CCNP Architecture Practice Question
A network engineer is implementing Cisco TrustSec in a data center. The engineer wants to enforce security policies based on logical groupings of endpoints rather than IP addresses. Which component is used to assign a Security Group Tag (SGT) to traffic at the ingress point?
⚠ Common exam trap
It's easy for candidates to confuse the role of Cisco ISE, which defines and provides SGT information, with the ingress device that actually applies the tag to the traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ingress enforcement device
In Cisco TrustSec, the ingress enforcement device assigns the Security Group Tag (SGT) to packets as they enter the network. This can be done statically by configuring a port or dynamically via 802.1X authentication and authorization with Cisco ISE. The SGT is then carried in the packet, enabling egress enforcement devices to apply SGACLs based on the tag without re-examining IP addresses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ingress enforcement device
Why this is correct
The ingress enforcement device, such as a switch or wireless controller, assigns the SGT to traffic as it enters the network. It can do this statically via port configuration or dynamically based on authentication and authorization from Cisco ISE. The SGT is then carried in the packet, allowing egress devices to enforce SGACLs based on the tag without needing to reclassify the traffic.
- ✗
Security Group ACL (SGACL)
Why it's wrong here
SGACLs are used to enforce policy based on SGTs, not to assign them. They define which traffic is permitted or denied between security groups. SGACLs are downloaded to enforcement devices and applied to traffic after the SGT has already been assigned. They do not perform the initial tagging of packets at ingress; that is done by a different component.
- ✗
Egress enforcement device
Why it's wrong here
The egress enforcement device is responsible for enforcing SGACLs based on the SGT carried in the packet. It does not assign the SGT; it relies on the tag already being present. If the egress device were to assign the tag, it would be too late for policy enforcement along the path and would not provide consistent classification. The tagging must occur at ingress.
- ✗
Cisco Identity Services Engine (ISE)
Why it's wrong here
Cisco ISE is the policy management platform for TrustSec. It defines security groups and policies, and it can dynamically assign SGTs during authentication. However, ISE itself does not tag the traffic at the ingress point; it provides the SGT information to the network device, which then applies the tag. The actual tagging is performed by the ingress device based on information from ISE.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.