenario calls for Layer 2 link security, which IPsec does not provide, so this option fails.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.