300-415 · Question #378
Which Cisco SD-WAN feature propagates packets with SGTs through the network?
The correct answer is B. TrustSec Inline Tagging. Cisco TrustSec Inline Tagging is the feature responsible for propagating Security Group Tags (SGTs) directly within the packet header as it traverses the network, enabling consistent policy enforcement.
Question
Exhibit
Options
- ASXP
- BTrustSec Inline Tagging
- CQoS
- DSGT Enforcement
How the community answered
(23 responses)- B91% (21)
- C4% (1)
- D4% (1)
Why each option
Cisco TrustSec Inline Tagging is the feature responsible for propagating Security Group Tags (SGTs) directly within the packet header as it traverses the network, enabling consistent policy enforcement.
SXP (Security Group Tag Exchange Protocol) is used to exchange SGT information between network devices, not to propagate SGTs within data packets.
TrustSec Inline Tagging is the specific Cisco SD-WAN (and general Cisco TrustSec) feature that embeds Security Group Tags (SGTs) directly into network packets, typically using an EtherType, as they travel through the network. This allows for consistent identity-based policy enforcement across TrustSec-enabled devices.
QoS (Quality of Service) is used to prioritize network traffic, not to propagate security group tags.
SGT Enforcement refers to the actions taken by devices based on SGTs, not the mechanism by which SGTs are propagated in the packets themselves.
Concept tested: TrustSec SGT propagation mechanism
Source: https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-0/TrustSec_SRND/TrustSec_Tech.html
Topics
Community Discussion
No community discussion yet for this question.
