Courseiva
Security →mediumMultiple Select

350-401 Security Practice Question

A network security team is deploying MACsec on a Cisco Catalyst 9000 switch series to secure Layer 2 traffic between two switches. Which two statements about MACsec operation are true? (Choose two.)

⚠ Common exam trap

It's easy for candidates to confuse MACsec with IPsec by assuming it uses IKEv2 or encrypts the entire frame including MAC addresses, when it actually uses MKA and leaves MAC addresses in clear text.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MACsec uses MKA (MACsec Key Agreement) to negotiate session keys between peers.

MACsec is an IEEE 802.1AE standard that provides hop-by-hop encryption and integrity on Ethernet links. It uses GCM-AES-128 for encryption and MKA for key agreement. It does not encrypt MAC addresses, and it does not use IKEv2. It is deployed on switchports, not routed interfaces. Therefore, the two true statements are that it provides hop-by-hop encryption with GCM-AES-128 and that it uses MKA to negotiate session keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MACsec encrypts the entire Ethernet frame including the source and destination MAC addresses.

    Why it's wrong here

    MACsec does not encrypt the entire frame. It encrypts the payload and some fields but leaves the source and destination MAC addresses in clear text to allow forwarding by intermediate switches. The MACsec header includes a SecTAG and ICV, but the outer MAC addresses remain visible. This statement is incorrect because MAC addresses must be readable for normal Layer 2 forwarding.

  • ✓

    MACsec uses MKA (MACsec Key Agreement) to negotiate session keys between peers.

    Why this is correct

    MKA is a protocol defined in IEEE 802.1X-2010 that handles key agreement for MACsec. It elects a key server, distributes secure association keys (SAKs), and manages key rotation. On Cisco switches, MKA must be enabled with a pre-shared key or 802.1X-derived CAK. This statement correctly describes how MACsec establishes and maintains cryptographic keys between peers.

  • ✓

    MACsec provides hop-by-hop encryption using the GCM-AES-128 cipher suite.

    Why this is correct

    MACsec operates at Layer 2 and provides hop-by-hop encryption, meaning each link is secured independently. The default cipher suite is GCM-AES-128, which offers both confidentiality and integrity. This is a correct characteristic of MACsec as implemented on Cisco Catalyst switches, ensuring that each Ethernet segment is protected against eavesdropping and tampering.

  • ✗

    MACsec requires the use of IKEv2 to establish the secure channel between switches.

    Why it's wrong here

    MACsec does not use IKEv2 for key establishment. IKEv2 is used for IPsec VPNs at Layer 3. MACsec relies on MKA for key agreement, which is a Layer 2 protocol. IKEv2 is not involved in MACsec operations. This statement is incorrect and confuses MACsec with IPsec VPN technologies.

  • ✗

    MACsec can only be deployed on routed interfaces, not on switchports.

    Why it's wrong here

    MACsec is designed for switchports and can be enabled on physical switch interfaces in both access and trunk modes. It is a Layer 2 technology, so it is typically deployed on switchports rather than routed interfaces. This statement is false because MACsec is specifically intended for LAN switch environments to secure links between switches or between a switch and an endpoint.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.