CCNP Security Practice Question
A security architect is designing a network where endpoint identity and group membership must follow users and devices across both wired and wireless networks, and policy enforcement must be consistent regardless of VLAN or IP subnet. Which Cisco solution provides this identity-based, group-based access control?
⚠ Common exam trap
It's easy for candidates to confuse visibility and analytics products with enforcement technologies that actually tag and control traffic by identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco TrustSec with Security Group Tags and Cisco ISE
Cisco TrustSec uses Security Group Tags derived from identity and group information, typically populated by Cisco ISE, to enforce policy independent of IP addresses and VLANs. Because the tags travel with the traffic, consistent access control is maintained across wired and wireless networks, which matches the architect's requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cisco AnyConnect with posture assessment only
Why it's wrong here
AnyConnect provides VPN and endpoint posture checks, which help ensure devices meet security requirements before access. However, posture alone does not create identity-based group tags that follow traffic across the campus fabric. It is a component that can feed ISE, but it does not by itself deliver the VLAN-independent group-based enforcement described.
- ✗
Cisco Umbrella with DNS-layer security and SIG
Why it's wrong here
Cisco Umbrella protects DNS and internet-bound traffic by blocking malicious domains and enforcing acceptable use, but it does not tag internal endpoint identity for east-west access control across wired and wireless networks. It operates at the DNS and secure internet gateway layers, so it cannot enforce group-based policy for internal VLAN-independent access.
- ✓
Cisco TrustSec with Security Group Tags and Cisco ISE
Why this is correct
Cisco TrustSec assigns Security Group Tags to users and devices based on identity and group membership determined by Cisco ISE, and enforcement uses those tags rather than IP addresses or VLANs. This allows consistent policy across wired and wireless domains. Because tags travel with the traffic, access control remains intact even when subnets or VLANs change.
- ✗
Cisco Stealthwatch with NetFlow analytics
Why it's wrong here
Stealthwatch collects flow telemetry and uses analytics to detect anomalies and threats, providing visibility rather than enforcement. It can identify suspicious behavior but does not assign identity tags or enforce access policy based on group membership. This scenario requires active access control, so a monitoring and analytics platform does not satisfy the design goal.
Visual reference
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.