Command to Tag Packets with SGT via SXP

Configure Cisco TrustSec
Answer Correct answer: C — Enter the ip device tracking maximum command to enable the switch to track endpoints and impose SGTs learned via SXP.

An engineer is working on a switch and must tag packets with SGT values such that it learns via SXP. Which command must be entered to meet this requirement?

  1. ip source guard
  2. ip arp inspection
  3. ip device tracking maximum Correct Answer
  4. ip dhcp snooping

Community Votes

C
80%
D
20%

80% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the prerequisite command for imposing SGTs on data plane traffic when bindings are learned via SXP, where the common trap is confusing DHCP snooping with IP device tracking.

This page explains the required switch command to tag packets with SGT values learned via SXP in Cisco TrustSec. It establishes that IP device tracking is the necessary feature to map IP-to-SGT bindings to MAC addresses for data plane tagging.

Choosing ip dhcp snooping (D) because it also tracks IP addresses, but failing to recognize that IP device tracking is the explicit requirement for TrustSec SGT imposition.

Community Discussion (3 comments)

Jimmyb007 👍 1 Selected: C
ip device tracking is required. https://www.cisco.com/c/en/us/td/docs/switches/lan/trustsec/configuration/guide/trustsec/ident-conn_config.html The maximum part is supported on some switches too
zullo888 👍 1 Selected: D
I would go with D as there is no such command like "ip device tracking max": During endpoint authentication, a host accessing the Cisco TrustSec domain (the endpoint IP address) is associated with an SGT at the access device through Dynamic Host Control Protocol (DHCP) snooping and IP device tracking.
factmrojas 👍 3 Selected: C
C is correct answer

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

To impose an SGT on data plane traffic when the binding is learned via SXP, the switch must resolve the destination IP address to a MAC address. The ip device tracking command (specifically ip device tracking maximum on many platforms) enables the switch to track the IP-to-MAC bindings of endpoints, which is a strict prerequisite for applying SXP-learned SGTs to packets. Without this feature, the switch cannot map the IP-SGT binding to the hardware forwarding plane.

Why the Other Options Are Wrong

Option A (ip source guard) is a security feature that prevents IP spoofing by filtering traffic, but it does not track endpoints for SGT imposition. Option B (ip arp inspection) validates ARP packets to prevent man-in-the-middle attacks but does not provide the IP-to-MAC tracking needed for TrustSec. Option D (ip dhcp snooping) builds a DHCP binding table, but it is not the explicit command required to enable the endpoint tracking mechanism for TrustSec SXP tagging, which relies on IP device tracking.

Community Comment Notes

Commenters debated whether ip device tracking maximum is a valid command, with one user incorrectly arguing it does not exist and favoring DHCP snooping. However, as Jimmyb007 noted, "ip device tracking is required" and "The maximum part is supported on some switches too", confirming that option C is the correct syntax for those platforms.

Official Reference

Exam Strategy

When asked about switch commands for TrustSec SXP or SGT imposition, look for IP device tracking as the prerequisite. Remember that DHCP snooping builds a binding table but IP device tracking is the specific feature required to map IP-SGT bindings to MAC addresses for tagging.

Related Analysis

← Back to 300-715 Study Guide