A network administrator is configuring MACsec on a Cisco Catalyst switch to secure Layer 2 traffic between two switches. Which two statements about MACsec are true? (Choose two.)
MACsec (802.1AE) provides hop-by-hop encryption and integrity check for Ethernet frames. It encrypts the payload and adds an integrity check value (ICV) to detect tampering. This is correct: it operates at Layer 2 and secures the data link between two directly connected devices.
Why this answer
MACsec (802.1AE) provides Layer 2 encryption and integrity for Ethernet frames, and it is commonly deployed with Cisco TrustSec for switch-to-switch links. It uses MKA for key agreement, not IPsec. It does not encrypt MAC addresses, and it is hop-by-hop rather than end-to-end.
Exam trap
The trap here is assuming MACsec provides end-to-end encryption or that it relies on IPsec, when it is actually a hop-by-hop Layer 2 technology using MKA.