Courseiva
Infrastructure →hardMultiple Choice

CCNP Infrastructure Practice Question

A network engineer is implementing Cisco TrustSec in a campus network. The requirement is to classify traffic based on the identity of the user and the device, and to enforce policy across the network without relying on IP addresses. Which component assigns the Security Group Tag (SGT) to the packet at ingress?

⚠ Common exam trap

The trap here is assuming that ISE, as the policy server, writes the SGT into packets, when ISE only provides the classification and the ingress network device performs tag imposition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ingress access layer switch or router inserts the SGT into the packet using inline tagging or SXP.

In Cisco TrustSec, the ingress network device classifies traffic and imposes the SGT after receiving the classification from ISE. Tag propagation uses inline tagging or SXP, and egress devices enforce Security Group ACLs based on source and destination SGTs. The policy decision comes from ISE, but tag imposition happens at the ingress enforcement point.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The egress switch removes the SGT and applies the Security Group ACL based on the source IP address.

    Why it's wrong here

    The egress device enforces policy by comparing source and destination SGTs against the Security Group ACL, but it does not classify or assign the tag. It also does not use source IP for policy enforcement in a TrustSec design, since the goal is to move away from IP-based rules. This option misstates both the role and the mechanism.

  • ✓

    The ingress access layer switch or router inserts the SGT into the packet using inline tagging or SXP.

    Why this is correct

    The ingress network device is responsible for classifying traffic and imposing the SGT. It receives the SGT value from ISE during authentication, then inserts the tag into the packet using inline tagging (Cisco Metadata or 802.1AE) or propagates the mapping via SXP to devices that do not support inline tagging. This is the enforcement point for tag imposition.

  • ✗

    The Cisco DNA Center appliance assigns the SGT during fabric VXLAN encapsulation.

    Why it's wrong here

    Cisco DNA Center is a management and automation platform, not an inline classification point. In SD-Access, SGTs are carried in VXLAN Group Policy Option headers, but the tag value is determined by ISE policy and imposed at the ingress edge node, not by the controller. This option conflates orchestration with enforcement.

  • ✗

    The Cisco Identity Services Engine (ISE) assigns the SGT directly into the packet header.

    Why it's wrong here

    ISE is the policy and identity authority that determines the SGT value for a user or device, but it does not write the tag into the packet header. Tag imposition occurs on the network device at the ingress point, based on the classification result returned by ISE via RADIUS. Confusing the policy decision point with the enforcement point is a common misunderstanding.

Quick reference

IPv4 Address Class Summary

ClassFirst Octet RangeDefault MaskNetworksHosts per Network
A1–126/8 (255.0.0.0)12616,777,214
B128–191/16 (255.255.0.0)16,38465,534
C192–223/24 (255.255.255.0)2,097,152254
D224–239N/AMulticast groups—
E240–255N/AReserved / experimental—

127.x.x.x is reserved for loopback. Modern networks use CIDR (classless) rather than classful addressing.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.