350-401 Infrastructure Practice Question
A network engineer is implementing Cisco TrustSec in a campus network. The requirement is to classify traffic based on the identity of the user and the device, and to enforce policy across the network without relying on IP addresses. Which component assigns the Security Group Tag (SGT) to the packet at ingress?
⚠ Common exam trap
The trap here is assuming that ISE, as the policy server, writes the SGT into packets, when ISE only provides the classification and the ingress network device performs tag imposition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The ingress access layer switch or router inserts the SGT into the packet using inline tagging or SXP.
In Cisco TrustSec, the ingress network device classifies traffic and imposes the SGT after receiving the classification from ISE. Tag propagation uses inline tagging or SXP, and egress devices enforce Security Group ACLs based on source and destination SGTs. The policy decision comes from ISE, but tag imposition happens at the ingress enforcement point.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The egress switch removes the SGT and applies the Security Group ACL based on the source IP address.
Why it's wrong here
The egress device enforces policy by comparing source and destination SGTs against the Security Group ACL, but it does not classify or assign the tag. It also does not use source IP for policy enforcement in a TrustSec design, since the goal is to move away from IP-based rules. This option misstates both the role and the mechanism.
- ✓
The ingress access layer switch or router inserts the SGT into the packet using inline tagging or SXP.
Why this is correct
The ingress network device is responsible for classifying traffic and imposing the SGT. It receives the SGT value from ISE during authentication, then inserts the tag into the packet using inline tagging (Cisco Metadata or 802.1AE) or propagates the mapping via SXP to devices that do not support inline tagging. This is the enforcement point for tag imposition.
- ✗
The Cisco DNA Center appliance assigns the SGT during fabric VXLAN encapsulation.
Why it's wrong here
Cisco DNA Center is a management and automation platform, not an inline classification point. In SD-Access, SGTs are carried in VXLAN Group Policy Option headers, but the tag value is determined by ISE policy and imposed at the ingress edge node, not by the controller. This option conflates orchestration with enforcement.
- ✗
The Cisco Identity Services Engine (ISE) assigns the SGT directly into the packet header.
Why it's wrong here
ISE is the policy and identity authority that determines the SGT value for a user or device, but it does not write the tag into the packet header. Tag imposition occurs on the network device at the ingress point, based on the classification result returned by ISE via RADIUS. Confusing the policy decision point with the enforcement point is a common misunderstanding.
Quick reference
IPv4 Address Class Summary
| Class | First Octet Range | Default Mask | Networks | Hosts per Network |
|---|---|---|---|---|
| A | 1–126 | /8 (255.0.0.0) | 126 | 16,777,214 |
| B | 128–191 | /16 (255.255.0.0) | 16,384 | 65,534 |
| C | 192–223 | /24 (255.255.255.0) | 2,097,152 | 254 |
| D | 224–239 | N/A | Multicast groups | — |
| E | 240–255 | N/A | Reserved / experimental | — |
127.x.x.x is reserved for loopback. Modern networks use CIDR (classless) rather than classful addressing.
Go deeper
Related to this question
Learn chapter
ACLs and Infrastructure Security Features
Key term
SGACL
SGACL stands for Security Group Access Control List, a Cisco technology that controls network traffic based on the security group membership of the source and destination devices rather than IP addresses.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.