Courseiva
Security →hardMultiple Choice

CCNP Security Practice Question

A network security architect is designing a Zero Trust architecture for a campus network using Cisco Identity Services Engine (ISE) and Cisco TrustSec. The requirement is to enforce segmentation based on user identity and device posture, and to apply policy dynamically as users move between wired and wireless access points. Which Cisco TrustSec component is responsible for tagging packets with a Security Group Tag (SGT) at the access layer?

⚠ Common exam trap

A common mix-up: candidates confuse the policy decision point with the enforcement point, when SGT tagging actually occurs on the access device.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The access layer switch or wireless controller that supports Cisco TrustSec.

In Cisco TrustSec, the access layer device performs classification and tagging by inserting the SGT into the packet after authentication and authorization. ISE nodes define and evaluate policy, but they do not tag packets. This design allows dynamic segmentation to follow users as they move between wired and wireless access points.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Policy Administration Node (PAN) in Cisco ISE.

    Why it's wrong here

    The PAN is responsible for creating and distributing policies, including SGT definitions and matrix policies, but it does not tag packets. Tagging occurs at the network device where the endpoint connects. The PAN provides the policy framework, while enforcement and tagging happen at the access layer.

  • ✓

    The access layer switch or wireless controller that supports Cisco TrustSec.

    Why this is correct

    In Cisco TrustSec, the access layer device, such as a Catalyst switch or wireless controller, is responsible for classifying and tagging packets with an SGT after the endpoint is authenticated. This tagging enables enforcement throughout the network based on the Security Group Tag, allowing dynamic segmentation as users move between wired and wireless access points.

  • ✗

    The Policy Enforcement Node (PEN) in Cisco ISE.

    Why it's wrong here

    The PEN, often called the Policy Service Node (PSN), evaluates policy and provides authorization decisions to network devices. It does not insert SGTs into packets. The actual tagging is performed by the network device, such as a switch or wireless controller, after receiving the authorization result from ISE.

  • ✗

    The Cisco DNA Center appliance.

    Why it's wrong here

    Cisco DNA Center provides network automation, assurance, and policy management, but it does not insert SGTs into packets at the access layer. TrustSec tagging is performed by the network device where the endpoint connects, not by a centralized controller. DNA Center may orchestrate policy, but enforcement and tagging remain on the access device.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.