Courseiva
Security →mediumMultiple Choice

350-401 Security Practice Question

A network engineer is deploying Cisco TrustSec in a campus network. The security team requires that the Security Group Tag (SGT) be carried inside the Ethernet frame so that switches in the path can enforce group-based policy without inline tagging. Which Cisco-proprietary protocol should be enabled on the uplinks between the access and distribution switches to achieve this?

⚠ Common exam trap

The trap here is assuming that any Layer 2 security feature on the uplink, such as MACsec, will also carry the SGT for TrustSec policy enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cisco TrustSec CMD (Cisco Meta Data)

Inline SGT tagging between TrustSec-capable switches is accomplished with Cisco Meta Data, which places the Security Group Tag into the Ethernet frame so each hop can enforce Security Group ACLs. MACsec provides encryption rather than tag transport, SXP propagates IP-to-SGT mappings across non-TrustSec hops, and L2TP is unrelated to TrustSec tagging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Layer 2 Tunneling Protocol (L2TP)

    Why it's wrong here

    L2TP is a tunneling protocol used to encapsulate PPP sessions over IP networks, typically for remote access VPNs. It has no role in TrustSec SGT propagation and does not provide inline tag carriage on Ethernet uplinks. Enabling L2TP on the access-to-distribution links would be inappropriate and would not satisfy the group-based policy enforcement requirement.

  • ✓

    Cisco TrustSec CMD (Cisco Meta Data)

    Why this is correct

    Cisco Meta Data (CMD) is the TrustSec inline tagging mechanism that inserts the SGT into a reserved field of the Ethernet frame. Enabling CMD on the inter-switch uplinks allows each hop to read the tag and apply Security Group ACLs without re-classifying based on IP address, which is exactly the inline tagging behaviour the scenario requires.

  • ✗

    802.1AE MACsec

    Why it's wrong here

    MACsec (802.1AE) provides hop-by-hop encryption and integrity for Layer 2 frames. It does not carry SGT values in the frame for downstream policy enforcement, and it is not a TrustSec SGT transport. Enabling MACsec on the uplinks protects confidentiality but leaves the SGT field unpopulated, so group-based ACLs at the distribution layer cannot classify the traffic.

  • ✗

    Cisco TrustSec SXP

    Why it's wrong here

    SXP (SGT Exchange Protocol) is a control-plane protocol used to propagate IP-to-SGT bindings between TrustSec domains that do not share a common Layer 2 path, such as across a non-TrustSec device. It does not embed the SGT inside the Ethernet frame on a link, so it cannot enable inline tagging on the uplinks between access and distribution switches.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.