350-401 Security Practice Question
A network security team is deploying MACsec on Cisco Catalyst switches to protect Layer 2 traffic between two distribution switches. They want to ensure that the link is encrypted and that only authorized devices can participate in the secured session. Which two statements about MACsec operation on Cisco platforms are correct? (Choose two.)
⚠ Common exam trap
The trap here is assuming MACsec is a Layer 3 IPsec-like technology or that it sends keys in clear text, when it is actually a Layer 2 frame encryption method with secure MKA key exchange.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MACsec can be configured in switch-to-host mode where the host runs an 802.1X supplicant that supports MACsec key agreement, allowing encryption to the endpoint.
MACsec secures Ethernet frames using MKA to negotiate keys, supporting both pre-shared CAK and 802.1X-based key derivation. It can be deployed switch-to-switch or switch-to-host when the endpoint has a MACsec-capable supplicant. These two facts address the requirement for encryption and authorized participation on the Layer 2 link.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
MACsec can be configured in switch-to-host mode where the host runs an 802.1X supplicant that supports MACsec key agreement, allowing encryption to the endpoint.
Why this is correct
Cisco supports MACsec in switch-to-host deployments, where the endpoint runs a supplicant capable of MKA, such as the Cisco AnyConnect Network Access Manager or a compatible NIC driver. This extends encryption to the access edge rather than only between switches. It requires 802.1X authentication and a supplicant that supports MACsec, but it is a valid and commonly deployed mode.
- ✓
MACsec uses the MKA protocol to negotiate and exchange keys between peers, and it can be configured with a pre-shared key or with 802.1X-based key derivation.
Why this is correct
MACsec relies on the MACsec Key Agreement protocol to establish a secure channel and derive session keys. Cisco supports both static CAK pre-shared keys and dynamic key derivation via 802.1X with MKA, allowing integration with ISE for scalable deployments. The MKA exchange authenticates peers before any encrypted traffic flows, which satisfies the requirement for authorized participation.
- ✗
MACsec is only supported on routed ports and cannot be enabled on switch access ports or EtherChannel member links.
Why it's wrong here
MACsec is supported on various interface types, including switch access ports and EtherChannel member links, depending on platform and license. Saying it is limited to routed ports is inaccurate and would unnecessarily restrict design options. In campus deployments, MACsec is frequently used on uplinks and access ports to secure Layer 2 traffic between switches and endpoints.
- ✗
MACsec encryption keys are exchanged in clear text during the MKA handshake, so the link is only protected against physical taps after the session is established.
Why it's wrong here
MKA does not exchange encryption keys in clear text. The CAK is used to derive a KEK and ICK, and the SAK is distributed encrypted with the KEK. This design prevents eavesdroppers from learning the session keys even if they capture the handshake. The statement misrepresents how MKA protects key distribution and would lead to an incorrect security assessment.
- ✗
MACsec operates at Layer 3 and encrypts IP packets between routers, requiring IPsec configuration on the participating interfaces.
Why it's wrong here
MACsec is a Layer 2 technology that secures Ethernet frames, not Layer 3 IP packets. It does not use IPsec and does not encrypt routed traffic in the way described. Confusing MACsec with IPsec leads to incorrect design assumptions, since MACsec protects the hop-by-hop Ethernet link while IPsec protects end-to-end or gateway-to-gateway IP flows.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Wireless Deployment Models and Security
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
Key term
MACsec
MACsec (Media Access Control Security) is a security protocol that encrypts and authenticates data at the Ethernet frame level to protect traffic on local area networks.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.