hardMultiple Select
350-401 Practice Question: Which three statements about Cisco TrustSec (CTS)…
Which three statements about Cisco TrustSec (CTS) are true? (Choose three.)
⚠ Common exam trap
350-401 often tests CTS details, and candidates incorrectly believe SGTs are mapped to IPs centrally or that CTS removes all ACLs, missing that SGTs are identity-based and SGACLs replace only some ACL functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cisco TrustSec uses Security Group Tags (SGTs) to classify traffic based on user or device identity.
Option A is correct because Cisco TrustSec classifies traffic by applying Security Group Tags (SGTs) that represent the identity/role of the user or device, enabling group-based policy rather than IP-based rules. Option C is correct because 802.1X authentication can drive dynamic SGT assignment: after the supplicant authenticates, the ISE/AAA server returns an authorization result (e.g., cisco-av-pair with an SGT value) that the switch applies to the port/session. Option E is correct because TrustSec supports inline tagging, where the 16-bit SGT is inserted into the Ethernet frame (using the Cisco Meta Data / CMD header with EtherType 0x8909) so the tag travels with the packet hop-by-hop. Option B is not correct as stated because SGTs are not 'typically assigned to IP addresses' via a centralized mapping database; SGT-to-IP mappings are used for devices that cannot tag natively (e.g., via SXP or IP-to-SGT mapping), but the primary assignment is identity/session-based, not IP-based. Option D is not correct because TrustSec augments, but does not eliminate, traditional ACLs; SGACL enforcement still relies on underlying ACL-like constructs and existing ACLs may remain for other purposes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cisco TrustSec uses Security Group Tags (SGTs) to classify traffic based on user or device identity.
Why this is correct
Security Group Tags are the classification mechanism at the heart of TrustSec, tagging packets based on user or device identity rather than IP addresses. This identity-based classification is what enables scalable, topology-independent segmentation across the network.
- ✗
SGTs are typically assigned to IP addresses using a centralized SGT mapping database.
Why it's wrong here
SGTs are assigned to IP addresses through the centralised SGT Mapping Database on Cisco ISE, or statically via CLI and dynamically via SXP, so the statement is true. It is tempting to reject because SXP peer-to-peer propagation exists, but that supplements rather than replaces centralised IP-to-SGT mapping.
- ✓
802.1X can be used as the authentication mechanism to dynamically assign an SGT to a supplicant.
Why this is correct
802.1X provides identity-based authentication at the access layer, and the resulting identity can be mapped to an SGT via the SGT Exchange Protocol or static mapping. This makes 802.1X a valid dynamic SGT assignment mechanism for supplicants.
- ✗
Cisco TrustSec eliminates the need for all traditional ACLs in the network.
Why it's wrong here
TrustSec enforces policy through SGT-based SGACLs, which replace IP-based ACLs but do not eliminate ACLs entirely; SGACLs are still ACLs, and non-TrustSec traffic still needs traditional ACLs. It is tempting because TrustSec removes IP-address dependence, which is the correct fix for scaling policy in large networks.
- ✓
SGTs can be carried in the Ethernet frame header using Cisco's inline tagging method.
Why this is correct
Inline tagging inserts the 16-bit source group tag directly into the Ethernet frame header, letting CTS enforce group-based policy without reclassifying traffic at every hop. This satisfies the stem's requirement that SGTs travel in the frame itself, unlike SXP, which propagates tags out-of-band between devices.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
ACLs and Infrastructure Security Features
Key term
SGACL
SGACL stands for Security Group Access Control List, a Cisco technology that controls network traffic based on the security group membership of the source and destination devices rather than IP addresses.
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.