350-401 Security Practice Question
A security team wants to deploy MACsec on a Cisco Catalyst switch uplink between two buildings to protect Layer 2 traffic. The switches are Cisco Catalyst 9300 series running IOS XE, and the link must encrypt all frames between them. Which statement accurately describes a requirement for this deployment?
⚠ Common exam trap
The trap here is believing MACsec requires 802.1X or routed ports, when in fact it needs matching key material and MACsec-capable endpoints on the Layer 2 link.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MACsec requires that both switches support the MACsec feature and that a connectivity association key be configured or negotiated before encrypted traffic can flow.
MACsec secures Layer 2 links by encrypting frames using keys derived from a connectivity association. Both endpoints must support MACsec and share matching key material, either pre-shared or via MKA. This allows the uplink between the Catalyst switches to carry encrypted traffic, meeting the requirement to protect all frames on that link.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MACsec can only be enabled on routed ports, so the uplink must be converted from a switchport to a no switchport interface.
Why it's wrong here
MACsec on Catalyst switches is supported on switch ports and can be configured with MKA on point-to-point links; it does not require converting the uplink to a routed port. Converting to a routed port would change the Layer 2 nature of the link and is not a MACsec requirement, so this statement is incorrect for the scenario.
- ✓
MACsec requires that both switches support the MACsec feature and that a connectivity association key be configured or negotiated before encrypted traffic can flow.
Why this is correct
MACsec uses a secure connectivity association defined by a connectivity association key (CAK) and connectivity association key name (CKN), either pre-shared or negotiated via MKA. Both endpoints must support MACsec and agree on keys before encrypted frames can be exchanged. This matches the requirement to protect all Layer 2 traffic on the uplink between the two Catalyst switches.
- ✗
MACsec encrypts only control plane traffic, so data frames between the switches would remain in clear text.
Why it's wrong here
MACsec encrypts all frames on the secured link, including user data, not just control plane traffic. The scenario requires all Layer 2 traffic to be encrypted, and MACsec provides that by securing the entire link. Limiting encryption to control traffic would not satisfy the requirement and misrepresents how MACsec operates.
- ✗
MACsec requires that 802.1X authentication be completed on the link before any encryption keys can be generated.
Why it's wrong here
MACsec key agreement (MKA) can operate independently of 802.1X; keys are derived from the CAK and CKN, not from an EAP exchange. While 802.1X can be used with MACsec in some designs, it is not a prerequisite for encrypting the uplink between two switches, so this option misstates the requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.