CCNP Security Practice Question
A network administrator is deploying Cisco TrustSec in a campus network. The security team wants to enforce role-based access control between endpoints without relying on IP addresses or VLANs, and they need to ensure that access policies are consistently applied even when endpoints move between switches. The administrator has already configured Cisco ISE for authentication and authorization. Which technology should be used to propagate the security group tag (SGT) information to network devices that do not support SGT tagging natively?
⚠ Common exam trap
Watch out — candidates often confuse SGT propagation with SGT enforcement or authentication, assuming that any security feature can carry SGT information when only SXP is designed for that purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SXP (SGT Exchange Protocol)
SXP is designed to share SGT-to-IP bindings with devices that cannot natively tag packets with SGTs, enabling consistent role-based access control across mixed hardware. The other options either provide encryption, authentication, or tunneling but do not propagate SGT information. In a Cisco TrustSec deployment where some switches lack hardware SGT support, SXP bridges the gap so that SGACLs can still be enforced based on the endpoint's security group.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MACsec (802.1AE)
Why it's wrong here
MACsec provides hop-by-hop encryption and integrity on Ethernet links, not SGT propagation. It secures the data plane between adjacent devices but does not carry security group tag information to devices that lack native SGT support. While it can protect SGT-tagged frames on the wire, it does not solve the problem of delivering SGT mappings to non-capable hardware, so it fails the scenario requirement.
- ✗
IPsec VPN tunnels
Why it's wrong here
IPsec VPN tunnels provide encrypted connectivity between sites or remote users, not SGT propagation. They operate at Layer 3 and do not carry Cisco TrustSec SGT metadata between network devices. While IPsec can secure traffic, it does not enable role-based access control based on SGTs across a campus network. Thus, it is unrelated to the propagation requirement described.
- ✓
SXP (SGT Exchange Protocol)
Why this is correct
SXP is a Cisco TrustSec protocol that propagates SGT-to-IP mappings to network devices that cannot natively tag packets with SGTs. It allows enforcement of security group ACLs (SGACLs) on devices that lack hardware SGT support by exchanging IP-to-SGT bindings with peer devices. This enables consistent policy enforcement across mixed hardware, which matches the scenario's requirement for propagation to non-SGT-capable devices.
- ✗
802.1X with EAP-TLS
Why it's wrong here
802.1X with EAP-TLS is an authentication method used to validate endpoint identity and assign an SGT via ISE. It does not propagate SGT information to network devices that lack native tagging capability. The scenario already states that ISE authentication and authorization are configured, so the missing piece is propagation, not authentication. Therefore, this option does not address the requirement.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.