Courseiva
Security →hardMultiple Choice

CCNP Security Practice Question

A security architect is designing segmentation for a data center using Cisco TrustSec. The requirement is that classification of traffic into Security Group Tags (SGTs) occur at the access layer based on the identity of the user or device, and that enforcement occur at the data center core where the SGT-to-SGACL matrix is applied. Which statement describes the correct deployment approach?

⚠ Common exam trap

The trap here is reversing classification and enforcement points, or assuming SGACL enforcement happens on the access switch using dACLs rather than on TrustSec-capable devices in the core using the SGT matrix.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SGTs are assigned by the access switch using 802.1X or SXP, propagated in the SGT Exchange Protocol or inline tagging, and enforced by SGACLs on the core device.

TrustSec's strength is the separation of classification from enforcement. Identity-based classification happens as close to the source as possible at the access layer, using 802.1X, MAB, or SXP to assign SGTs. Tags then travel across the fabric via inline tagging or SXP propagation. Enforcement devices, typically in the distribution or core, apply SGACLs derived from the SGT matrix, allowing consistent policy regardless of IP addressing or topology changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SGTs are assigned by Cisco ISE to the core switch, and enforcement is performed by the access switch using downloadable ACLs.

    Why it's wrong here

    ISE is the policy and identity source that can authorize SGTs, but the SGT must be applied at the ingress access device and propagated. Downloadable ACLs are IP-based access lists pushed to switches and do not implement the group-based SGACL enforcement model. This option confuses dACL behavior with TrustSec SGACL enforcement and misplaces the enforcement point.

  • ✓

    SGTs are assigned by the access switch using 802.1X or SXP, propagated in the SGT Exchange Protocol or inline tagging, and enforced by SGACLs on the core device.

    Why this is correct

    TrustSec separates classification from enforcement. Access-layer devices assign SGTs based on identity (802.1X, MAB) or receive them via SXP from upstream, then propagate the tag in the packet header using inline tagging (CMD) or via SXP to devices that cannot tag. Enforcement devices at the core apply SGACLs from the SGT matrix. This matches the described architecture.

  • ✗

    SGTs are assigned at the core based on destination subnet, and enforcement occurs at the access layer using PACLs.

    Why it's wrong here

    Classification at the core based on destination subnet contradicts identity-based tagging and loses the ability to differentiate users or device types that share subnets. Enforcement with PACLs at the access layer is a port-based mechanism unrelated to SGACL enforcement, which requires TrustSec-capable hardware and the SGACL matrix. This reverses the intended classification and enforcement points.

  • ✗

    SGTs are carried in IPsec ESP headers across the data center, and enforcement is performed by the Cisco ASA using the SGT matrix.

    Why it's wrong here

    TrustSec inline tagging uses the Cisco Metadata (CMD) header in Ethernet frames or the SGT field in IP headers on supported platforms, not IPsec ESP headers. Enforcement is performed by TrustSec-capable switches and routers using SGACLs, not the ASA's SGT matrix in the described architecture. This misrepresents both the tagging transport and the enforcement platform.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.