Courseiva
Security →mediumMultiple Choice

CCNP Security Practice Question

A network security team deploys Cisco TrustSec on a Catalyst 9500 fabric. The team wants to enforce a policy where a user authenticated into the 'Contractor' security group tag (SGT) is denied access to servers tagged with the 'Finance' SGT, while remaining able to reach the 'Printers' SGT. Which enforcement mechanism applies the SGACL to traffic between the tagging devices?

⚠ Common exam trap

It's easy for candidates to confuse SXP, which propagates SGT bindings, with SGACL enforcement, which actually denies the traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SGACL enforcement applied on the egress enforcement device using the SGT carried in the Cisco Metadata (CMD) header.

Cisco TrustSec enforces group-based policy by inserting the source SGT into the Cisco Metadata header and evaluating SGACLs on the egress enforcement device against the destination SGT. The policy matrix authored on ISE defines deny Contractor-to-Finance and permit Contractor-to-Printers, and the enforcement device applies it inline. SXP only propagates bindings, dACLs only filter at the port, and MACsec only secures the link.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    802.1X with downloadable ACLs pushed from Cisco ISE to the access switch on the user's port.

    Why it's wrong here

    Downloadable ACLs are port-based and only filter traffic entering the access port, not east-west traffic between SGT-tagged endpoints across the fabric. They cannot enforce a group-to-group policy such as Contractor-to-Finance, so they do not meet the inter-group requirement.

  • ✗

    SGT Exchange Protocol (SXP) on the enforcement device, mapping IP addresses to SGTs at the egress point.

    Why it's wrong here

    SXP propagates SGT-to-IP bindings between TrustSec domains that cannot carry the Cisco Metadata header inline, such as legacy devices. It does not itself enforce SGACLs; enforcement still requires an SGACL-capable device with the appropriate policy matrix, so this alone does not deny Contractor-to-Finance traffic.

  • ✗

    MACsec encryption with MKA on the fabric uplinks, which implicitly denies unauthorized SGT combinations.

    Why it's wrong here

    MACsec provides hop-by-hop encryption and integrity for Ethernet frames; it does not inspect SGTs or apply SGACLs. It has no role in enforcing the Contractor-to-Finance deny rule, so it cannot satisfy the group-based access policy described.

  • ✓

    SGACL enforcement applied on the egress enforcement device using the SGT carried in the Cisco Metadata (CMD) header.

    Why this is correct

    SGACLs are evaluated on the enforcement device using the source and destination SGTs carried in the Cisco Metadata header. This allows the fabric to deny Contractor-to-Finance while permitting Contractor-to-Printers based on the policy matrix defined on Cisco ISE, satisfying the requirement precisely.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.