Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityHard

A small business is setting up its first network and wants to ensure that all internal network traffic is protected from eavesdropping by unauthorized devices, even if they gain access to the physical network. The business needs a solution that encrypts all data packets exchanged between devices on the local network. Which security technology should be implemented?

  1. AARP Inspection
  2. BPort Mirroring
  3. CDHCP Snooping
  4. DMACsec (802.1AE)
Show answer & explanation

Correct answer: D. MACsec (802.1AE)

MACsec (Media Access Control Security), defined by IEEE 802.1AE, provides point-to-point encryption and authentication for Ethernet frames at Layer 2. This ensures that all data packets exchanged between devices on the local network are encrypted and authenticated, protecting against eavesdropping and tampering even within the physical network.

Why the other options are wrong

  • A. ARP Inspection prevents ARP spoofing attacks but does not encrypt data packets.
  • B. Port Mirroring (SPAN) copies traffic for analysis but does not encrypt or secure the traffic itself.
  • C. DHCP Snooping prevents rogue DHCP servers but does not encrypt local network traffic.

MACsec (802.1AE)

IEEE 802.1AE (MACsec) is a standard for providing connectionless data confidentiality and integrity for media access independent protocols.

  • Provides Layer 2 encryption and authentication.
  • Protects against eavesdropping and tampering on local networks.
  • Ensures data integrity and confidentiality for Ethernet frames.

Memory trick: MACsec Makes All Communication Secure.

More Network Security questions