Courseiva
Architecture →hardMultiple Choice

CCNP Architecture Practice Question

A network engineer is implementing Cisco TrustSec in a data center. The engineer wants to enforce security policies based on logical groupings of endpoints rather than IP addresses. Which component is used to assign a Security Group Tag (SGT) to traffic at the ingress point?

⚠ Common exam trap

It's easy for candidates to confuse the role of Cisco ISE, which defines and provides SGT information, with the ingress device that actually applies the tag to the traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ingress enforcement device

In Cisco TrustSec, the ingress enforcement device assigns the Security Group Tag (SGT) to packets as they enter the network. This can be done statically by configuring a port or dynamically via 802.1X authentication and authorization with Cisco ISE. The SGT is then carried in the packet, enabling egress enforcement devices to apply SGACLs based on the tag without re-examining IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ingress enforcement device

    Why this is correct

    The ingress enforcement device, such as a switch or wireless controller, assigns the SGT to traffic as it enters the network. It can do this statically via port configuration or dynamically based on authentication and authorization from Cisco ISE. The SGT is then carried in the packet, allowing egress devices to enforce SGACLs based on the tag without needing to reclassify the traffic.

  • ✗

    Security Group ACL (SGACL)

    Why it's wrong here

    SGACLs are used to enforce policy based on SGTs, not to assign them. They define which traffic is permitted or denied between security groups. SGACLs are downloaded to enforcement devices and applied to traffic after the SGT has already been assigned. They do not perform the initial tagging of packets at ingress; that is done by a different component.

  • ✗

    Egress enforcement device

    Why it's wrong here

    The egress enforcement device is responsible for enforcing SGACLs based on the SGT carried in the packet. It does not assign the SGT; it relies on the tag already being present. If the egress device were to assign the tag, it would be too late for policy enforcement along the path and would not provide consistent classification. The tagging must occur at ingress.

  • ✗

    Cisco Identity Services Engine (ISE)

    Why it's wrong here

    Cisco ISE is the policy management platform for TrustSec. It defines security groups and policies, and it can dynamically assign SGTs during authentication. However, ISE itself does not tag the traffic at the ingress point; it provides the SGT information to the network device, which then applies the tag. The actual tagging is performed by the ingress device based on information from ISE.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.