Courseiva
Security →hardMultiple Choice

CCNP Security Practice Question

A security architect is designing a network where endpoint identity and group membership must follow users and devices across both wired and wireless networks, and policy enforcement must be consistent regardless of VLAN or IP subnet. Which Cisco solution provides this identity-based, group-based access control?

⚠ Common exam trap

It's easy for candidates to confuse visibility and analytics products with enforcement technologies that actually tag and control traffic by identity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cisco TrustSec with Security Group Tags and Cisco ISE

Cisco TrustSec uses Security Group Tags derived from identity and group information, typically populated by Cisco ISE, to enforce policy independent of IP addresses and VLANs. Because the tags travel with the traffic, consistent access control is maintained across wired and wireless networks, which matches the architect's requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cisco AnyConnect with posture assessment only

    Why it's wrong here

    AnyConnect provides VPN and endpoint posture checks, which help ensure devices meet security requirements before access. However, posture alone does not create identity-based group tags that follow traffic across the campus fabric. It is a component that can feed ISE, but it does not by itself deliver the VLAN-independent group-based enforcement described.

  • ✗

    Cisco Umbrella with DNS-layer security and SIG

    Why it's wrong here

    Cisco Umbrella protects DNS and internet-bound traffic by blocking malicious domains and enforcing acceptable use, but it does not tag internal endpoint identity for east-west access control across wired and wireless networks. It operates at the DNS and secure internet gateway layers, so it cannot enforce group-based policy for internal VLAN-independent access.

  • ✓

    Cisco TrustSec with Security Group Tags and Cisco ISE

    Why this is correct

    Cisco TrustSec assigns Security Group Tags to users and devices based on identity and group membership determined by Cisco ISE, and enforcement uses those tags rather than IP addresses or VLANs. This allows consistent policy across wired and wireless domains. Because tags travel with the traffic, access control remains intact even when subnets or VLANs change.

  • ✗

    Cisco Stealthwatch with NetFlow analytics

    Why it's wrong here

    Stealthwatch collects flow telemetry and uses analytics to detect anomalies and threats, providing visibility rather than enforcement. It can identify suspicious behavior but does not assign identity tags or enforce access policy based on group membership. This scenario requires active access control, so a monitoring and analytics platform does not satisfy the design goal.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.