Courseiva
Security →hardMultiple Select

350-401 Security Practice Question

A network security engineer is deploying Cisco TrustSec in a campus network. The engineer wants to implement Security Group Tagging (SGT) and enforce policies based on SGTs. Which two mechanisms can be used to propagate SGTs between network devices? (Choose two.)

⚠ Common exam trap

It's easy for candidates to confuse RADIUS CoA with SGT propagation, when CoA is only for session authorization changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Native tagging (inline tagging) within the Ethernet frame

SGTs can be propagated between network devices using two primary mechanisms: native tagging (inline tagging) where the SGT is embedded in the Ethernet frame, and SXP where the SGT bindings are exchanged via a control-plane protocol. These methods allow enforcement points to apply Security Group ACLs based on the source SGT.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    RADIUS Change of Authorization (CoA) with SGT attributes

    Why it's wrong here

    RADIUS CoA is used to change authorization attributes for an authenticated session, and it can carry SGT attributes to update the policy on a switch. However, CoA is not a mechanism for propagating SGTs between network devices for policy enforcement; it is a session management tool. It does not propagate SGTs in the data plane.

  • ✗

    Inline tagging using Cisco Metadata (CMD) in the Ethernet frame

    Why it's wrong here

    Inline tagging uses a Cisco TrustSec header (CMD) inserted into the Ethernet frame to carry the SGT. This is a native method for SGT propagation on supported hardware. However, it is not a separate mechanism from native tagging; it is the native tagging itself. The question asks for mechanisms to propagate SGTs, and inline tagging is one, but it is not typically referred to as CMD in this context. The correct term is native tagging, so this option is less precise.

  • ✓

    Native tagging (inline tagging) within the Ethernet frame

    Why this is correct

    Native tagging, also known as inline tagging, inserts the SGT into the Ethernet frame using the Cisco TrustSec header. This allows switches and routers that support TrustSec hardware to read the SGT directly from the frame and enforce policies without needing an external mapping protocol. It is the preferred method for high-performance SGT propagation in the campus.

  • ✓

    SGT Exchange Protocol (SXP)

    Why this is correct

    SXP is used to propagate SGT bindings (IP-to-SGT mappings) to devices that do not support hardware-based SGT tagging, such as older switches or firewalls. It allows these devices to participate in TrustSec policy enforcement by learning the SGT mappings via a TCP-based protocol. This enables consistent policy across the network even where native tagging is not available.

  • ✗

    IPsec Encapsulating Security Payload (ESP) with SGT extension

    Why it's wrong here

    IPsec ESP is used for VPN encryption and does not carry SGTs natively. While TrustSec can be used in conjunction with IPsec, the SGT is not propagated via ESP. This option is incorrect because it misrepresents how SGTs are carried across the network.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.