350-401 Infrastructure Practice Question
A network engineer is implementing a Cisco TrustSec solution. The engineer needs to classify traffic based on user identity and apply security policies accordingly. Which component is responsible for tagging packets with a Security Group Tag (SGT) at the ingress point?
⚠ Common exam trap
Candidates often confuse the roles of the PDP and PEP, or assuming that the PDP tags packets, when in fact the tagging is done at the ingress point.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ingress Policy Enforcement Point (Ingress PEP)
In Cisco TrustSec, the Ingress Policy Enforcement Point (Ingress PEP) is the device that first receives traffic into the TrustSec domain. It classifies the traffic, determines the source Security Group Tag (SGT), and inserts the SGT into the packet. This tag is then used by other enforcement points to apply security policies. The PDP (ISE) provides the policy, but the Ingress PEP performs the tagging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Policy Enforcement Point (PEP)
Why it's wrong here
The Policy Enforcement Point (PEP) is responsible for enforcing policies based on the SGT, but it does not tag packets. The PEP is typically a switch or firewall that receives tagged packets and applies the appropriate policy. Tagging occurs at the ingress point, which is a different component. Therefore, the PEP is not responsible for tagging.
- ✗
Policy Decision Point (PDP)
Why it's wrong here
The Policy Decision Point (PDP) is the Cisco Identity Services Engine (ISE) that makes policy decisions and distributes them to enforcement points. It does not tag packets. The PDP provides the mapping of SGTs to policies, but the actual tagging is done by the ingress device. Thus, the PDP is not the correct answer.
- ✗
Network Device Admission Control (NDAC)
Why it's wrong here
Network Device Admission Control (NDAC) is a component of TrustSec that authenticates and authorizes network devices before they can join the trusted network. It ensures that only authorized devices participate in the TrustSec domain. However, NDAC does not tag packets with SGTs. Its role is admission control, not traffic classification.
- ✓
Ingress Policy Enforcement Point (Ingress PEP)
Why this is correct
The Ingress Policy Enforcement Point (Ingress PEP) is the device where traffic enters the TrustSec domain. It is responsible for classifying the traffic and tagging the packet with the appropriate Security Group Tag (SGT). This tagging allows subsequent devices to enforce policies based on the SGT without reclassifying the traffic. The Ingress PEP is typically a switch or router that supports TrustSec.
Go deeper
Related to this question
Learn chapter
Wireless Deployment Models and Security
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
Key term
SGACL
SGACL stands for Security Group Access Control List, a Cisco technology that controls network traffic based on the security group membership of the source and destination devices rather than IP addresses.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.