exam questions

Exam 300-420 All Questions

View all questions & answers for the 300-420 exam

Exam 300-420 topic 1 question 53 discussion

Actual exam question from Cisco's 300-420
Question #: 53
Topic #: 1
[All 300-420 Questions]

Which component of Cisco SD-Access integrates with Cisco DNA Center to perform policy segmentation and enforcement through the use of security group access control lists and security group tags?

  • A. Cisco Application Policy Infrastructure Controller Enterprise Module
  • B. Cisco Network Data Platform
  • C. Cisco Identity Services Engine
  • D. Cisco TrustSec
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
SpicyMochi
5 months, 4 weeks ago
Selected Answer: C
The correct answer is C. Cisco Identity Services Engine (ISE). Cisco ISE integrates with Cisco DNA Center to perform policy segmentation and enforcement in an SD-Access network. It uses security group access control lists (SGACLs) and security group tags (SGTs) to enforce policies based on user and device profiles. ISE enables the creation and management of these security policies, ensuring that proper access is granted based on user and device identity.
upvoted 2 times
...
cerifyme85
6 months, 1 week ago
Selected Answer: C
SGT ==> DNAC + ISE While SGTs are administered by Cisco ISE through the tightly integrated REST APIs, Cisco DNA Center is used as the pane of glass to manage and create SGTs and define their policies.
upvoted 2 times
...
cerifyme85
6 months, 1 week ago
SGT ==> DNAC + ISE While SGTs are administered by Cisco ISE through the tightly integrated REST APIs, Cisco DNA Center is used as the pane of glass to manage and create SGTs and define their policies. TrustSec--> Just a term Cisco TrustSec is an umbrella term for security improvements to Cisco network devices based on the capability to strongly identify users, hosts and network devices within a network. TrustSec provides topology independent and scalable access controls by uniquely classifying data traffic for a particular role. TrustSec ensures data confidentiality and integrity by establishing trust among authenticated peers and encrypting links with those peers. The key component of Cisco TrustSec is the Cisco Identity Services Engine. It is typical for the Cisco ISE to provision switches with TrustSec Identities and Security Group ACLs (SGACLs), though these may be configured manually.
upvoted 1 times
...
DOSKIM
7 months ago
IT IS TRUSTSEC
upvoted 1 times
...
iLikeHamburgers
10 months, 2 weeks ago
Selected Answer: C
also if you look at the OCG, pg330, it says "Cisco ISE is a critical component of SD-Access for policy enforcement..."
upvoted 2 times
...
iLikeHamburgers
1 year ago
Selected Answer: C
Answer is C "The key component of Cisco TrustSec is the Cisco Identity Services Engine." https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12-2SY/configuration/guide/sy_swcg/trustsec.pdf
upvoted 2 times
...
SergeBesse
1 year, 1 month ago
Selected Answer: C
C is the correct answer. Cisco ISE is a sd-access component. Cisco trustsec is a feature
upvoted 2 times
...
Kamran202034
1 year, 2 months ago
Selected Answer: C
C is correct. Policy management with identity services is enabled in an SD-Access network using ISE integrated with Cisco DNA Center for dynamic mapping of users and devices to scalable groups. https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-sda-design-guide.html#CiscoDNACenterSoftware
upvoted 2 times
...
python_tamer
1 year, 4 months ago
I'm torn between C and D. Trustsec is the name of the feature. But it's ISE that actually pushes SGTs and SGACLs to the NADs. DNAC is a single pane of glass to manage it. So I think the answer is more likely to be C because ISE has to be integrated with DNAC for Trustsec to work in SDA. https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/cisco-sda-design-guide.html#IdentityServicesEngine
upvoted 1 times
...
Xavi07
2 years, 3 months ago
Yes, it-s trustsec
upvoted 3 times
...
luisjuradoledesma
2 years, 8 months ago
Effectively, it's Cisco TrustSec - ISE is for identity context, authentication, posture validation, etc Cisco TrustSec - Security provided by Cisco TrustSec ® infrastructure (Security Group Tags [SGT], SGACLs) and Cisco segmentation capabilities (Cisco Locator/ID Separation Protocol [LISP], VXLAN, and Virtual Routing and Forwarding [VRF]). Identity context for users and devices, including authentication, posture validation, and device profiling, provided by the Cisco ISE. https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/software-defined-access/nb-09-sda-faq-cte-en.html
upvoted 4 times
CCNPWILL
2 years, 3 months ago
Correct. Answer is D.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago