300-320 · Question #505
Which two options regarding the Cisco TrustSec Security Group Tag are true? (Choose Two.)
The correct answer is A. It is assigned by the Cisco ISE to the user or endpoint session upon login E. Best Practice dictates that deployments should include a security group for common services. Cisco TrustSec SGTs (Security Group Tags) are 16-bit values used to classify traffic based on identity and policy. (A) is correct: ISE dynamically assigns an SGT to a user or endpoint at authentication time, binding the tag to that session. This dynamic assignment is the core…
Question
Which two options regarding the Cisco TrustSec Security Group Tag are true? (Choose Two.)
Options
- AIt is assigned by the Cisco ISE to the user or endpoint session upon login
- BBest practice dictates it should be statically created on the switch
- CIt is removed by the Cisco ISE before reaching the endpoint.
- DBest Practice dictates that deployments should include a guest group allowing access to minimal
- EBest Practice dictates that deployments should include a security group for common services
How the community answered
(47 responses)- A89% (42)
- B6% (3)
- C2% (1)
- D2% (1)
Explanation
Cisco TrustSec SGTs (Security Group Tags) are 16-bit values used to classify traffic based on identity and policy. (A) is correct: ISE dynamically assigns an SGT to a user or endpoint at authentication time, binding the tag to that session. This dynamic assignment is the core TrustSec model. (E) is correct: Cisco best practice recommends defining a dedicated security group for common/shared services (DNS, DHCP, NTP, etc.) to simplify policy creation and ensure all user groups can reach shared infrastructure. Static switch-based assignment (B) is not best practice - dynamic ISE assignment is preferred. SGTs are not removed by ISE before reaching the endpoint (C) - they travel with traffic headers through the network.
Topics
Community Discussion
No community discussion yet for this question.