300-710 SNCF Integration Practice Question
A network security engineer configures Cisco Secure Firewall Threat Defense to ingest Security Group Tags (SGTs) from Cisco ISE via pxGrid. The integration is active, and SGTs are successfully mapped to IP addresses. However, access control rules referencing Security Group Tags fail to match traffic originating from authenticated endpoints. What is the most likely cause of this behavior on FTD?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The TrustSec SXP peering is not configured between the FTD and the authenticator switch, causing the firewall data plane to drop or ignore inline SGT headers.
For SGTs to be enforced in Access Control policies on FTD, the SGT metadata must be preserved in the data plane (such as through inline SGT propagation using Cisco TrustSec SXP or inline tagging). If SXP is not configured to propagate the tags across routed hops, or if the interface is not configured to trust SGT headers, FTD will not inspect the tag in the packet header.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cisco Secure Firewall Threat Defense does not support enforcement of SGTs learned via pxGrid; it only supports SXP.
Why it's wrong here
FTD fully supports pxGrid for IP-to-SGT mappings for use in Access Control policies.
- ✓
The TrustSec SXP peering is not configured between the FTD and the authenticator switch, causing the firewall data plane to drop or ignore inline SGT headers.
Why this is correct
If SXP or inline TrustSec is missing along the data path, the firewall does not receive the SGT metadata embedded or mapped in the packets.
- ✗
The Identity Source Sequence on ISE must include Active Directory LDAP bindings specifically for FTD rule evaluation.
Why it's wrong here
ISE handles the authentication and identity mapping; FTD consumes the IP-to-SGT mapping via pxGrid independently of the LDAP source sequence.
- ✗
The FMC requires a manual restart of the Snort detection engine every time a new SGT is learned via pxGrid.
Why it's wrong here
Snort dynamically maps SGTs from the pxGrid thread without requiring a restart.
About these practice questions
This 300-710 SNCF question is part of Courseiva's 478-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Cisco exam blueprint
This 300-710 SNCF practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-710 SNCF exam.