Which statement correctly describes MACsec?
Choose an answer
Tap an option to check your answer.
Correct answer: 802.1AE is established between host and switch via MKA, which derives encryption keys from the primary session key of a successful 802.1X session..
Why this is the answer
MACsec (802.1AE) is a Layer 2 security protocol that provides hop-by-hop encryption and authentication. It is established between a host and a switch using the MACsec Key Agreement (MKA) protocol. MKA is responsible for discovering MACsec-capable peers and negotiating the session keys. When 802.1X is used for authentication, MKA derives the encryption keys for MACsec from the primary session key generated during a successful 802.1X authentication. This ensures that only authenticated devices can establish a secure MACsec session. The incorrect options are: Cisco AnyConnect NAM and SAP are not used for MACsec negotiation; MKA is the standard. While Diffie-Hellman can be used in some key exchange scenarios, MKA is the specific protocol for MACsec key agreement, and it typically uses keys derived from 802.1X or pre-shared keys, not necessarily anonymous Diffie-Hellman for the primary key derivation in this context. While 802.1AE does provide encryption and authentication, this statement is incomplete and less precise than the correct option, which details the key establishment mechanism.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed