Courseiva
Architecture →mediumMultiple Choice

350-401 Architecture Practice Question

A network engineer is implementing Cisco TrustSec in a campus network. The security team wants to enforce access policies based on user identity and device type without relying on IP addresses. Which component is responsible for assigning Security Group Tags (SGTs) to traffic at the ingress point?

⚠ Common exam trap

The trap here is assuming that ISE, as the policy engine, also performs the tagging, when in fact the tagging is done by the ingress network device.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cisco Catalyst switch with TrustSec support

In Cisco TrustSec, the ingress network device (such as a Catalyst switch or wireless controller) is responsible for classifying and tagging packets with SGTs. This classification is based on policies downloaded from ISE. The switch inserts the SGT into the packet, allowing subsequent devices to enforce access policies without examining IP addresses. ISE defines the policies but does not perform the tagging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cisco Identity Services Engine (ISE)

    Why it's wrong here

    Cisco ISE is the policy management component that defines security group tags (SGTs) and their associated policies. It does not assign SGTs to traffic at the ingress point; instead, it provides the mapping of users and devices to SGTs. The actual tagging of packets occurs on the network device (switch or wireless controller) based on information from ISE. So ISE is not the component that assigns SGTs at ingress.

  • ✗

    Cisco Firepower Threat Defense (FTD)

    Why it's wrong here

    Cisco FTD is a next-generation firewall that can enforce policies based on SGTs, but it does not assign SGTs at ingress. It typically acts as an enforcement point in the network, inspecting traffic that already carries SGTs. The assignment of SGTs occurs at the ingress switch or wireless controller. Therefore, FTD is not the correct component for this role.

  • ✗

    Cisco DNA Center

    Why it's wrong here

    Cisco DNA Center is a network management and automation platform. It can orchestrate policies and integrate with ISE, but it does not assign SGTs to traffic at ingress. The actual tagging is performed by the network devices (switches, wireless controllers) that enforce the policy. DNA Center is not directly involved in the data plane tagging process.

  • ✓

    Cisco Catalyst switch with TrustSec support

    Why this is correct

    The ingress Cisco Catalyst switch (or wireless controller) is responsible for assigning SGTs to packets based on the classification policy received from ISE. It inserts the SGT into the Cisco Metadata (CMD) field of the packet or uses inline tagging. This enables enforcement throughout the network without relying on IP addresses. Thus, the switch is the component that assigns SGTs at the ingress point.

Quick reference

IPv4 Address Class Summary

ClassFirst Octet RangeDefault MaskNetworksHosts per Network
A1–126/8 (255.0.0.0)12616,777,214
B128–191/16 (255.255.0.0)16,38465,534
C192–223/24 (255.255.255.0)2,097,152254
D224–239N/AMulticast groups—
E240–255N/AReserved / experimental—

127.x.x.x is reserved for loopback. Modern networks use CIDR (classless) rather than classful addressing.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.