350-401 Architecture Practice Question
A network administrator is implementing Cisco TrustSec in a data center. The security team wants to enforce segmentation based on user roles rather than IP addresses. The administrator has configured security group tags (SGTs) on the access layer switches and now needs to propagate this information across the network. Which protocol should be used to carry SGT information between Cisco TrustSec-capable devices?
⚠ Common exam trap
The trap here is assuming that RADIUS, which can deliver SGTs during authentication, also propagates SGTs between network devices for enforcement, when that is the role of SXP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SXP
SXP (SGT Exchange Protocol) is designed to propagate SGT-to-IP mappings between Cisco TrustSec domains, particularly when devices cannot natively tag packets with SGTs. It enables policy enforcement across network boundaries by sharing the mapping of IP addresses to security groups. This allows consistent role-based segmentation even in mixed environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RADIUS
Why it's wrong here
RADIUS is used for authentication, authorization, and accounting (AAA) and can return SGT values during authentication via vendor-specific attributes. However, RADIUS does not propagate SGTs between network devices for enforcement; it only communicates the tag to the authenticator during the initial session setup. It does not carry SGT information in data packets or between switches, so it is not the correct protocol for this purpose.
- ✗
TACACS+
Why it's wrong here
TACACS+ is a AAA protocol primarily used for device administration and command authorization. It does not carry SGT information between network devices for traffic enforcement. While it can be used for administrative access control, it does not participate in the TrustSec data plane or the propagation of security group tags across the network. Thus, it is not suitable for this requirement.
- ✓
SXP
Why this is correct
SXP (SGT Exchange Protocol) is used to propagate SGT information between Cisco TrustSec-capable devices, especially when some devices do not support hardware-based SGT tagging. It allows IP-to-SGT mappings to be shared across network boundaries, enabling consistent policy enforcement. In this scenario, SXP is the correct protocol to carry SGT information between devices that need to enforce role-based segmentation.
- ✗
802.1X
Why it's wrong here
802.1X is used for port-based network access control and can authenticate users and devices, but it does not carry SGT information between network devices. While 802.1X can be part of the TrustSec architecture for initial authentication, the propagation of SGTs across the network requires a different protocol that can encapsulate the tag in the packet. Therefore, 802.1X alone does not fulfill the requirement.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
Key term
SGACL
SGACL stands for Security Group Access Control List, a Cisco technology that controls network traffic based on the security group membership of the source and destination devices rather than IP addresses.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.