350-401 Security Practice Question
A network security team is implementing Cisco TrustSec in a campus network. They need to deploy Security Group Tags (SGTs) and enforce policies using Security Group ACLs (SGACLs). Which two statements are true regarding SGT propagation and enforcement in this environment? (Choose two.)
⚠ Common exam trap
The trap here is assuming SGTs are carried in the IP header or that enforcement is limited to ingress, while the actual mechanisms are inline tagging and SXP with enforcement at multiple points.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SGT Exchange Protocol (SXP) is used to propagate SGTs to devices that do not support hardware-based tagging.
SGTs can be propagated inline using Cisco Metadata on supported hardware, and SXP is used for devices that cannot do inline tagging. These two methods allow flexible deployment in mixed environments. SGACLs can be enforced at various points, not just ingress, and SGTs are not carried in DSCP. SXP does not mandate IPsec.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SGT Exchange Protocol (SXP) is used to propagate SGTs to devices that do not support hardware-based tagging.
Why this is correct
SXP is a control-plane protocol that maps IP addresses to SGTs and is used to propagate SGT information to devices that cannot perform inline tagging, such as older switches or routers. It allows these devices to enforce SGACLs based on the SGT mapping. This is a key component of TrustSec for mixed environments.
- ✗
SXP requires the use of IPsec for secure communication between peers.
Why it's wrong here
SXP does not require IPsec; it can be secured using TCP MD5 authentication or other methods, but IPsec is not mandatory. SXP is a TCP-based protocol that can be protected with authentication, but IPsec is not a requirement. This statement is false because it overstates the security requirements for SXP.
- ✓
SGTs can be propagated inline within the Ethernet frame using Cisco Metadata (CMD) on supported hardware.
Why this is correct
Cisco TrustSec supports inline tagging where the SGT is inserted into the Ethernet frame using Cisco Metadata (CMD) on hardware that supports it, such as Cisco Catalyst 9000 series switches. This allows the tag to be carried natively without encapsulation, enabling enforcement at each hop. This is a valid method for SGT propagation in a TrustSec deployment.
- ✗
SGACLs are enforced only on the ingress interface where the SGT is assigned.
Why it's wrong here
SGACLs can be enforced at multiple points in the network, not just the ingress interface. In fact, enforcement typically occurs at the egress interface or at a central enforcement point, depending on the design. The ingress device assigns the SGT, but enforcement can happen elsewhere. This statement is false because it restricts enforcement to ingress only.
- ✗
SGTs are always carried in the IP header using the DSCP field.
Why it's wrong here
SGTs are not carried in the IP header DSCP field. They are either inline in the Ethernet frame using CMD or propagated via SXP. The DSCP field is used for QoS marking, not for SGT transport. This statement is incorrect because it misidentifies the transport mechanism for SGTs.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
ACLs and Infrastructure Security Features
Key term
QoS Classification and Marking
QoS Classification and Marking is the process of identifying network traffic by type and assigning a priority label to ensure important data gets handled first.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.