nerdexam
Cisco

300-715 · Question #248

An engineer is configuring static SGT classification. Which configuration should be used when authentication is disabled and third-party switches are in use?

The correct answer is B. IP Address to SGT mapping. When authentication is disabled (no 802.1X or MAB) and third-party (non-Cisco TrustSec-capable) switches are in use, IP Address to SGT mapping is the correct static SGT classification method. VLAN-to-SGT and L3IF-to-SGT mappings require TrustSec-capable Cisco switches that can…

Policy Enforcement

Question

An engineer is configuring static SGT classification. Which configuration should be used when authentication is disabled and third-party switches are in use?

Options

  • AVLAN to SGT mapping
  • BIP Address to SGT mapping
  • CL3IF to SGT mapping
  • DSubnet to SGT mapping

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    85% (29)
  • C
    9% (3)
  • D
    3% (1)

Explanation

When authentication is disabled (no 802.1X or MAB) and third-party (non-Cisco TrustSec-capable) switches are in use, IP Address to SGT mapping is the correct static SGT classification method. VLAN-to-SGT and L3IF-to-SGT mappings require TrustSec-capable Cisco switches that can enforce inline tagging. Subnet-to-SGT is a broader form of IP mapping but IP Address-to-SGT is the specific per-host static method that works independently of authentication state and switch TrustSec capability, making it the only viable option in this environment.

Topics

#SGT Classification#IP-SGT Mapping#Static SGT#TrustSec

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice