Courseiva
Security →mediumMultiple Choice

CCNP Security Practice Question

A network administrator is deploying Cisco TrustSec in a campus network. The security team wants to enforce access policy based on a device's role rather than its IP address, so that the enforced policy remains consistent even when endpoints move between VLANs or subnets. Which Cisco TrustSec component is responsible for assigning and carrying this role-based identity through the network?

⚠ Common exam trap

The trap here is assuming that endpoint profiling or encryption alone delivers role-based enforcement, when only the Security Group Tag actually carries role identity in the data plane.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security Group Tag (SGT) applied at ingress and propagated via inline tagging or SXP.

Role-based enforcement in TrustSec depends on Security Group Tags that travel with the traffic. The ingress device classifies the packet and inserts the SGT; downstream devices enforce the Security Group ACL based on that tag. Because the tag, not the IP address, drives policy, endpoints keep the same access rights after moving between VLANs and subnets, satisfying the stated requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IPsec tunnel established between the access switch and the Cisco DNA Center appliance.

    Why it's wrong here

    IPsec tunnels encrypt traffic between endpoints but do not distribute role identity. DNA Center is a management platform and does not participate in TrustSec data-plane enforcement. This option confuses management-plane connectivity with the data-plane tagging mechanism TrustSec actually uses for role-based access control.

  • ✓

    Security Group Tag (SGT) applied at ingress and propagated via inline tagging or SXP.

    Why this is correct

    The SGT is a 16-bit value inserted into the frame or packet at the ingress device, which then enforces policy at egress based on the tag instead of IP. Propagation via inline tagging or the SGT Exchange Protocol (SXP) keeps role identity intact across VLAN and subnet boundaries, which is exactly what the security team requires.

  • ✗

    MACsec encryption applied on the uplink between access and distribution switches.

    Why it's wrong here

    MACsec provides hop-by-hop Layer 2 confidentiality and integrity, not role-based access enforcement. It encrypts frames but does not carry group membership, so it cannot enforce policy according to a device's role. Using MACsec alone would leave access decisions dependent on IP or MAC addresses, which fails the mobility requirement.

  • ✗

    Cisco Identity Services Engine (ISE) profiling the endpoint after DHCP and HTTP probes.

    Why it's wrong here

    ISE profiling identifies device type and can assign an SGT through authorization, but profiling alone does not carry the role identity across the network. Without a tag or SXP propagation, downstream devices cannot enforce role-based policy consistently as endpoints move. Profiling is a supporting function, not the transport mechanism.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

IPv4 Address Class Summary

ClassFirst Octet RangeDefault MaskNetworksHosts per Network
A1–126/8 (255.0.0.0)12616,777,214
B128–191/16 (255.255.0.0)16,38465,534
C192–223/24 (255.255.255.0)2,097,152254
D224–239N/AMulticast groups—
E240–255N/AReserved / experimental—

127.x.x.x is reserved for loopback. Modern networks use CIDR (classless) rather than classful addressing.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.