nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #337

You work for a large organization that recently implemented a 100GB Cloud Interconnect connection between your Google Cloud and your on-premises edge router. While routinely checking the…

The correct answer is D. Ensure that the active pre-shared key matches on both the on-premises and Google edge. MACsec (IEEE 802.1AE) is a Layer 2 encryption protocol that requires both endpoints to share identical pre-shared keys - specifically the Connectivity Association Key (CAK) and Connectivity Association Key Name (CKN). If the active pre-shared key on the on-premises router does…

Submitted by noor.lb· Apr 18, 2026Configuring network security

Question

You work for a large organization that recently implemented a 100GB Cloud Interconnect connection between your Google Cloud and your on-premises edge router. While routinely checking the connectivity, you noticed that the connection is operational but there is an error message that indicates MACsec is operationally down. You need to resolve this error. What should you do?

Options

  • AEnsure that the Cloud Interconnect connection supports MACsec.
  • BEnsure that the on-premises router is not down.
  • CEnsure that the active pre-shared key created for MACsec is not expired on both the on-premises
  • DEnsure that the active pre-shared key matches on both the on-premises and Google edge

How the community answered

(46 responses)
  • A
    9% (4)
  • B
    7% (3)
  • C
    2% (1)
  • D
    83% (38)

Explanation

MACsec (IEEE 802.1AE) is a Layer 2 encryption protocol that requires both endpoints to share identical pre-shared keys - specifically the Connectivity Association Key (CAK) and Connectivity Association Key Name (CKN). If the active pre-shared key on the on-premises router does not exactly match the key configured on the Google edge router, the MACsec Security Association cannot be established, and MACsec will show as operationally down even though the underlying physical/logical connection is operational. This key mismatch is the most direct cause of MACsec being down when the connection itself is working. Option A is irrelevant since the 100GB connection already supports MACsec (it is configured). Option B is ruled out because the connection is confirmed operational. Option C (expired key) is partially related but expiration is typically a subset of or the result of a key mismatch scenario; a mismatched key is the more fundamental and common cause.

Topics

#MACsec#Cloud Interconnect#Network Security#Troubleshooting

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice