PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #337
You work for a large organization that recently implemented a 100GB Cloud Interconnect connection between your Google Cloud and your on-premises edge router. While routinely checking the…
The correct answer is D. Ensure that the active pre-shared key matches on both the on-premises and Google edge. MACsec (IEEE 802.1AE) is a Layer 2 encryption protocol that requires both endpoints to share identical pre-shared keys - specifically the Connectivity Association Key (CAK) and Connectivity Association Key Name (CKN). If the active pre-shared key on the on-premises router does…
Question
Options
- AEnsure that the Cloud Interconnect connection supports MACsec.
- BEnsure that the on-premises router is not down.
- CEnsure that the active pre-shared key created for MACsec is not expired on both the on-premises
- DEnsure that the active pre-shared key matches on both the on-premises and Google edge
How the community answered
(46 responses)- A9% (4)
- B7% (3)
- C2% (1)
- D83% (38)
Explanation
MACsec (IEEE 802.1AE) is a Layer 2 encryption protocol that requires both endpoints to share identical pre-shared keys - specifically the Connectivity Association Key (CAK) and Connectivity Association Key Name (CKN). If the active pre-shared key on the on-premises router does not exactly match the key configured on the Google edge router, the MACsec Security Association cannot be established, and MACsec will show as operationally down even though the underlying physical/logical connection is operational. This key mismatch is the most direct cause of MACsec being down when the connection itself is working. Option A is irrelevant since the 100GB connection already supports MACsec (it is configured). Option B is ruled out because the connection is confirmed operational. Option C (expired key) is partially related but expiration is typically a subset of or the result of a key mismatch scenario; a mismatched key is the more fundamental and common cause.
Topics
Community Discussion
No community discussion yet for this question.