hardMultiple Choice
350-401 Practice Question: Is implementing Cisco TrustSec (CTS) with…
A network engineer is implementing Cisco TrustSec (CTS) with Security Group Tags (SGTs) using SXP (SGT Exchange Protocol). The engineer configures the switch as an SXP speaker and the Cisco ISE as an SXP listener. The engineer verifies that SXP peers are established. However, when the engineer checks 'show cts role-based sgt map', the SGT mappings for users are not present. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the misconception that SXP itself creates or assigns SGTs, when in reality SXP only propagates existing mappings; the trap here is assuming a working SXP peer relationship guarantees populated SGT mappings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The switch is not configured to assign SGTs to users via 802.1X or static mapping.
The SXP protocol only propagates SGT-to-IP mappings that already exist on the speaker device. If the switch is not configured to assign SGTs to users via 802.1X or static mapping, no SGT mappings will be generated to send to ISE. The 'show cts role-based sgt map' command displays the local SGT mapping table, which remains empty because the switch has no mechanism to associate users with SGTs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The SXP version mismatch between the switch and ISE.
Why it's wrong here
An SXP version mismatch does not prevent SGT propagation because SXP peers negotiate a common version during connection setup, and the protocol is designed to be backward compatible. ISE and modern IOS/IOS-XE support multiple SXP versions, so even if the configured version differs, the peers still establish and exchange bindings. Since the SXP adjacency is already up, a version mismatch cannot be the reason no SGTs are sent to ISE.
- ✓
The switch is not configured to assign SGTs to users via 802.1X or static mapping.
Why this is correct
SXP is a transport mechanism that only propagates IP-to-SGT bindings that already exist locally on the speaker device. If the access switch has not been configured with a downloadable SGT from 802.1X (e.g., via Cisco ISE policy and RADIUS dACL attributes) or with static 'ip sgt' mappings, then its SXP table is empty and there is nothing to publish to ISE. The absence of local SGT assignments is the direct cause of no SGTs being sent.
- ✗
The ISE is configured as an SXP speaker instead of a listener.
Why it's wrong here
An SXP speaker/listener role mismatch is not the issue because the engineer configured the switch as the speaker and ISE as the listener, which is the correct topology for distributing IP-to-SGT bindings from the access layer to the policy server. SXP requires one speaker and one listener; reversing them would make ISE the sender, but the switch would then be a listener and would not export its own mappings. Since the SXP connection is established with the right roles, this option is incorrect.
- ✗
The SXP connection is using the wrong TCP port.
Why it's wrong here
SXP uses the well-known TCP port 64999 by default, and the scenario states that the SXP peers are already established. If the TCP port were incorrect, the SXP connection would never complete the TCP handshake, and the adjacency would not show as up. Because the connection is up and the problem is specifically a lack of SGTs propagating, the port setting is not the cause.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
ACLs and Infrastructure Security Features
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.