CCNP Security Practice Question
A security architect is designing a Cisco TrustSec deployment for a campus network. The architect needs to ensure that security group tags (SGTs) are propagated across a Layer 2 trunk between two Catalyst switches that do not support SGACL enforcement. Which technology should be used to carry SGT information inline within the Ethernet frame?
⚠ Common exam trap
Many exam-takers confuse SXP with inline tagging; SXP exchanges SGT bindings out-of-band, while CMD embeds the tag directly in the frame.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco Meta Data (CMD)
Cisco Meta Data (CMD) is the inline tagging mechanism in Cisco TrustSec that inserts the SGT into the Ethernet frame. It enables SGT propagation across switches that may not enforce SGACLs, allowing downstream devices to apply policies. This satisfies the requirement for inline SGT carriage over a Layer 2 trunk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MACsec
Why it's wrong here
MACsec provides Layer 2 encryption and integrity but does not carry SGT information. It secures the link but does not propagate group tags. While MACsec can be used with TrustSec, it does not fulfill the requirement of inline SGT propagation. The architect needs a method to embed SGTs in the frame, which MACsec does not provide.
- ✗
SXP
Why it's wrong here
SXP (SGT Exchange Protocol) propagates SGT bindings between devices that cannot use inline tagging, but it does so out-of-band via TCP, not inline within the Ethernet frame. The question specifies inline propagation, so SXP is not the correct choice. SXP is used when hardware does not support inline tagging, but it does not embed SGTs in the data frame.
- ✗
802.1Q tunneling (QinQ)
Why it's wrong here
802.1Q tunneling (QinQ) is used to encapsulate VLAN tags for service provider networks, not to carry SGTs. It adds an outer VLAN tag but does not include security group tag information. While it can preserve VLAN tags, it does not propagate SGTs inline. The architect requires a TrustSec-specific tagging method, which QinQ is not.
- ✓
Cisco Meta Data (CMD)
Why this is correct
Cisco Meta Data (CMD) is the inline tagging method that embeds the SGT directly into the Ethernet frame using a special EtherType. It allows SGT propagation across Layer 2 trunks without requiring SGACL enforcement on every switch. This is the correct technology for carrying SGT information inline in the frame, enabling TrustSec propagation across the campus.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.