Courseiva
Security →mediumMultiple Select

350-401 Security Practice Question

A network engineer is implementing MACsec on a Cisco Catalyst switch to secure Layer 2 traffic between two campus distribution switches. Which two statements accurately describe MACsec operation on Cisco platforms? (Choose two.)

⚠ Common exam trap

The trap here is conflating MACsec with IPsec by assuming MACsec provides end-to-end protection or uses IKEv2 for key negotiation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MACsec uses the MACsec Key Agreement (MKA) protocol to negotiate and distribute session keys between peers.

MACsec is a Layer 2 hop-by-hop security standard that encrypts Ethernet frames and validates integrity between directly connected devices. The MKA protocol handles key negotiation and distribution, electing a key server and refreshing keys. It does not provide end-to-end protection across Layer 3 hops and does not rely on IKEv2, which belongs to the IPsec suite.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MACsec can secure traffic end-to-end between two hosts separated by multiple Layer 3 hops.

    Why it's wrong here

    MACsec is a link-layer technology that protects frames between adjacent devices. It cannot provide end-to-end protection across Layer 3 boundaries because each router terminates the Layer 2 frame and re-encapsulates traffic. For multi-hop end-to-end protection, technologies like IPsec should be used instead.

  • ✓

    MACsec uses the MACsec Key Agreement (MKA) protocol to negotiate and distribute session keys between peers.

    Why this is correct

    MKA is the control protocol that establishes the secure association between MACsec peers, electing a key server and distributing the secure association key used for encryption. It runs over EAPOL frames and is fundamental to how MACsec maintains and refreshes cryptographic material on a link.

  • ✗

    MACsec requires the use of IKEv2 to establish the security association between switches.

    Why it's wrong here

    IKEv2 is used by IPsec to negotiate security associations at Layer 3, not by MACsec. MACsec relies on MKA for key agreement and does not use IKEv2. Confusing the two protocols leads to incorrect design assumptions about how MACsec peers authenticate and exchange keys.

  • ✗

    MACsec encrypts the entire IP packet including the original source and destination IP addresses.

    Why it's wrong here

    MACsec encrypts the Ethernet payload and adds an integrity check value but does not hide the outer Ethernet header, which includes source and destination MAC addresses. IP addresses inside the payload are encrypted, but the statement's claim about the entire IP packet including outer addressing is inaccurate for MACsec framing.

  • ✓

    MACsec provides hop-by-hop encryption and integrity checking on Ethernet frames between directly connected devices.

    Why this is correct

    MACsec operates at Layer 2 and secures frames on a per-link basis between two directly connected devices using the MKA protocol to negotiate keys. Each hop encrypts and validates frames independently, so traffic is protected only on links where MACsec is enabled, matching the described campus distribution interconnect scenario.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.