Courseiva
Question 1,055 of 1,840
hardMultiple ChoiceObjective-mapped

350-401 Practice Question: Is deploying Cisco TrustSec (CTS) with Security…

A network engineer is deploying Cisco TrustSec (CTS) with Security Group Access Control Lists (SGACLs) on a campus network. The engineer configures the switch with 'cts role-based enforcement' and assigns SGTs to users via 802.1X. The engineer tests connectivity between a user in SGT 10 and a server in SGT 20. The SGACL permits traffic from SGT 10 to SGT 20, but the user cannot reach the server. The engineer checks 'show cts role-based sgt map' and sees that the user's SGT is 0. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the misconception that SGT 0 is a special deny-all SGT, but in reality, SGT 0 is the default untagged SGT and simply means no SGT was assigned, causing traffic to be implicitly denied by SGACL default-deny logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The RADIUS server is not configured to send the SGT in the Access-Accept message.

The user's SGT is shown as 0 in the 'show cts role-based sgt map' output, which is the default SGT assigned when no SGT is received from the RADIUS server. Since the SGACL permits traffic from SGT 10 to SGT 20, but the user has SGT 0, the SGACL does not match, and traffic is implicitly denied. The most likely cause is that the RADIUS server is not configured to send the SGT in the Access-Accept message, so the switch cannot dynamically assign the correct SGT.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The RADIUS server is not configured to send the SGT in the Access-Accept message.

    Why this is correct

    Correct because the SGT must be assigned by the RADIUS server during authentication.

  • The SGACL is applied to the wrong interface.

    Why it's wrong here

    Incorrect because SGACLs are role-based, not interface-based.

  • The switch is not configured with 'cts role-based enforcement'.

    Why it's wrong here

    Incorrect because the engineer configured it, and the command is present.

  • The user's SGT is 0, which is a valid SGT that denies all traffic.

    Why it's wrong here

    Incorrect because SGT 0 means no SGT assigned; it does not deny all traffic by default.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jul 4, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.