exam questions

Exam 350-401 All Questions

View all questions & answers for the 350-401 exam

Exam 350-401 topic 1 question 260 discussion

Actual exam question from Cisco's 350-401
Question #: 260
Topic #: 1
[All 350-401 Questions]

Which feature does Cisco TrustSec use to provide scalable, secure communication throughout a network?

  • A. security group tag ACL assigned to each port on a switch
  • B. security group tag number assigned to each user on a switch
  • C. security group tag number assigned to each port on a network
  • D. security group tag ACL assigned to each router on a network
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nep1019
Highly Voted 4 years, 10 months ago
According to the Cisco Press official study guide "Cisco TrustSec SGT tags are assigned to authenticated groups of users or end devices". Since the rest mention networks and B mentions users, I'd argue that the correct answer is B.
upvoted 32 times
...
d656971
Most Recent 1 week, 2 days ago
Selected Answer: B
A SGT will certainly be applied to all users. Would it apply to all ports? Not necessarily. All users ports (based on ISE assigned SGT)? Sure. But not trunk ports ;)
upvoted 2 times
...
Doopfenel
1 month, 1 week ago
Selected Answer: C
The correct answer is C. security group tag number assigned to each port on a network. Cisco TrustSec uses a feature called Security Group Tagging (SGT). SGTs are unique identifiers assigned to groups of users, devices, or resources. These tags are not limited to just switches or users. The SGT is propogated on each network port, so that traffic originating or traversing that port can have its traffic properly tagged.
upvoted 1 times
...
CiscoTerminator
6 months ago
I think keyword here is "scalable" - are static assignments scalable? Food for thought!
upvoted 1 times
...
zbeugene7
7 months ago
Correct answer is B. Official Guide, page 735 " ISE assigns SGT tags to users or devices that are successfully authenticated and authorized ... After the SGT tag is assigned. an access enforcement policy based on the SGT tag can be applied at any egress point of the TrustSec network. SGT tags represent the context of the user, device, use case or function, ...SGT named after particular roles.... This is definitely not assigned to a port
upvoted 1 times
...
Eyad_Alotaibi
10 months ago
Security Group Tags allow an organization to create policies based on a user.
upvoted 1 times
...
[Removed]
11 months ago
Selected Answer: C
C is correct Cisco TrustSec uses SGT (Security Group Tagging) to provide scalable, secure communication throughout a network. SGT is a 16-bit tag that is assigned to each port on a switch, not each user. This tag is then attached to network traffic as it passes through network infrastructure devices, based on predefined policies and rules. By using SGTs, Cisco TrustSec can provide granular and dynamic access control throughout the network, allowing only authorized traffic to flow between endpoints.
upvoted 1 times
...
[Removed]
11 months, 1 week ago
Selected Answer: B
not 100% sure but i think B is the correct answer
upvoted 1 times
...
supershysherlock
1 year, 1 month ago
Selected Answer: B
Cisco TrustSec uses Security Group Tags (SGTs), which are assigned to each user or device rather than specific ports or routers. The SGTs are then used to enforce policy decisions across the network.
upvoted 3 times
...
Beehurls
1 year, 1 month ago
Selected Answer: B
The security group tag number is assigned to the user. I am not sure how people are getting caught up on C. The tag number is assigned at the port, but the port does not get assigned a tag number of its own. The port can assign different tag numbers to packets coming in, depending on the user that is sending those packets. Only thing wrong with A and D is where the SGT ACL is applied. It is only at the TrustSec entry points, which may not be all switches or routers.
upvoted 3 times
...
kivi_bg
1 year, 3 months ago
The correct answer is C. They are asking about the network not for a specific switch: "Dynamic classification is typically used to assign SGT to users because users are mobile." https://community.cisco.com/t5/security-knowledge-base/group-based-policy-fundamentals/ta-p/3764433
upvoted 1 times
kivi_bg
1 year, 3 months ago
I mean B :)
upvoted 1 times
...
...
teems5uk
1 year, 4 months ago
Selected Answer: C
Cisco TrustSec uses security group tags (SGTs) to provide scalable, secure communication throughout a network. These security group tags are assigned to network devices, such as switches and routers, and are used to enforce policies based on the identity of the devices and users in the network. The correct answer is: C. security group tag number assigned to each port on a network
upvoted 3 times
...
DJ_Yahia
1 year, 7 months ago
Selected Answer: C
The correct answer is A. security group tag ACL assigned to each port on a switch. Cisco TrustSec is a security architecture that uses security group tags (SGTs) to classify and control traffic flows in a network. SGTs are assigned to ports, switches, and routers. When a packet enters a network, it is tagged with the SGT of the port it entered through. This tag is then used to determine which security group ACLs should be applied to the packet. SGT ACLs are lists of rules that define which traffic is allowed and blocked. These ACLs can be used to create flexible and granular security policies. By using SGTs and SGT ACLs, Cisco TrustSec provides scalable, secure communication throughout a network. The other answer choices are incorrect: B. security group tag number assigned to each user on a switch C. security group tag number assigned to each port on a network D. security group tag ACL assigned to each router on a network SGTs are assigned to ports, switches, and routers, not to users or networks.
upvoted 3 times
...
kewokil120
2 years, 3 months ago
Selected Answer: B
B per nep1019
upvoted 2 times
...
Rose66
2 years, 3 months ago
Selected Answer: C
Cisco TrustSec uses tags to represent logical group privilege. This tag, called a Security Group Tag (SGT), is used in access policies. The SGT is understood and is used to enforce traffic by Cisco switches, routers and firewalls . Cisco TrustSec is defined in three phases: classification, propagation and enforcement. When users and devices connect to a network, the network assigns a specific security group. This process is called classification. Classification can be based on the results of the authentication or by associating the SGT with an IP, VLAN, or port-profile (-> Answer A and answer B are not correct as they say “assigned ... on a switch” only. Answer D is not correct either as it says “assigned to each router”).
upvoted 4 times
...
nopenotme123
2 years, 8 months ago
Selected Answer: B
I deal with ISE on the regular and its assigned based off the user permission.
upvoted 3 times
...
Dreket
2 years, 9 months ago
Selected Answer: B
Provided answer is correct. Explanation below: At the point of network access, a Cisco TrustSec policy group called a Security Group Tag (SGT) is assigned to an endpoint, typically based on that endpoint’s user, device, and location attributes. The SGT denotes the endpoint’s access entitlements, and all traffic from the endpoint will carry the SGT information. The SGT is used by switches, routers, and firewalls to make forwarding decisions. Because SGT assignments can denote business roles and functions, Cisco TrustSec controls can be defined in terms of business needs and not underlying networking detail. https://www.cisco.com/c/dam/en/us/products/collateral/security/identity-services-engine/at_a_glance_c45-726831.pdf
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago