Courseiva
mediumMultiple ChoiceObjective-mapped

350-701 Practice Question: Wants to enforce micro-segmentation in a data…

An organization wants to enforce micro-segmentation in a data center to isolate application tiers. Which Cisco technology allows defining security policies based on endpoint groups rather than IP addresses?

⚠ Common exam trap

Cisco often tests the distinction between IP-based ACLs (ASA) and identity-based segmentation (TrustSec), so the trap here is assuming that any firewall or NGFW can achieve micro-segmentation without understanding that TrustSec's SGTs are specifically designed for endpoint-group policies independent of IP addresses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Cisco TrustSec with Security Group Tags (SGTs)

Cisco TrustSec uses Security Group Tags (SGTs) to classify traffic based on endpoint groups (e.g., application tiers) rather than IP addresses. This allows micro-segmentation by enforcing policies that follow the traffic regardless of IP changes, using SGTs carried in the packet via Cisco Metadata (CMD) or inline tagging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cisco ASA with access-lists

    Why it's wrong here

    Traditional ACLs are IP-based and do not provide dynamic group-based segmentation.

  • Cisco TrustSec with Security Group Tags (SGTs)

    Why this is correct

    TrustSec uses SGTs for group-based policy enforcement, ideal for micro-segmentation.

  • Cisco ISE with guest services

    Why it's wrong here

    ISE provides authentication and policy, but guest services are not for micro-segmentation.

  • Cisco Firepower NGFW with URL filtering

    Why it's wrong here

    URL filtering is used for web traffic control, not for network micro-segmentation.

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.