Courseiva
hardMultiple SelectObjective-mapped

CCNP Practice Question: Which three statements about Cisco TrustSec…

Which three statements about Cisco TrustSec security group access control lists (SGACLs) are true? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SGACLs define policies based on source and destination security group tags.

SGACLs are applied based on source and destination SGTs, they are downloaded from the Cisco ISE, and they can be used to permit or deny traffic. Option A is correct because SGACLs are policy rules based on SGTs. Option B is correct because ISE distributes SGACLs to network devices. Option D is correct because SGACLs enforce permit/deny decisions. Option C is incorrect because SGACLs are not applied to interfaces like traditional ACLs; they are applied to SGT pairs. Option E is incorrect because SGACLs do not modify packets; they just enforce policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • SGACLs define policies based on source and destination security group tags.

    Why this is correct

    Correct; SGACLs use SGTs to determine access rights.

  • SGACLs are typically downloaded from the Cisco ISE policy server to network devices.

    Why this is correct

    Correct; ISE pushes SGACL definitions to switches and routers.

  • SGACLs are applied directly to switch ports using the ip access-group command.

    Why it's wrong here

    Incorrect; SGACLs are not interface ACLs; they are applied to SGT pairs via the Cisco TrustSec policy.

  • SGACLs can be used to permit or deny traffic between different security groups.

    Why this is correct

    Correct; SGACLs enforce permit or deny actions between SGTs.

  • SGACLs can rewrite the security group tag in the packet header.

    Why it's wrong here

    Incorrect; SGACLs do not modify packets; they only enforce policy. SGT rewriting is done by other mechanisms.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 350-401 question is part of Courseiva's 1,175-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.