nerdexam
Cisco

300-320 · Question #607

Which two modes for deploying Cisco TrustSec are valid? (Choose two.)

The correct answer is C. monitor D. low-impact. Cisco TrustSec (used with 802.1X) defines three phased deployment modes. Monitor mode (C) allows all traffic to pass regardless of authentication outcome while logging authentication results - used for initial assessment without impacting users. Low-impact mode (D) applies a…

Security Services

Question

Which two modes for deploying Cisco TrustSec are valid? (Choose two.)

Options

  • Aopen
  • Bhigh availability
  • Cmonitor
  • Dlow-impact
  • Ecascade

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    89% (32)
  • E
    6% (2)

Explanation

Cisco TrustSec (used with 802.1X) defines three phased deployment modes. Monitor mode (C) allows all traffic to pass regardless of authentication outcome while logging authentication results - used for initial assessment without impacting users. Low-impact mode (D) applies a minimal pre-authentication ACL permitting limited traffic (e.g., DHCP, DNS) before authentication, then applies a full downloadable ACL (dACL) after successful authentication - balancing security with accessibility. The third mode is High-Security (Closed) mode, which denies all traffic before authentication. 'Open' (A) is sometimes referenced in 802.1X contexts but is not a standard TrustSec deployment mode. 'High availability' (B) and 'cascade' (E) are not TrustSec deployment modes.

Topics

#TrustSec#network access control#deployment modes#Cisco security

Community Discussion

No community discussion yet for this question.

Full 300-320 Practice