Courseiva
IntegrationhardMultiple ChoiceObjective-mapped

300-710 SNCF Integration Practice Question

A network security engineer configures Cisco Secure Firewall Threat Defense to ingest Security Group Tags (SGTs) from Cisco ISE via pxGrid. The integration is active, and SGTs are successfully mapped to IP addresses. However, access control rules referencing Security Group Tags fail to match traffic originating from authenticated endpoints. What is the most likely cause of this behavior on FTD?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The TrustSec SXP peering is not configured between the FTD and the authenticator switch, causing the firewall data plane to drop or ignore inline SGT headers.

For SGTs to be enforced in Access Control policies on FTD, the SGT metadata must be preserved in the data plane (such as through inline SGT propagation using Cisco TrustSec SXP or inline tagging). If SXP is not configured to propagate the tags across routed hops, or if the interface is not configured to trust SGT headers, FTD will not inspect the tag in the packet header.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cisco Secure Firewall Threat Defense does not support enforcement of SGTs learned via pxGrid; it only supports SXP.

    Why it's wrong here

    FTD fully supports pxGrid for IP-to-SGT mappings for use in Access Control policies.

  • The TrustSec SXP peering is not configured between the FTD and the authenticator switch, causing the firewall data plane to drop or ignore inline SGT headers.

    Why this is correct

    If SXP or inline TrustSec is missing along the data path, the firewall does not receive the SGT metadata embedded or mapped in the packets.

  • The Identity Source Sequence on ISE must include Active Directory LDAP bindings specifically for FTD rule evaluation.

    Why it's wrong here

    ISE handles the authentication and identity mapping; FTD consumes the IP-to-SGT mapping via pxGrid independently of the LDAP source sequence.

  • The FMC requires a manual restart of the Snort detection engine every time a new SGT is learned via pxGrid.

    Why it's wrong here

    Snort dynamically maps SGTs from the pxGrid thread without requiring a restart.

About these practice questions

This 300-710 SNCF question is part of Courseiva's 478-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Cisco exam blueprint

This 300-710 SNCF practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-710 SNCF exam.