mediumMultiple Choice
350-401 Practice Question: Consider this configuration for TrustSec on a…
Consider this configuration for TrustSec on a Cisco switch:
cts role-based enforcement
interface GigabitEthernet1/0/5
cts manual sap pmk AABBCCDDEEFF00112233445566778899 mode-list both propagate sgt
What is the purpose of the 'propagate sgt' command under the interface?
⚠ Common exam trap
Cisco often tests the distinction between 'propagate sgt' (which inserts SGT into packets) and SXP (which propagates SGT mappings via TCP), causing candidates to confuse the two or think 'propagate sgt' is about receiving SGT information.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It enables the switch to insert SGT tags into packets forwarded out of this interface.
The 'propagate sgt' command under a TrustSec manual interface instructs the switch to insert the Security Group Tag (SGT) into packets that are forwarded out of this interface. This is essential for downstream devices to receive the SGT and enforce role-based access control (RBAC) based on the source's security group. Option B correctly identifies this behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It allows the switch to receive SGT information from the connected device.
Why it's wrong here
Receiving SGT information from a connected device is the function of the Cisco TrustSec SXP (SGT Exchange Protocol) or the 'cts manual' configuration with SAP (SGT Advertisement Protocol) on an interface. The 'propagate sgt' command, in contrast, is purely an egress behavior: it copies the SGT from the incoming packet's metadata and inserts it into the Ethernet header of packets leaving this interface. It does not establish any listening or learning mechanism for SGTs from the peer, so this option misidentifies the direction and protocol involved.
- ✓
It enables the switch to insert SGT tags into packets forwarded out of this interface.
Why this is correct
The 'propagate sgt' interface command instructs the switch to take the SGT it has associated with a received frame (either from its own classification or from an upstream TrustSec device) and insert that tag into the 802.1Q or MACsec header of packets forwarded out of this interface. This is an egress tagging action only — the switch is not learning SGTs from the neighbor on this port, nor is it applying any policy decision. It enables downstream devices that are TrustSec-capable to receive the SGT and use it for their own enforcement, effectively extending the TrustSec domain across that link.
- ✗
It enables the switch to enforce role-based access control on this interface.
Why it's wrong here
Role-based access control (RBAC) enforcement using SGTs is activated globally with the command 'cts role-based enforcement' on the switch, not per-interface with 'propagate sgt'. Per-interface SGT propagation merely tags packets for downstream consumption; it does not evaluate permissions, apply SGACL policies, or block/allow traffic based on source/destination SGT pairs. Enforcement decisions happen in the forwarding plane on the switch itself, where the SGT of the source is looked up against the destination SGT's policy in the SGACL table — a function entirely independent of egress tag insertion.
- ✗
It configures the interface to use SXP for SGT propagation.
Why it's wrong here
SXP (SGT Exchange Protocol) is a separate control-plane protocol used to propagate IP-to-SGT bindings to devices that do not support inline tagging, typically over TCP port 64999. It is configured globally or on a loopback/management interface with 'cts sxp enable' and related commands, not on a data-facing interface with 'propagate sgt'. The 'propagate sgt' command operates on the data plane, inserting SGTs into actual forwarded frames, whereas SXP transmits binding information (IP addresses and corresponding SGTs) between peers so that non-inline devices can perform classification — they are complementary but distinct mechanisms and not interchangeable.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
Key term
SGACL
SGACL stands for Security Group Access Control List, a Cisco technology that controls network traffic based on the security group membership of the source and destination devices rather than IP addresses.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.