350-401 exam dumps

350-401 practice question 300 of 631

Implementing Cisco Enterprise Network Core Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-401 Question 300

Select 3

A network administrator is tasked with implementing enhanced security for sensitive traffic between switches in a campus LAN. They decide to use Cisco TrustSec to enforce role-based access control and MACsec to provide encryption for data in motion. Which requirements must be met to successfully deploy this solution?

  1. A

    All participating devices must support Cisco TrustSec and MACsec.

  2. B

    The switches must have Secure Group Tag (SGT) support enabled.

  3. C

    A RADIUS server is required for MACsec Key Agreement (MKA).

  4. D

    IEEE 802.1X must be configured on all endpoints to enable MACsec.

  5. E

    A key management protocol such as MKA is required for MACsec operation.

Show answer and explanation

Correct answers: A, B, E

Explanation

To successfully deploy Cisco TrustSec and MACsec, all devices in the network must support these technologies. Cisco TrustSec relies on Secure Group Tags (SGTs) to enforce role-based access control. For MACsec, a key management protocol like MKA is necessary to handle encryption keys for securing data in motion. While IEEE 802.1X and RADIUS can enhance security and authentication, they are not strictly mandatory for deploying MACsec and TrustSec in all scenarios.

  • A. Correct.

    Correct: Both Cisco TrustSec and MACsec require device compatibility to work as expected. All devices must support these technologies to ensure proper enforcement and encryption.

  • B. Correct.

    Correct: Cisco TrustSec uses Secure Group Tags (SGTs) to enforce role-based access control. Enabling SGT support is essential for TrustSec to function.

  • C. Incorrect.

    Incorrect: A RADIUS server is not required for MACsec itself. While RADIUS can be used for authentication in some scenarios, it is not a mandatory component for MACsec Key Agreement.

  • D. Incorrect.

    Incorrect: MACsec can operate without requiring IEEE 802.1X on all endpoints. While 802.1X is commonly used with MACsec, it is not strictly mandatory for all deployments.

  • E. Correct.

    Correct: MACsec requires a key management protocol, such as MACsec Key Agreement (MKA), to establish and manage encryption keys for secure communication.

Timed practice exam

Take a 350-401 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam