TrustSec Static Security Group Tag Classifications
A security engineer has a new TrustSec projct and must create a few static security group tag classifications as proof of concept. Which two classifications must the engineer configure? (Choose two.)
Community Votes
100% of anonymous learners picked answer CE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
TrustSec static SGT classification maps tags to fixed network attributes like VLAN and interface, whereas dynamic classification maps tags to authenticated user identities.
This guide identifies the valid static security group tag (SGT) classifications for a Cisco TrustSec proof of concept. It confirms that VLAN and interface are the correct static classification methods on a network device.
Choosing user ID (D) because it is a common classification method, but it is used for dynamic classification via ISE, not static classification on the switch.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In Cisco TrustSec, Security Group Tags (SGTs) can be assigned statically on network devices or dynamically via Cisco ISE. Static classification maps an SGT to a fixed network attribute that does not change based on the authenticated user, such as a VLAN or a physical interface. For a proof of concept requiring static bindings, configuring VLAN and interface are the appropriate and valid choices. This allows the switch to locally enforce TrustSec policies based on the point of attachment.Why the Other Options Are Wrong
User ID (Option D) is a dynamic classification method typically assigned by ISE during authentication and authorization, not a static switch configuration. Switch ID (Option A) is not a valid classification source for mapping SGTs on a network device. MAC address (Option B) is generally used for dynamic authentication methods like MAB rather than static SGT classification on the switch. Therefore, these options do not fit the requirement for static SGT classification.Community Comment Notes
The community correctly identifies VLAN and interface as the correct static classification methods. As TiberiuszSun noted, "map the SGT to some thing, like a VLAN, subnet, IP Address" for static assignments, contrasting with dynamic user assignments. Other users like qqqqqqqqqqq123 simply confirmed "VLAN & Interface" as the correct choices. This consensus aligns perfectly with the official Cisco TrustSec configuration guidelines for static SGT mapping.Official Reference
Exam Strategy
When asked about TrustSec static classifications, remember that static bindings are tied to non-user-specific network entities like VLANs, subnets, or interfaces. Dynamic bindings involve authentication results like user IDs.