Courseiva
easyMultiple SelectObjective-mapped

350-701 Practice Question: Which TWO of the following are common security…

Which TWO of the following are common security objectives of the Cisco TrustSec solution? (Choose two.)

⚠ Common exam trap

Cisco often tests the distinction between TrustSec's microsegmentation (using SGTs) and encryption (e.g., IPsec or MACsec), so the trap here is assuming that TrustSec provides end-to-end encryption when it actually focuses on access control and segmentation, not data confidentiality.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsegmentation of network traffic

Cisco TrustSec uses Security Group Tags (SGTs) to enforce microsegmentation by classifying traffic based on user, device, or role rather than IP addresses. This allows granular policy enforcement at the access layer, reducing lateral movement within the network. Microsegmentation is a core security objective of TrustSec, enabling dynamic, identity-based access control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsegmentation of network traffic

    Why this is correct

    TrustSec allows granular segmentation based on security groups.

  • VPN termination for remote users

    Why it's wrong here

    TrustSec does not terminate VPNs; that's done by VPN concentrators.

  • End-to-end data encryption

    Why it's wrong here

    TrustSec focuses on access control, not encryption.

  • Network topology discovery

    Why it's wrong here

    Network discovery is a function of protocols like LLDP, not a security objective.

  • Role-based access control using security group tags (SGTs)

    Why this is correct

    TrustSec uses SGTs for role-based policies.

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.