Courseiva
Security →hardMultiple Select

CCNP Security Practice Question

A network security team is implementing Cisco TrustSec in a campus network. They need to deploy Security Group Tags (SGTs) and enforce policies using Security Group ACLs (SGACLs). Which two statements are true regarding SGT propagation and enforcement in this environment? (Choose two.)

⚠ Common exam trap

The trap here is assuming SGTs are carried in the IP header or that enforcement is limited to ingress, while the actual mechanisms are inline tagging and SXP with enforcement at multiple points.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SGT Exchange Protocol (SXP) is used to propagate SGTs to devices that do not support hardware-based tagging.

SGTs can be propagated inline using Cisco Metadata on supported hardware, and SXP is used for devices that cannot do inline tagging. These two methods allow flexible deployment in mixed environments. SGACLs can be enforced at various points, not just ingress, and SGTs are not carried in DSCP. SXP does not mandate IPsec.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SGT Exchange Protocol (SXP) is used to propagate SGTs to devices that do not support hardware-based tagging.

    Why this is correct

    SXP is a control-plane protocol that maps IP addresses to SGTs and is used to propagate SGT information to devices that cannot perform inline tagging, such as older switches or routers. It allows these devices to enforce SGACLs based on the SGT mapping. This is a key component of TrustSec for mixed environments.

  • ✗

    SXP requires the use of IPsec for secure communication between peers.

    Why it's wrong here

    SXP does not require IPsec; it can be secured using TCP MD5 authentication or other methods, but IPsec is not mandatory. SXP is a TCP-based protocol that can be protected with authentication, but IPsec is not a requirement. This statement is false because it overstates the security requirements for SXP.

  • ✓

    SGTs can be propagated inline within the Ethernet frame using Cisco Metadata (CMD) on supported hardware.

    Why this is correct

    Cisco TrustSec supports inline tagging where the SGT is inserted into the Ethernet frame using Cisco Metadata (CMD) on hardware that supports it, such as Cisco Catalyst 9000 series switches. This allows the tag to be carried natively without encapsulation, enabling enforcement at each hop. This is a valid method for SGT propagation in a TrustSec deployment.

  • ✗

    SGACLs are enforced only on the ingress interface where the SGT is assigned.

    Why it's wrong here

    SGACLs can be enforced at multiple points in the network, not just the ingress interface. In fact, enforcement typically occurs at the egress interface or at a central enforcement point, depending on the design. The ingress device assigns the SGT, but enforcement can happen elsewhere. This statement is false because it restricts enforcement to ingress only.

  • ✗

    SGTs are always carried in the IP header using the DSCP field.

    Why it's wrong here

    SGTs are not carried in the IP header DSCP field. They are either inline in the Ethernet frame using CMD or propagated via SXP. The DSCP field is used for QoS marking, not for SGT transport. This statement is incorrect because it misidentifies the transport mechanism for SGTs.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.