exam questions

Exam 300-715 All Questions

View all questions & answers for the 300-715 exam

Exam 300-715 topic 1 question 180 discussion

Actual exam question from Cisco's 300-715
Question #: 180
Topic #: 1
[All 300-715 Questions]

A Cisco device has a port configured in multi-authentication mode and is accepting connections only from hosts assigned the SGT of SGT_0123456789. The
VLAN trunk link supports a maximum of 8 VLANS. What is the reason for these restrictions?

  • A. The device is performing inline tagging without acting as a SXP speaker.
  • B. The device is performing inline tagging while acting as a SXP speaker.
  • C. The IP subnet addresses are dynamically mapped to an SGT.
  • D. The IP subnet addresses are statically mapped to an SGT.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
denverfly
5 months ago
Selected Answer: A
The answer is The device is performing inline tagging without acting as a SXP speaker. When a Cisco device is performing inline tagging, it inserts a Security Group Tag (SGT) into the packet header. This allows the device to enforce security policies based on the SGT. However, if the device is not acting as a SXP speaker, it can only accept connections from hosts that are assigned the same SGT as the device. This is because the device cannot learn about other SGTs without being a SXP speaker. The VLAN trunk link supports a maximum of 8 VLANs because each VLAN requires a unique SGT. If the device were to accept connections from hosts with different SGTs, it would not be able to enforce security policies correctly.
upvoted 4 times
...
iceise
11 months, 4 weeks ago
Selected Answer: A
https://www.cisco.com/c/en/us/td/docs/switches/lan/trustsec/configuration/guide/trustsec/sxp_config.html#Restriction%20for%20SGT%20Exchange%20Protocol The following restrictions are applicable when running Cisco TrustSec in enforcement mode or inline tagging mode. These restrictions do not apply when these switches are used as an SXP speaker: • An IP subnet address cannot be statically mapped to a Security Group Tag (SGT). • If a port is configured in multi-authentication mode, all hosts connecting to that port must be assigned the same SGT. • Cisco TrustSec enforcement mode on a VLAN trunk line supports only up to eight VLANs. If more than eight VLANs are configured on a VLAN trunk link and Cisco TrustSec is enabled on those VLANs,
upvoted 3 times
...
shonda319
1 year, 1 month ago
Selected Answer: A
Correct answer is A https://www.cisco.com/c/en/us/td/docs/switches/lan/trustsec/configuration/guide/trustsec/sxp_config.html
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago