Courseiva
Security →mediumMultiple Choice

CCNP Security Practice Question

A network administrator is deploying Cisco TrustSec in a campus network. The security team wants to enforce role-based access control between endpoints without relying on IP addresses or VLANs, and they need to ensure that access policies are consistently applied even when endpoints move between switches. The administrator has already configured Cisco ISE for authentication and authorization. Which technology should be used to propagate the security group tag (SGT) information to network devices that do not support SGT tagging natively?

⚠ Common exam trap

Watch out — candidates often confuse SGT propagation with SGT enforcement or authentication, assuming that any security feature can carry SGT information when only SXP is designed for that purpose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SXP (SGT Exchange Protocol)

SXP is designed to share SGT-to-IP bindings with devices that cannot natively tag packets with SGTs, enabling consistent role-based access control across mixed hardware. The other options either provide encryption, authentication, or tunneling but do not propagate SGT information. In a Cisco TrustSec deployment where some switches lack hardware SGT support, SXP bridges the gap so that SGACLs can still be enforced based on the endpoint's security group.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MACsec (802.1AE)

    Why it's wrong here

    MACsec provides hop-by-hop encryption and integrity on Ethernet links, not SGT propagation. It secures the data plane between adjacent devices but does not carry security group tag information to devices that lack native SGT support. While it can protect SGT-tagged frames on the wire, it does not solve the problem of delivering SGT mappings to non-capable hardware, so it fails the scenario requirement.

  • ✗

    IPsec VPN tunnels

    Why it's wrong here

    IPsec VPN tunnels provide encrypted connectivity between sites or remote users, not SGT propagation. They operate at Layer 3 and do not carry Cisco TrustSec SGT metadata between network devices. While IPsec can secure traffic, it does not enable role-based access control based on SGTs across a campus network. Thus, it is unrelated to the propagation requirement described.

  • ✓

    SXP (SGT Exchange Protocol)

    Why this is correct

    SXP is a Cisco TrustSec protocol that propagates SGT-to-IP mappings to network devices that cannot natively tag packets with SGTs. It allows enforcement of security group ACLs (SGACLs) on devices that lack hardware SGT support by exchanging IP-to-SGT bindings with peer devices. This enables consistent policy enforcement across mixed hardware, which matches the scenario's requirement for propagation to non-SGT-capable devices.

  • ✗

    802.1X with EAP-TLS

    Why it's wrong here

    802.1X with EAP-TLS is an authentication method used to validate endpoint identity and assign an SGT via ISE. It does not propagate SGT information to network devices that lack native tagging capability. The scenario already states that ISE authentication and authorization are configured, so the missing piece is propagation, not authentication. Therefore, this option does not address the requirement.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.