350-401 Security Practice Question
A network engineer is deploying Cisco TrustSec in a campus network. The security team requires that the Security Group Tag (SGT) be carried inside the Ethernet frame so that switches in the path can enforce group-based policy without inline tagging. Which Cisco-proprietary protocol should be enabled on the uplinks between the access and distribution switches to achieve this?
⚠ Common exam trap
The trap here is assuming that any Layer 2 security feature on the uplink, such as MACsec, will also carry the SGT for TrustSec policy enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco TrustSec CMD (Cisco Meta Data)
Inline SGT tagging between TrustSec-capable switches is accomplished with Cisco Meta Data, which places the Security Group Tag into the Ethernet frame so each hop can enforce Security Group ACLs. MACsec provides encryption rather than tag transport, SXP propagates IP-to-SGT mappings across non-TrustSec hops, and L2TP is unrelated to TrustSec tagging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Layer 2 Tunneling Protocol (L2TP)
Why it's wrong here
L2TP is a tunneling protocol used to encapsulate PPP sessions over IP networks, typically for remote access VPNs. It has no role in TrustSec SGT propagation and does not provide inline tag carriage on Ethernet uplinks. Enabling L2TP on the access-to-distribution links would be inappropriate and would not satisfy the group-based policy enforcement requirement.
- ✓
Cisco TrustSec CMD (Cisco Meta Data)
Why this is correct
Cisco Meta Data (CMD) is the TrustSec inline tagging mechanism that inserts the SGT into a reserved field of the Ethernet frame. Enabling CMD on the inter-switch uplinks allows each hop to read the tag and apply Security Group ACLs without re-classifying based on IP address, which is exactly the inline tagging behaviour the scenario requires.
- ✗
802.1AE MACsec
Why it's wrong here
MACsec (802.1AE) provides hop-by-hop encryption and integrity for Layer 2 frames. It does not carry SGT values in the frame for downstream policy enforcement, and it is not a TrustSec SGT transport. Enabling MACsec on the uplinks protects confidentiality but leaves the SGT field unpopulated, so group-based ACLs at the distribution layer cannot classify the traffic.
- ✗
Cisco TrustSec SXP
Why it's wrong here
SXP (SGT Exchange Protocol) is a control-plane protocol used to propagate IP-to-SGT bindings between TrustSec domains that do not share a common Layer 2 path, such as across a non-TrustSec device. It does not embed the SGT inside the Ethernet frame on a link, so it cannot enable inline tagging on the uplinks between access and distribution switches.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
Wireless Deployment Models and Security
Key term
MACsec
MACsec (Media Access Control Security) is a security protocol that encrypts and authenticates data at the Ethernet frame level to protect traffic on local area networks.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.