300-715 · Question #300
A security engineer has a new TrustSec projct and must create a few static security group tag classifications as proof of concept. Which two classifications must the engineer configure? (Choose two.)
The correct answer is B. MAC address C. VLAN. For a TrustSec proof of concept requiring static Security Group Tag (SGT) classifications, the engineer needs to configure MAC address and VLAN based classifications.
Question
A security engineer has a new TrustSec projct and must create a few static security group tag classifications as proof of concept. Which two classifications must the engineer configure? (Choose two.)
Options
- Aswitch ID
- BMAC address
- CVLAN
- Duser ID
- Einterface
How the community answered
(41 responses)- B95% (39)
- D2% (1)
- E2% (1)
Why each option
For a TrustSec proof of concept requiring static Security Group Tag (SGT) classifications, the engineer needs to configure MAC address and VLAN based classifications.
Switch ID is used for identifying the network device itself, not for classifying endpoints with SGTs.
MAC address-based static SGT classification assigns an SGT to endpoints based on their specific MAC address, which is a common and effective method for statically classifying individual devices.
VLAN-based static SGT classification assigns an SGT to all endpoints within a particular VLAN, providing a straightforward way to group devices for security policy enforcement without dynamic authentication.
User ID is typically used for dynamic SGT assignment based on user authentication, not for static classification.
Interface-based classification is often dynamic or part of access policy configuration, but MAC and VLAN are more direct for static SGT assignments.
Concept tested: TrustSec static SGT classification methods
Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/trustsec/configuration/guide/trustsec/concepts.html#concept_D5154316D72A4A7697B703F934177F0C
Topics
Community Discussion
No community discussion yet for this question.