mediumMultiple Choice
350-401 Practice Question: Consider the following TrustSec configuration on…
Consider the following TrustSec configuration on a Cisco switch:
cts role-based enforcement
interface GigabitEthernet1/0/3
cts manual sap pmk 0123456789ABCDEF mode-list both
What is the purpose of this configuration?
⚠ Common exam trap
It's easy for candidates to confuse `cts manual` with SXP or 802.1X, because all three involve security group tags or authentication, but `cts manual sap` is specifically for inline tagging with a pre-shared key on a directly connected link, not for SXP propagation or 802.1X-based dynamic VLAN assignment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It enables CTS inline tagging with a pre-shared key for SGT exchange between peers.
The `cts manual` command with `sap pmk` and `mode-list both` configures Cisco TrustSec (CTS) inline tagging on the interface. This enables the exchange of Security Group Tags (SGTs) between directly connected peers using a pre-shared key (PSK) for authentication and encryption of the SGT metadata, without requiring 802.1X or SXP. The `mode-list both` specifies that both Layer 2 (802.1AE MACsec) and Layer 3 (SGT encapsulation) protection are used.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It enables 802.1X authentication with a pre-shared key.
Why it's wrong here
802.1X is a port-based network access control standard that uses EAP, a RADIUS server, and a supplicant/authenticator model; it does not rely on a pre-shared key. Here the PMK is used by Cisco TrustSec to authenticate the Security Association Protocol (SAP) exchange so that SGTs can propagate over the link. This command is therefore not enabling 802.1X authentication at all.
- ✗
It configures the interface to use SGT (Security Group Tag) propagation via SXP.
Why it's wrong here
SXP (Security eXchange Protocol) is a control-plane protocol that carries IP-to-SGT mappings over TCP to distribute security group tags to devices that cannot perform inline tagging. This configuration instead uses `cts manual` with `sap pmk`, which establishes a Security Association Protocol session over the data plane; SAP inserts or reads the SGT directly in the Ethernet frame's CMD header. Since no SXP connection is created and no IP-to-SGT bindings are exchanged, this option is incorrect.
- ✓
It enables CTS inline tagging with a pre-shared key for SGT exchange between peers.
Why this is correct
This correctly describes the `cts manual` command with a `sap pmk` policy: manual TrustSec mode uses a pre-shared key to bring up a Security Association Protocol session. After SAP is established, the interface performs inline SGT tagging, inserting the SGT into the CMD (Cisco Meta-Data) header of each frame so the peer can enforce security-group-based policies. The pre-shared key authenticates the peer for this SGT exchange, not for user authentication.
- ✗
It enables dynamic VLAN assignment based on user authentication.
Why it's wrong here
Dynamic VLAN assignment is a distinct feature in which a RADIUS server, during 802.1X or MAC authentication, returns attributes such as Tunnel-Private-Group-ID to place the port or client in a specific VLAN. The `cts manual` + `sap pmk` configuration has nothing to do with VLAN placement; it only establishes the TrustSec SAP session and enables inline SGT tagging. Therefore this option misidentifies the function of the command.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Wireless Deployment Models and Security
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 350-401
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Consider this configuration for TrustSec on a Cisco switch: cts role-based enforcement interface GigabitEthernet1/0/5 cts manual sap pmk AABBCCDDEEFF00112233445566778899 mode-list both propagate sgt What is the purpose of the 'propagate sgt' command under the interface?
medium- A.It allows the switch to receive SGT information from the connected device.
- ✓ B.It enables the switch to insert SGT tags into packets forwarded out of this interface.
- C.It enables the switch to enforce role-based access control on this interface.
- D.It configures the interface to use SXP for SGT propagation.
Why B: The 'propagate sgt' command under a TrustSec manual interface instructs the switch to insert the Security Group Tag (SGT) into packets that are forwarded out of this interface. This is essential for downstream devices to receive the SGT and enforce role-based access control (RBAC) based on the source's security group. Option B correctly identifies this behavior.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.