Courseiva
mediumMultiple Choice

Understanding CTS Role-Based Permissions Output

A network engineer runs the following command on switch SW9:

SW9# show cts role-based policy

Role-based policy:

Source Group Dest Group Action 10 20 PERMIT 10 30 DENY 20 30 PERMIT

Based on this output, what can be concluded?

⚠ Common exam trap

Cisco often tests the unidirectional nature of CTS role-based policies, where candidates mistakenly assume policies are bidirectional or that a permit in one direction implies a permit in the reverse direction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Traffic from SGT 20 to SGT 30 is permitted.

The command 'show cts role-based policy' displays Cisco TrustSec (CTS) role-based policies that define access control between source and destination Security Group Tags (SGTs). The output shows that traffic from SGT 20 to SGT 30 is explicitly permitted (PERMIT action), making option B correct. These policies are unidirectional, meaning the action applies only from the specified source group to the specified destination group.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Traffic from SGT 10 to SGT 20 is denied.

    Why it's wrong here

    The policy table includes an explicit Access Control Entry (ACE) for traffic from SGT 10 to SGT 20, and the action in that ACE is PERMIT, not DENY. Therefore, this statement is false because the output shows the traffic is explicitly allowed, not denied. The presence of a permit rule for that pairing directly contradicts the claim of denial.

  • ✓

    Traffic from SGT 20 to SGT 30 is permitted.

    Why this is correct

    The displayed Security Group ACL (SGACL) contains a rule with source SGT 20 and destination SGT 30, and the action for that rule is PERMIT. This explicitly allows traffic from security group 20 to security group 30, making the statement correct. No other rule in the output overrides or denies this match, so the traffic is indeed permitted.

  • ✗

    Traffic from SGT 30 to SGT 10 is denied.

    Why it's wrong here

    The output does not list any ACE that matches source SGT 30 to destination SGT 10, so there is no explicit deny rule for that traffic. While a missing ACE could result in an implicit deny if the enforcement model uses a default-deny, the output itself does not establish that the traffic is denied. The statement asserts a definitive denial that cannot be verified from the provided policy information.

  • ✗

    The policy is configured on an ISE server.

    Why it's wrong here

    The output shows the SGT policy table as viewed on a network device, but it does not contain any information about the management plane or configuration source. TrustSec policies can be centrally configured on Cisco ISE and distributed via SXP or other mechanisms, but they can also be locally configured on the device itself. Without explicit cues, such as ISE-generated access lists or management-plane headers, we cannot conclude that the policy was configured on ISE.

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.