hardMultiple Choice
350-401 Practice Question: Runs the following command on switch SW8: SW8#…
A network engineer runs the following command on switch SW8:
SW8# show cts role-based sgt-map 192.168.1.10 IP Address: 192.168.1.10
SGT: 10 Source: SXP
Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the distinction between the 'Source' field in 'show cts role-based sgt-map' output, where candidates may confuse 'SXP' with manual configuration or local authentication, leading them to incorrectly select options A or D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SGT mapping was learned via SXP from a peer.
The output shows 'Source: SXP', which indicates that the Security Group Tag (SGT) mapping for IP address 192.168.1.10 was learned via the SXP (SGT Exchange Protocol) from a peer. SXP is used to propagate SGT-to-IP bindings from an authentication point (e.g., an ISE or a switch) to other network devices without requiring inline enforcement. Therefore, the mapping was not manually configured, not locally authenticated, and is indeed mapped to SGT 10.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The SGT mapping was configured manually.
Why it's wrong here
The source field for this binding is listed as SXP, which indicates the IP-to-SGT mapping was advertised dynamically over the Security Exchange Protocol from a trusted peer. A manually configured mapping would instead appear with a source such as "local" or "static" in show cts ip-sgt-binding output. Because the output explicitly shows SXP, the mapping cannot be a manual administrator-defined entry.
- ✓
The SGT mapping was learned via SXP from a peer.
Why this is correct
The IP address 192.168.1.10 is associated with SGT 10, and the source column shows SXP. This means the binding was learned dynamically via the Security Exchange Protocol from a peer device that is speaking SXP, rather than being configured locally or derived from authentication events. SXP propagates IP-to-SGT mappings that were originally assigned at an authentication point, allowing downstream devices to perform SGT enforcement without direct authentication. Therefore, this is the correct interpretation of the output.
- ✗
The IP address 192.168.1.10 is not mapped to any SGT.
Why it's wrong here
The output directly contradicts this statement because the mapping table includes a row for IP 192.168.1.10 with an SGT value of 10. If the IP had no SGT binding, it would not appear in the IP-to-SGT mapping table at all. The entry for 192.168.1.10 with SGT 10 proves that the address is indeed mapped to a security group tag.
- ✗
The SGT mapping is from local authentication.
Why it's wrong here
Local authentication, such as 802.1X with a local RADIUS server, would create an IP-to-SGT binding with a source of "local" or "auth" in the output. The source shown here is SXP, which indicates the mapping was received from a remote SXP peer, not generated by local authentication on this device. Therefore, this option is incorrect because the presence of SXP as the source explicitly rules out a local authentication origin.
Go deeper
Related to this question
Learn chapter
Wireless Deployment Models and Security
Key term
REST API for Network Devices
A REST API for network devices is a set of rules that allows software applications to communicate with routers, switches, and firewalls using standard web methods like GET, POST, PUT, and DELETE over HTTP or HTTPS.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.