Cisco TrustSec SGT Propagation Methods
Which two types of SGT propagation are supported by Cisco TrustSec? (Choose two.)
Community Votes
100% of anonymous learners picked answer CE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the distinction between active tagging protocols and mapping databases; the common trap is confusing these with authentication or reconciliation features.
This question tests knowledge of Cisco TrustSec Security Group Tag (SGT) propagation mechanisms, specifically identifying inline tagging and SXP as the supported methods.
Learners often select 'reconciliation' or 'offline tagging' because they sound like valid network management terms, but they are not standard SGT propagation methods in this context.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Cisco TrustSec utilizes two primary methods to propagate Security Group Tags (SGTs) across the network: inline tagging and SGT Exchange Protocol (SXP). Inline tagging involves embedding the SGT directly into the Ethernet frame header (using either MACsec or a dedicated field), allowing switches to read the tag natively. SXP operates at layer 3, maintaining a database that maps IP addresses to SGTs for devices that cannot support inline tagging, such as legacy endpoints or servers.Why the Other Options Are Wrong
Key chains are used for authentication key rotation, not security group tagging. Offline tagging typically refers to manual assignment or non-real-time processes, which does not constitute active propagation across the network fabric. Reconciliation is a concept related to identity management synchronization (like syncing AD groups to SGACLs), not the transport mechanism for the tags themselves.Community Comment Notes
Community feedback strongly supports options C and E. As noted by user Loi2525, official Cisco documentation confirms that both SXP and inline tagging are the core propagation technologies. Multiple users verified this answer as correct based on their exam experience.Official Reference
Exam Strategy
Memorize the two pillars of TrustSec propagation: Layer 2/3 frame modification (Inline) and Layer 3 IP-to-SGT mapping (SXP). Distinguish these from configuration tools like feature profiles or templates.
Frequently Asked Questions
What is the difference between inline tagging and SXP?
Inline tagging embeds the SGT in the data frame (Layer 2), while SXP maps IP addresses to SGTs over TCP (Layer 3) for devices that cannot modify frames.
Can offline tagging be used for real-time segmentation?
No, offline tagging implies manual or delayed assignment. Real-time propagation requires either inline tagging or SXP to ensure immediate policy enforcement.
Related Analysis
Practice All 300-415 Questions
Access 120 questions with complete answers and detailed explanations.
View Full 300-415 Practice Test →