350-401 Security Practice Question
A network engineer is implementing MACsec on a Cisco Catalyst switch to secure Layer 2 traffic between two campus distribution switches. Which two statements accurately describe MACsec operation on Cisco platforms? (Choose two.)
⚠ Common exam trap
The trap here is conflating MACsec with IPsec by assuming MACsec provides end-to-end protection or uses IKEv2 for key negotiation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MACsec uses the MACsec Key Agreement (MKA) protocol to negotiate and distribute session keys between peers.
MACsec is a Layer 2 hop-by-hop security standard that encrypts Ethernet frames and validates integrity between directly connected devices. The MKA protocol handles key negotiation and distribution, electing a key server and refreshing keys. It does not provide end-to-end protection across Layer 3 hops and does not rely on IKEv2, which belongs to the IPsec suite.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MACsec can secure traffic end-to-end between two hosts separated by multiple Layer 3 hops.
Why it's wrong here
MACsec is a link-layer technology that protects frames between adjacent devices. It cannot provide end-to-end protection across Layer 3 boundaries because each router terminates the Layer 2 frame and re-encapsulates traffic. For multi-hop end-to-end protection, technologies like IPsec should be used instead.
- ✓
MACsec uses the MACsec Key Agreement (MKA) protocol to negotiate and distribute session keys between peers.
Why this is correct
MKA is the control protocol that establishes the secure association between MACsec peers, electing a key server and distributing the secure association key used for encryption. It runs over EAPOL frames and is fundamental to how MACsec maintains and refreshes cryptographic material on a link.
- ✗
MACsec requires the use of IKEv2 to establish the security association between switches.
Why it's wrong here
IKEv2 is used by IPsec to negotiate security associations at Layer 3, not by MACsec. MACsec relies on MKA for key agreement and does not use IKEv2. Confusing the two protocols leads to incorrect design assumptions about how MACsec peers authenticate and exchange keys.
- ✗
MACsec encrypts the entire IP packet including the original source and destination IP addresses.
Why it's wrong here
MACsec encrypts the Ethernet payload and adds an integrity check value but does not hide the outer Ethernet header, which includes source and destination MAC addresses. IP addresses inside the payload are encrypted, but the statement's claim about the entire IP packet including outer addressing is inaccurate for MACsec framing.
- ✓
MACsec provides hop-by-hop encryption and integrity checking on Ethernet frames between directly connected devices.
Why this is correct
MACsec operates at Layer 2 and secures frames on a per-link basis between two directly connected devices using the MKA protocol to negotiate keys. Each hop encrypts and validates frames independently, so traffic is protected only on links where MACsec is enabled, matching the described campus distribution interconnect scenario.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.