TrustSec Static Security Group Tag Classifications

Configure Cisco TrustSec
Answer Correct answer: C, E — The engineer must configure VLAN and interface for static security group tag classifications.

A security engineer has a new TrustSec projct and must create a few static security group tag classifications as proof of concept. Which two classifications must the engineer configure? (Choose two.)

  1. switch ID
  2. MAC address
  3. VLAN Correct Answer
  4. user ID
  5. interface Correct Answer

Community Votes

CE
100%

100% of anonymous learners picked answer CE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

TrustSec static SGT classification maps tags to fixed network attributes like VLAN and interface, whereas dynamic classification maps tags to authenticated user identities.

This guide identifies the valid static security group tag (SGT) classifications for a Cisco TrustSec proof of concept. It confirms that VLAN and interface are the correct static classification methods on a network device.

Choosing user ID (D) because it is a common classification method, but it is used for dynamic classification via ISE, not static classification on the switch.

Community Discussion (5 comments)

logitrain 👍 1
The correct answer is C. VLAN. Reason: In the context of Cisco TrustSec, VLAN (Virtual Local Area Network) is a common classification used to segment network traffic based on logical groupings. By configuring VLANs as security group tags, the engineer can enforce policy-based access controls and ensure that traffic within the same VLAN is treated consistently. This is essential for maintaining security across different segments of the network.
TiberiuszSun 👍 1 Selected: CE
The process of assigning the SGT is called Classification. A SGT can be assigned dynamically as the result of an ISE authorization or it can be assigned via static methods that map the SGT to some thing, like a VLAN, subnet, IP Address, or port-profile (for VMs or interface). Dynamic classification is typically used to assign SGT to users because users are mobile. They could be connected from any location via wireless, wired, or vpn. On the other hand, servers tend not to move, so typically static classification methods are used.
NullNull88 👍 1
vlan and int
HercJ 👍 2
I believe it should be VLAN and interface
qqqqqqqqqqq123 👍 3 Selected: CE
VLAN & Interface

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In Cisco TrustSec, Security Group Tags (SGTs) can be assigned statically on network devices or dynamically via Cisco ISE. Static classification maps an SGT to a fixed network attribute that does not change based on the authenticated user, such as a VLAN or a physical interface. For a proof of concept requiring static bindings, configuring VLAN and interface are the appropriate and valid choices. This allows the switch to locally enforce TrustSec policies based on the point of attachment.

Why the Other Options Are Wrong

User ID (Option D) is a dynamic classification method typically assigned by ISE during authentication and authorization, not a static switch configuration. Switch ID (Option A) is not a valid classification source for mapping SGTs on a network device. MAC address (Option B) is generally used for dynamic authentication methods like MAB rather than static SGT classification on the switch. Therefore, these options do not fit the requirement for static SGT classification.

Community Comment Notes

The community correctly identifies VLAN and interface as the correct static classification methods. As TiberiuszSun noted, "map the SGT to some thing, like a VLAN, subnet, IP Address" for static assignments, contrasting with dynamic user assignments. Other users like qqqqqqqqqqq123 simply confirmed "VLAN & Interface" as the correct choices. This consensus aligns perfectly with the official Cisco TrustSec configuration guidelines for static SGT mapping.

Official Reference

Exam Strategy

When asked about TrustSec static classifications, remember that static bindings are tied to non-user-specific network entities like VLANs, subnets, or interfaces. Dynamic bindings involve authentication results like user IDs.

Related Analysis

← Back to 300-715 Study Guide