hardMultiple Choice
350-401 Practice Question: An enterprise is implementing Cisco TrustSec…
An enterprise is implementing Cisco TrustSec (CTS) to enforce role-based access control. The network engineer configures the switch with 'cts role-based enforcement' and 'cts manual' on an interface connecting to a trusted Cisco switch. The engineer also configures Security Group Tags (SGTs) on the RADIUS server. However, traffic between two hosts in different SGTs is not being filtered as expected. The engineer checks 'show cts role-based counters' and sees no drops. What is the most likely reason for the lack of enforcement?
⚠ Common exam trap
Cisco often tests the distinction between SGT assignment (via RADIUS) and SGT propagation (via SXP or manual mapping), leading candidates to assume that configuring SGTs on the RADIUS server alone is sufficient for enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SGTs are not being propagated to the switch; the switch lacks SGT mappings for the hosts.
Cisco TrustSec enforcement relies on the switch having the correct SGT-to-IP mapping for each host. Even if SGTs are assigned on the RADIUS server and CTS role-based enforcement is enabled, the switch must learn the SGT for each source IP address. Without these mappings, the switch cannot classify traffic into SGTs and therefore cannot apply role-based ACLs, resulting in no drops in the counters.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The switch is not configured for 802.1X on the interface.
Why it's wrong here
This is incorrect because Cisco TrustSec does not strictly require 802.1X authentication on an interface. When the interface is configured with 'cts manual' and a manually assigned SGT is applied to untagged traffic, the switch can classify packets without any 802.1X session. The absence of 802.1X only means there is no dynamic authentication or SGT propagation via RADIUS, but manual SGT assignment can still be fully operational. Therefore, a missing 802.1X configuration does not explain why role-based policies are not enforced.
- ✗
The 'cts manual' command is incorrect; 'cts dot1x' should be used instead.
Why it's wrong here
This is wrong because 'cts manual' is a completely valid command for trusted interfaces where SGTs are manually assigned to untagged or non-802.1X traffic. It is not a typo or an invalid alternative to 'cts dot1x'—the two modes serve different purposes: 'cts dot1x' is used when the switch relies on 802.1X and RADIUS to dynamically receive SGTs, while 'cts manual' is used for static SGT assignment on trusted links. The problem is not the command syntax but that the SGT mappings themselves are missing on the switch, so the classification cannot occur regardless of which mode is configured.
- ✓
The SGTs are not being propagated to the switch; the switch lacks SGT mappings for the hosts.
Why this is correct
This is correct because role-based enforcement in Cisco TrustSec depends entirely on the switch having a valid SGT mapping for the traffic source. If the SGT is not propagated via CTS/SXP/RADIUS or manually configured as an IP-SGT mapping, the switch cannot determine which SGT to assign to the hosts' traffic. Without that mapping, packets remain untagged or are assigned a default SGT, and the role-based ACL (RBACL) is never applied, so the expected drop does not happen. The root cause is the missing SGT propagation or mapping on the switch, not the interface mode.
- ✗
The 'show cts role-based counters' command shows no drops, indicating the ACLs are not configured.
Why it's wrong here
This is incorrect because 'show cts role-based counters' only displays the number of packets that were actually dropped by role-based access control lists. If enforcement is not active—for example, because the SGTs are missing or the RBACL is not applied to the relevant source/destination pair—the counters will remain at zero, even if an ACL is configured somewhere. The command does not show whether ACLs are configured or attached; it only shows the outcome of enforcement. Therefore, zero drops simply indicate that no packets were rejected, which is consistent with the switch lacking SGT mappings and never evaluating a policy.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
ACLs and Infrastructure Security Features
Key term
SGACL
SGACL stands for Security Group Access Control List, a Cisco technology that controls network traffic based on the security group membership of the source and destination devices rather than IP addresses.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.