350-401 Security Practice Question
A network security team is deploying Cisco TrustSec in a data center environment. They want to assign Security Group Tags (SGTs) to traffic based on user identity and device type without relying on IP addresses or VLANs. The team plans to use inline tagging on Cisco Nexus switches that support hardware-based SGACL enforcement. Which statement correctly describes how inline tagging propagates SGT information?
⚠ Common exam trap
The trap here is assuming SGTs are carried in IP headers like DSCP, when in reality they are embedded in Layer 2 frames using Cisco Metadata.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SGT is inserted into the Layer 2 frame using Cisco Metadata (CMD) fields, allowing downstream devices to enforce SGACLs without reclassification.
Inline tagging in Cisco TrustSec inserts the SGT directly into the Ethernet frame using Cisco Metadata fields. This allows downstream devices to enforce SGACLs based on the original classification without needing to reclassify traffic, preserving security group integrity across the network path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The SGT is inserted into the Layer 2 frame using Cisco Metadata (CMD) fields, allowing downstream devices to enforce SGACLs without reclassification.
Why this is correct
Inline tagging uses Cisco Metadata to carry the SGT value within the Ethernet frame itself. Downstream devices that support CMD can read the tag and enforce SGACLs directly, eliminating the need to reclassify traffic based on IP or user identity at each hop, which preserves the original classification throughout the path.
- ✗
The SGT is encoded in the DSCP field of the IP header, enabling enforcement at any Layer 3 device along the path.
Why it's wrong here
SGT values are not carried in the DSCP field. DSCP is used for QoS marking and has only six bits, which is insufficient for the full SGT range. Attempting to map SGTs to DSCP would conflict with QoS policies and lacks the structured enforcement capabilities that CMD provides.
- ✗
The SGT is stored in the ARP cache of each device, and devices query a central server to resolve SGTs for enforcement decisions.
Why it's wrong here
SGTs are not stored in ARP caches. ARP resolves IP-to-MAC mappings and has no relationship to security group tagging. TrustSec uses either inline tagging within the frame or SXP to propagate IP-to-SGT bindings, not ARP-based lookups, which would introduce latency and scalability issues.
- ✗
The SGT is propagated through a proprietary GRE tunnel between all TrustSec-capable devices, encapsulating the original frame.
Why it's wrong here
While SGT Exchange Protocol (SXP) can share IP-to-SGT mappings between devices, it does not tunnel frames. Inline tagging does not use GRE tunnels; it modifies the Ethernet frame directly with CMD fields. GRE encapsulation would add significant overhead and is not part of the TrustSec inline tagging mechanism.
Visual reference
Quick reference
IPv4 Address Class Summary
| Class | First Octet Range | Default Mask | Networks | Hosts per Network |
|---|---|---|---|---|
| A | 1–126 | /8 (255.0.0.0) | 126 | 16,777,214 |
| B | 128–191 | /16 (255.255.0.0) | 16,384 | 65,534 |
| C | 192–223 | /24 (255.255.255.0) | 2,097,152 | 254 |
| D | 224–239 | N/A | Multicast groups | — |
| E | 240–255 | N/A | Reserved / experimental | — |
127.x.x.x is reserved for loopback. Modern networks use CIDR (classless) rather than classful addressing.
Go deeper
Related to this question
Learn chapter
ACLs and Infrastructure Security Features
Key term
SGACL
SGACL stands for Security Group Access Control List, a Cisco technology that controls network traffic based on the security group membership of the source and destination devices rather than IP addresses.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.