Which TrustSec policy feature provides endpoint entitlement?
Which policy feature is used with TrustSec to provide endpoint entitlement in an enterprise network?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests your understanding that TrustSec enforces identity-based access using SGTs, not traditional IP-based ACLs or segmentation technologies.
Cisco TrustSec uses Security Group Tags (SGTs) to classify endpoints and enforce policy based on identity rather than IP address. Community consensus unanimously selects SGTs as the correct answer.
Some candidates choose VLANs (option C) because VLANs also segment traffic, but VLANs are a legacy Layer 2 mechanism and not the policy feature TrustSec uses for endpoint entitlement.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Security Group Tags (SGTs) are the core policy element in Cisco TrustSec that represent an endpoint's security group or role. Once assigned via authentication or profiling, SGTs are carried in packets (typically in the SGT Exchange Protocol header) and used to build Security Group Access Control Lists (SGACLs) on enforcement devices. This enables identity- and role-based access enforcement independent of IP addressing or topology.Why the Other Options Are Wrong
Access Control Lists (ACLs) enforce rules but are not the TrustSec-specific policy feature for endpoint entitlement; SGACLs are the TrustSec variant that references SGTs. VLANs provide broadcast-domain segmentation but do not convey endpoint identity or role across the network. Virtual Routing and Forwarding (VRF) is a routing-instance technology unrelated to endpoint classification or TrustSec policy enforcement.Community Comment Notes
Top-voted comments confirm that TrustSec dynamically assigns and enforces access policies based on the SGT attached to each endpoint. One comment incorrectly suggests VLANs, but the overwhelming consensus and Cisco documentation align with SGTs as the defining TrustSec policy feature.Official Reference
- https://www.cisco.com/c/en/us/products/security/trustsec/index.html
- https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus9000/sw/9-x/security/configuration/guide/b_Cisco_Nexus_9000_Series_NX-OS_Security_Configuration_Guide/b_Cisco_Nexus_9000_Series_NX-OS_Security_Configuration_Guide_chapter_011.html
Exam Strategy
When a question mentions TrustSec and endpoint entitlement, immediately look for Security Group Tags. Eliminate IP-centric or topology-centric options like ACLs, VLANs, and VRFs, which do not carry identity metadata in the TrustSec framework.
Related Analysis
Practice All 350-401 Questions
Access 218 questions with complete answers and detailed explanations.
View Full 350-401 Practice Test →