Cisco TrustSec SGT Propagation Methods

Describe Cloud security integration
Answer Correct answer: C, E — SXP and inline tagging are the two supported methods for propagating Security Group Tags in Cisco TrustSec.

Which two types of SGT propagation are supported by Cisco TrustSec? (Choose two.)

  1. key chain
  2. offline tagging
  3. SXP Correct Answer
  4. reconciliation
  5. inline tagging Correct Answer

Community Votes

CE
100%

100% of anonymous learners picked answer CE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the distinction between active tagging protocols and mapping databases; the common trap is confusing these with authentication or reconciliation features.

This question tests knowledge of Cisco TrustSec Security Group Tag (SGT) propagation mechanisms, specifically identifying inline tagging and SXP as the supported methods.

Learners often select 'reconciliation' or 'offline tagging' because they sound like valid network management terms, but they are not standard SGT propagation methods in this context.

Community Discussion (3 comments)

Loi2525 👍 2 Selected: CE
CE correct https://www.cisco.com/c/en/us/td/docs/switches/lan/trustsec/configuration/guide/trustsec/sgt_inline_tagging.html
Gycu 👍 1 Selected: CE
CE correct
Stanleymahamadi 👍 1
Correct Answer CE

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Cisco TrustSec utilizes two primary methods to propagate Security Group Tags (SGTs) across the network: inline tagging and SGT Exchange Protocol (SXP). Inline tagging involves embedding the SGT directly into the Ethernet frame header (using either MACsec or a dedicated field), allowing switches to read the tag natively. SXP operates at layer 3, maintaining a database that maps IP addresses to SGTs for devices that cannot support inline tagging, such as legacy endpoints or servers.

Why the Other Options Are Wrong

Key chains are used for authentication key rotation, not security group tagging. Offline tagging typically refers to manual assignment or non-real-time processes, which does not constitute active propagation across the network fabric. Reconciliation is a concept related to identity management synchronization (like syncing AD groups to SGACLs), not the transport mechanism for the tags themselves.

Community Comment Notes

Community feedback strongly supports options C and E. As noted by user Loi2525, official Cisco documentation confirms that both SXP and inline tagging are the core propagation technologies. Multiple users verified this answer as correct based on their exam experience.

Official Reference

Exam Strategy

Memorize the two pillars of TrustSec propagation: Layer 2/3 frame modification (Inline) and Layer 3 IP-to-SGT mapping (SXP). Distinguish these from configuration tools like feature profiles or templates.

Frequently Asked Questions

What is the difference between inline tagging and SXP?

Inline tagging embeds the SGT in the data frame (Layer 2), while SXP maps IP addresses to SGTs over TCP (Layer 3) for devices that cannot modify frames.

Can offline tagging be used for real-time segmentation?

No, offline tagging implies manual or delayed assignment. Real-time propagation requires either inline tagging or SXP to ensure immediate policy enforcement.

Related Analysis

Practice All 300-415 Questions

Access 120 questions with complete answers and detailed explanations.

View Full 300-415 Practice Test →

← Back to 300-415 Study Guide