Courseiva
Infrastructure →hardMultiple Choice

350-401 Infrastructure Practice Question

A network engineer is implementing a Cisco TrustSec solution. The engineer needs to classify traffic based on user identity and apply security policies accordingly. Which component is responsible for tagging packets with a Security Group Tag (SGT) at the ingress point?

⚠ Common exam trap

Candidates often confuse the roles of the PDP and PEP, or assuming that the PDP tags packets, when in fact the tagging is done at the ingress point.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ingress Policy Enforcement Point (Ingress PEP)

In Cisco TrustSec, the Ingress Policy Enforcement Point (Ingress PEP) is the device that first receives traffic into the TrustSec domain. It classifies the traffic, determines the source Security Group Tag (SGT), and inserts the SGT into the packet. This tag is then used by other enforcement points to apply security policies. The PDP (ISE) provides the policy, but the Ingress PEP performs the tagging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Policy Enforcement Point (PEP)

    Why it's wrong here

    The Policy Enforcement Point (PEP) is responsible for enforcing policies based on the SGT, but it does not tag packets. The PEP is typically a switch or firewall that receives tagged packets and applies the appropriate policy. Tagging occurs at the ingress point, which is a different component. Therefore, the PEP is not responsible for tagging.

  • ✗

    Policy Decision Point (PDP)

    Why it's wrong here

    The Policy Decision Point (PDP) is the Cisco Identity Services Engine (ISE) that makes policy decisions and distributes them to enforcement points. It does not tag packets. The PDP provides the mapping of SGTs to policies, but the actual tagging is done by the ingress device. Thus, the PDP is not the correct answer.

  • ✗

    Network Device Admission Control (NDAC)

    Why it's wrong here

    Network Device Admission Control (NDAC) is a component of TrustSec that authenticates and authorizes network devices before they can join the trusted network. It ensures that only authorized devices participate in the TrustSec domain. However, NDAC does not tag packets with SGTs. Its role is admission control, not traffic classification.

  • ✓

    Ingress Policy Enforcement Point (Ingress PEP)

    Why this is correct

    The Ingress Policy Enforcement Point (Ingress PEP) is the device where traffic enters the TrustSec domain. It is responsible for classifying the traffic and tagging the packet with the appropriate Security Group Tag (SGT). This tagging allows subsequent devices to enforce policies based on the SGT without reclassifying the traffic. The Ingress PEP is typically a switch or router that supports TrustSec.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.