350-401 Security Practice Question
A network security engineer is deploying Cisco TrustSec in a campus network. The engineer wants to implement Security Group Tagging (SGT) and enforce policies based on SGTs. Which two mechanisms can be used to propagate SGTs between network devices? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse RADIUS CoA with SGT propagation, when CoA is only for session authorization changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Native tagging (inline tagging) within the Ethernet frame
SGTs can be propagated between network devices using two primary mechanisms: native tagging (inline tagging) where the SGT is embedded in the Ethernet frame, and SXP where the SGT bindings are exchanged via a control-plane protocol. These methods allow enforcement points to apply Security Group ACLs based on the source SGT.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
RADIUS Change of Authorization (CoA) with SGT attributes
Why it's wrong here
RADIUS CoA is used to change authorization attributes for an authenticated session, and it can carry SGT attributes to update the policy on a switch. However, CoA is not a mechanism for propagating SGTs between network devices for policy enforcement; it is a session management tool. It does not propagate SGTs in the data plane.
- ✗
Inline tagging using Cisco Metadata (CMD) in the Ethernet frame
Why it's wrong here
Inline tagging uses a Cisco TrustSec header (CMD) inserted into the Ethernet frame to carry the SGT. This is a native method for SGT propagation on supported hardware. However, it is not a separate mechanism from native tagging; it is the native tagging itself. The question asks for mechanisms to propagate SGTs, and inline tagging is one, but it is not typically referred to as CMD in this context. The correct term is native tagging, so this option is less precise.
- ✓
Native tagging (inline tagging) within the Ethernet frame
Why this is correct
Native tagging, also known as inline tagging, inserts the SGT into the Ethernet frame using the Cisco TrustSec header. This allows switches and routers that support TrustSec hardware to read the SGT directly from the frame and enforce policies without needing an external mapping protocol. It is the preferred method for high-performance SGT propagation in the campus.
- ✓
SGT Exchange Protocol (SXP)
Why this is correct
SXP is used to propagate SGT bindings (IP-to-SGT mappings) to devices that do not support hardware-based SGT tagging, such as older switches or firewalls. It allows these devices to participate in TrustSec policy enforcement by learning the SGT mappings via a TCP-based protocol. This enables consistent policy across the network even where native tagging is not available.
- ✗
IPsec Encapsulating Security Payload (ESP) with SGT extension
Why it's wrong here
IPsec ESP is used for VPN encryption and does not carry SGTs natively. While TrustSec can be used in conjunction with IPsec, the SGT is not propagated via ESP. This option is incorrect because it misrepresents how SGTs are carried across the network.
Go deeper
Related to this question
Learn chapter
Wireless Deployment Models and Security
Key term
REST API for Network Devices
A REST API for network devices is a set of rules that allows software applications to communicate with routers, switches, and firewalls using standard web methods like GET, POST, PUT, and DELETE over HTTP or HTTPS.
Key term
SGACL
SGACL stands for Security Group Access Control List, a Cisco technology that controls network traffic based on the security group membership of the source and destination devices rather than IP addresses.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.