Courseiva
hardMultiple Select

350-401 Practice Question: Which three statements about Cisco TrustSec (CTS)…

Which three statements about Cisco TrustSec (CTS) are true? (Choose three.)

⚠ Common exam trap

350-401 often tests CTS details, and candidates incorrectly believe SGTs are mapped to IPs centrally or that CTS removes all ACLs, missing that SGTs are identity-based and SGACLs replace only some ACL functions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cisco TrustSec uses Security Group Tags (SGTs) to classify traffic based on user or device identity.

Option A is correct because Cisco TrustSec classifies traffic by applying Security Group Tags (SGTs) that represent the identity/role of the user or device, enabling group-based policy rather than IP-based rules. Option C is correct because 802.1X authentication can drive dynamic SGT assignment: after the supplicant authenticates, the ISE/AAA server returns an authorization result (e.g., cisco-av-pair with an SGT value) that the switch applies to the port/session. Option E is correct because TrustSec supports inline tagging, where the 16-bit SGT is inserted into the Ethernet frame (using the Cisco Meta Data / CMD header with EtherType 0x8909) so the tag travels with the packet hop-by-hop. Option B is not correct as stated because SGTs are not 'typically assigned to IP addresses' via a centralized mapping database; SGT-to-IP mappings are used for devices that cannot tag natively (e.g., via SXP or IP-to-SGT mapping), but the primary assignment is identity/session-based, not IP-based. Option D is not correct because TrustSec augments, but does not eliminate, traditional ACLs; SGACL enforcement still relies on underlying ACL-like constructs and existing ACLs may remain for other purposes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cisco TrustSec uses Security Group Tags (SGTs) to classify traffic based on user or device identity.

    Why this is correct

    Security Group Tags are the classification mechanism at the heart of TrustSec, tagging packets based on user or device identity rather than IP addresses. This identity-based classification is what enables scalable, topology-independent segmentation across the network.

  • ✗

    SGTs are typically assigned to IP addresses using a centralized SGT mapping database.

    Why it's wrong here

    SGTs are assigned to IP addresses through the centralised SGT Mapping Database on Cisco ISE, or statically via CLI and dynamically via SXP, so the statement is true. It is tempting to reject because SXP peer-to-peer propagation exists, but that supplements rather than replaces centralised IP-to-SGT mapping.

  • ✓

    802.1X can be used as the authentication mechanism to dynamically assign an SGT to a supplicant.

    Why this is correct

    802.1X provides identity-based authentication at the access layer, and the resulting identity can be mapped to an SGT via the SGT Exchange Protocol or static mapping. This makes 802.1X a valid dynamic SGT assignment mechanism for supplicants.

  • ✗

    Cisco TrustSec eliminates the need for all traditional ACLs in the network.

    Why it's wrong here

    TrustSec enforces policy through SGT-based SGACLs, which replace IP-based ACLs but do not eliminate ACLs entirely; SGACLs are still ACLs, and non-TrustSec traffic still needs traditional ACLs. It is tempting because TrustSec removes IP-address dependence, which is the correct fix for scaling policy in large networks.

  • ✓

    SGTs can be carried in the Ethernet frame header using Cisco's inline tagging method.

    Why this is correct

    Inline tagging inserts the 16-bit source group tag directly into the Ethernet frame header, letting CTS enforce group-based policy without reclassifying traffic at every hop. This satisfies the stem's requirement that SGTs travel in the frame itself, unlike SXP, which propagates tags out-of-band between devices.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

Go deeper

Related to this question

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.