Courseiva
mediumMultiple Choice

350-401 Practice Question: Consider this configuration for TrustSec on a…

Consider this configuration for TrustSec on a Cisco switch:

cts role-based enforcement

interface GigabitEthernet1/0/5

cts manual sap pmk AABBCCDDEEFF00112233445566778899 mode-list both propagate sgt

What is the purpose of the 'propagate sgt' command under the interface?

⚠ Common exam trap

Cisco often tests the distinction between 'propagate sgt' (which inserts SGT into packets) and SXP (which propagates SGT mappings via TCP), causing candidates to confuse the two or think 'propagate sgt' is about receiving SGT information.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It enables the switch to insert SGT tags into packets forwarded out of this interface.

The 'propagate sgt' command under a TrustSec manual interface instructs the switch to insert the Security Group Tag (SGT) into packets that are forwarded out of this interface. This is essential for downstream devices to receive the SGT and enforce role-based access control (RBAC) based on the source's security group. Option B correctly identifies this behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It allows the switch to receive SGT information from the connected device.

    Why it's wrong here

    Receiving SGT information from a connected device is the function of the Cisco TrustSec SXP (SGT Exchange Protocol) or the 'cts manual' configuration with SAP (SGT Advertisement Protocol) on an interface. The 'propagate sgt' command, in contrast, is purely an egress behavior: it copies the SGT from the incoming packet's metadata and inserts it into the Ethernet header of packets leaving this interface. It does not establish any listening or learning mechanism for SGTs from the peer, so this option misidentifies the direction and protocol involved.

  • ✓

    It enables the switch to insert SGT tags into packets forwarded out of this interface.

    Why this is correct

    The 'propagate sgt' interface command instructs the switch to take the SGT it has associated with a received frame (either from its own classification or from an upstream TrustSec device) and insert that tag into the 802.1Q or MACsec header of packets forwarded out of this interface. This is an egress tagging action only — the switch is not learning SGTs from the neighbor on this port, nor is it applying any policy decision. It enables downstream devices that are TrustSec-capable to receive the SGT and use it for their own enforcement, effectively extending the TrustSec domain across that link.

  • ✗

    It enables the switch to enforce role-based access control on this interface.

    Why it's wrong here

    Role-based access control (RBAC) enforcement using SGTs is activated globally with the command 'cts role-based enforcement' on the switch, not per-interface with 'propagate sgt'. Per-interface SGT propagation merely tags packets for downstream consumption; it does not evaluate permissions, apply SGACL policies, or block/allow traffic based on source/destination SGT pairs. Enforcement decisions happen in the forwarding plane on the switch itself, where the SGT of the source is looked up against the destination SGT's policy in the SGACL table — a function entirely independent of egress tag insertion.

  • ✗

    It configures the interface to use SXP for SGT propagation.

    Why it's wrong here

    SXP (SGT Exchange Protocol) is a separate control-plane protocol used to propagate IP-to-SGT bindings to devices that do not support inline tagging, typically over TCP port 64999. It is configured globally or on a loopback/management interface with 'cts sxp enable' and related commands, not on a data-facing interface with 'propagate sgt'. The 'propagate sgt' command operates on the data plane, inserting SGTs into actual forwarded frames, whereas SXP transmits binding information (IP addresses and corresponding SGTs) between peers so that non-inline devices can perform classification — they are complementary but distinct mechanisms and not interchangeable.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.