Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityEasy
A network administrator needs to secure communication between two directly connected switches in a data center to prevent unauthorized devices from intercepting or tampering with traffic on that specific link. Which security protocol is best suited for encrypting and authenticating traffic at Layer 2?
- AIPsec
- BMACsec
- CSSL/TLS
- DSSH
Show answer & explanationAnswer & explanation
Correct answer: B. MACsec
MACsec (Media Access Control Security) operates at Layer 2 (data link layer) and provides hop-by-hop encryption and authentication for Ethernet frames, making it ideal for securing direct links between network devices.
Why the other options are wrong
- A. IPsec operates at Layer 3 (network layer).
- C. SSL/TLS operates at Layer 4-7 (transport/application layers).
- D. SSH operates at Layer 7 (application layer) for secure remote access.
MACsec (802.1AE)
A security standard that provides hop-by-hop, Layer 2 encryption and authentication for Ethernet frames.
- Operates at the Data Link Layer (Layer 2).
- Secures point-to-point Ethernet links.
- Uses AES-GCM for encryption and integrity.
Memory trick: Each network layer has its own bodyguard.