Command to Tag Packets with SGT via SXP
An engineer is working on a switch and must tag packets with SGT values such that it learns via SXP. Which command must be entered to meet this requirement?
Community Votes
80% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the prerequisite command for imposing SGTs on data plane traffic when bindings are learned via SXP, where the common trap is confusing DHCP snooping with IP device tracking.
This page explains the required switch command to tag packets with SGT values learned via SXP in Cisco TrustSec. It establishes that IP device tracking is the necessary feature to map IP-to-SGT bindings to MAC addresses for data plane tagging.
Choosing ip dhcp snooping (D) because it also tracks IP addresses, but failing to recognize that IP device tracking is the explicit requirement for TrustSec SGT imposition.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To impose an SGT on data plane traffic when the binding is learned via SXP, the switch must resolve the destination IP address to a MAC address. Theip device tracking command (specifically ip device tracking maximum on many platforms) enables the switch to track the IP-to-MAC bindings of endpoints, which is a strict prerequisite for applying SXP-learned SGTs to packets. Without this feature, the switch cannot map the IP-SGT binding to the hardware forwarding plane.Why the Other Options Are Wrong
Option A (ip source guard) is a security feature that prevents IP spoofing by filtering traffic, but it does not track endpoints for SGT imposition. Option B (ip arp inspection) validates ARP packets to prevent man-in-the-middle attacks but does not provide the IP-to-MAC tracking needed for TrustSec. Option D (ip dhcp snooping) builds a DHCP binding table, but it is not the explicit command required to enable the endpoint tracking mechanism for TrustSec SXP tagging, which relies on IP device tracking.Community Comment Notes
Commenters debated whetherip device tracking maximum is a valid command, with one user incorrectly arguing it does not exist and favoring DHCP snooping. However, as Jimmyb007 noted, "ip device tracking is required" and "The maximum part is supported on some switches too", confirming that option C is the correct syntax for those platforms. Official Reference
Exam Strategy
When asked about switch commands for TrustSec SXP or SGT imposition, look for IP device tracking as the prerequisite. Remember that DHCP snooping builds a binding table but IP device tracking is the specific feature required to map IP-SGT bindings to MAC addresses for tagging.