350-401 Architecture Practice Question
A network engineer is implementing Cisco TrustSec in a campus network. The security team wants to enforce access policies based on user identity and device type without relying on IP addresses. Which component is responsible for assigning Security Group Tags (SGTs) to traffic at the ingress point?
⚠ Common exam trap
The trap here is assuming that ISE, as the policy engine, also performs the tagging, when in fact the tagging is done by the ingress network device.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco Catalyst switch with TrustSec support
In Cisco TrustSec, the ingress network device (such as a Catalyst switch or wireless controller) is responsible for classifying and tagging packets with SGTs. This classification is based on policies downloaded from ISE. The switch inserts the SGT into the packet, allowing subsequent devices to enforce access policies without examining IP addresses. ISE defines the policies but does not perform the tagging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cisco Identity Services Engine (ISE)
Why it's wrong here
Cisco ISE is the policy management component that defines security group tags (SGTs) and their associated policies. It does not assign SGTs to traffic at the ingress point; instead, it provides the mapping of users and devices to SGTs. The actual tagging of packets occurs on the network device (switch or wireless controller) based on information from ISE. So ISE is not the component that assigns SGTs at ingress.
- ✗
Cisco Firepower Threat Defense (FTD)
Why it's wrong here
Cisco FTD is a next-generation firewall that can enforce policies based on SGTs, but it does not assign SGTs at ingress. It typically acts as an enforcement point in the network, inspecting traffic that already carries SGTs. The assignment of SGTs occurs at the ingress switch or wireless controller. Therefore, FTD is not the correct component for this role.
- ✗
Cisco DNA Center
Why it's wrong here
Cisco DNA Center is a network management and automation platform. It can orchestrate policies and integrate with ISE, but it does not assign SGTs to traffic at ingress. The actual tagging is performed by the network devices (switches, wireless controllers) that enforce the policy. DNA Center is not directly involved in the data plane tagging process.
- ✓
Cisco Catalyst switch with TrustSec support
Why this is correct
The ingress Cisco Catalyst switch (or wireless controller) is responsible for assigning SGTs to packets based on the classification policy received from ISE. It inserts the SGT into the Cisco Metadata (CMD) field of the packet or uses inline tagging. This enables enforcement throughout the network without relying on IP addresses. Thus, the switch is the component that assigns SGTs at the ingress point.
Quick reference
IPv4 Address Class Summary
| Class | First Octet Range | Default Mask | Networks | Hosts per Network |
|---|---|---|---|---|
| A | 1–126 | /8 (255.0.0.0) | 126 | 16,777,214 |
| B | 128–191 | /16 (255.255.0.0) | 16,384 | 65,534 |
| C | 192–223 | /24 (255.255.255.0) | 2,097,152 | 254 |
| D | 224–239 | N/A | Multicast groups | — |
| E | 240–255 | N/A | Reserved / experimental | — |
127.x.x.x is reserved for loopback. Modern networks use CIDR (classless) rather than classful addressing.
Go deeper
Related to this question
Learn chapter
Wireless Deployment Models and Security
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
Key term
SGACL
SGACL stands for Security Group Access Control List, a Cisco technology that controls network traffic based on the security group membership of the source and destination devices rather than IP addresses.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.