Which TrustSec policy feature provides endpoint entitlement?

Which policy feature is used with TrustSec to provide endpoint entitlement in an enterprise network?

  1. security group tags Source Reference Answer
  2. access control lists
  3. virtual local area network
  4. virtual routing and forwarding

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your understanding that TrustSec enforces identity-based access using SGTs, not traditional IP-based ACLs or segmentation technologies.

Cisco TrustSec uses Security Group Tags (SGTs) to classify endpoints and enforce policy based on identity rather than IP address. Community consensus unanimously selects SGTs as the correct answer.

Some candidates choose VLANs (option C) because VLANs also segment traffic, but VLANs are a legacy Layer 2 mechanism and not the policy feature TrustSec uses for endpoint entitlement.

Community Discussion (3 comments)

chiacche 👍 1 Selected: A
Security Group Tags (SGTs)
supershysherlock 👍 1 Selected: A
Correctus!
Mizuchan 👍 4 Selected: A
TrustSec utilizes Security Group Tags (SGTs) to define and enforce policies based on the identity of the endpoints in the network. This helps in dynamically assigning and enforcing access policies based on the security group to which an endpoint belongs.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Security Group Tags (SGTs) are the core policy element in Cisco TrustSec that represent an endpoint's security group or role. Once assigned via authentication or profiling, SGTs are carried in packets (typically in the SGT Exchange Protocol header) and used to build Security Group Access Control Lists (SGACLs) on enforcement devices. This enables identity- and role-based access enforcement independent of IP addressing or topology.

Why the Other Options Are Wrong

Access Control Lists (ACLs) enforce rules but are not the TrustSec-specific policy feature for endpoint entitlement; SGACLs are the TrustSec variant that references SGTs. VLANs provide broadcast-domain segmentation but do not convey endpoint identity or role across the network. Virtual Routing and Forwarding (VRF) is a routing-instance technology unrelated to endpoint classification or TrustSec policy enforcement.

Community Comment Notes

Top-voted comments confirm that TrustSec dynamically assigns and enforces access policies based on the SGT attached to each endpoint. One comment incorrectly suggests VLANs, but the overwhelming consensus and Cisco documentation align with SGTs as the defining TrustSec policy feature.

Official Reference

Exam Strategy

When a question mentions TrustSec and endpoint entitlement, immediately look for Security Group Tags. Eliminate IP-centric or topology-centric options like ACLs, VLANs, and VRFs, which do not carry identity metadata in the TrustSec framework.

Related Analysis

Practice All 350-401 Questions

Access 218 questions with complete answers and detailed explanations.

View Full 350-401 Practice Test →

← Back to 350-401 Study Guide