350-401 Security Practice Question
A network security team is deploying MACsec on a Cisco Catalyst 9000 switch series to secure Layer 2 traffic between two switches. Which two statements about MACsec operation are true? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse MACsec with IPsec by assuming it uses IKEv2 or encrypts the entire frame including MAC addresses, when it actually uses MKA and leaves MAC addresses in clear text.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MACsec uses MKA (MACsec Key Agreement) to negotiate session keys between peers.
MACsec is an IEEE 802.1AE standard that provides hop-by-hop encryption and integrity on Ethernet links. It uses GCM-AES-128 for encryption and MKA for key agreement. It does not encrypt MAC addresses, and it does not use IKEv2. It is deployed on switchports, not routed interfaces. Therefore, the two true statements are that it provides hop-by-hop encryption with GCM-AES-128 and that it uses MKA to negotiate session keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MACsec encrypts the entire Ethernet frame including the source and destination MAC addresses.
Why it's wrong here
MACsec does not encrypt the entire frame. It encrypts the payload and some fields but leaves the source and destination MAC addresses in clear text to allow forwarding by intermediate switches. The MACsec header includes a SecTAG and ICV, but the outer MAC addresses remain visible. This statement is incorrect because MAC addresses must be readable for normal Layer 2 forwarding.
- ✓
MACsec uses MKA (MACsec Key Agreement) to negotiate session keys between peers.
Why this is correct
MKA is a protocol defined in IEEE 802.1X-2010 that handles key agreement for MACsec. It elects a key server, distributes secure association keys (SAKs), and manages key rotation. On Cisco switches, MKA must be enabled with a pre-shared key or 802.1X-derived CAK. This statement correctly describes how MACsec establishes and maintains cryptographic keys between peers.
- ✓
MACsec provides hop-by-hop encryption using the GCM-AES-128 cipher suite.
Why this is correct
MACsec operates at Layer 2 and provides hop-by-hop encryption, meaning each link is secured independently. The default cipher suite is GCM-AES-128, which offers both confidentiality and integrity. This is a correct characteristic of MACsec as implemented on Cisco Catalyst switches, ensuring that each Ethernet segment is protected against eavesdropping and tampering.
- ✗
MACsec requires the use of IKEv2 to establish the secure channel between switches.
Why it's wrong here
MACsec does not use IKEv2 for key establishment. IKEv2 is used for IPsec VPNs at Layer 3. MACsec relies on MKA for key agreement, which is a Layer 2 protocol. IKEv2 is not involved in MACsec operations. This statement is incorrect and confuses MACsec with IPsec VPN technologies.
- ✗
MACsec can only be deployed on routed interfaces, not on switchports.
Why it's wrong here
MACsec is designed for switchports and can be enabled on physical switch interfaces in both access and trunk modes. It is a Layer 2 technology, so it is typically deployed on switchports rather than routed interfaces. This statement is false because MACsec is specifically intended for LAN switch environments to secure links between switches or between a switch and an endpoint.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.