Courseiva
mediumMultiple Choice

350-401 Practice Question: An architect is designing an SD-Access fabric for…

An architect is designing an SD-Access fabric for a campus network that requires segmentation of guest, employee, and IoT traffic. The design must use Cisco TrustSec for policy enforcement. Which component is responsible for assigning the Security Group Tag (SGT) to endpoints upon authentication?

⚠ Common exam trap

Cisco often tests the distinction between the policy decision point (ISE) and the policy enforcement point (fabric edge node), so the trap here is that candidates mistakenly think the fabric edge node assigns the SGT because it applies the tag to packets, but the assignment occurs during authentication by ISE.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cisco ISE

Cisco ISE is the policy decision point in a TrustSec-enabled SD-Access fabric. When an endpoint authenticates via 802.1X, MAB, or web authentication, ISE evaluates the authentication result and the applicable authorization policy, then dynamically assigns a Security Group Tag (SGT) to the endpoint. This SGT is passed to the network access device (e.g., fabric edge node) via RADIUS attributes in the Access-Accept message, enabling consistent policy enforcement throughout the fabric.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cisco ISE

    Why this is correct

    Cisco ISE is the SDA identity and policy layer; during 802.1X, MAB, or web authentication it authenticates each endpoint and dynamically classifies it by assigning a Security Group Tag (SGT). The SGT is sourced from ISE and distributed to the fabric via RADIUS and pxGrid, so downstream devices use that tag rather than IP ACLs for consistent policy enforcement. Without ISE, no endpoint can be reliably associated with an SGT in a scalable SD-Access deployment.

  • ✗

    Fabric edge node

    Why it's wrong here

    The fabric edge node is the access switch that attaches endpoints to the SD-Access fabric; it enforces the policy by applying SGACLs based on the SGT carried in the VXLAN header. However, it does not assign the SGT—it receives the tag as an authentication result from ISE over RADIUS or, in some designs, via SXP. The edge's role is forwarding and enforcement, not identity classification; treating the edge as the SGT source misunderstands the trust boundary in the fabric.

  • ✗

    Fabric control plane node

    Why it's wrong here

    The fabric control plane node implements the LISP mapping system, maintaining the EID-to-RLOC database that lets the fabric perform location/identity separation. LISP operates at Layer 3 and is concerned with reachability and routing, not with user identity or security policy classification. SGT assignment is an authorization decision from ISE and is propagated separately from the EID-to-RLOC mappings, so the control plane node has no role in creating or assigning the tag.

  • ✗

    Cisco DNA Center

    Why it's wrong here

    Cisco DNA Center serves as the controller and management plane for SD-Access, automating device onboarding, fabric provisioning, and policy intent. Although DNA Center can display and push policy configuration to devices, it does not authenticate endpoints and cannot independently generate or assign an SGT; the actual assignment is performed by ISE in its role as the Policy Service Point. DNA Center's visibility into security policy is aggregated from ISE, not created by the controller itself.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.