nerdexam
Cisco

500-651 · Question #65

Which TrustSec feature allows customers to simplify firewall administration, avoiding the common rule explosions that happen when new servers

The correct answer is C. Traffic tagging. Traffic tagging (SGT - Security Group Tags) is the TrustSec feature that prevents firewall rule explosions. Instead of writing rules based on individual IP addresses, TrustSec tags traffic at the source with a group identity (e.g., "Finance" or "Web-Servers"). Firewalls then…

Network Security

Question

Which TrustSec feature allows customers to simplify firewall administration, avoiding the common rule explosions that happen when new servers

Options

  • AFirewall administration
  • BPush policies
  • CTraffic tagging
  • DRegulate access

How the community answered

(18 responses)
  • A
    17% (3)
  • B
    6% (1)
  • C
    72% (13)
  • D
    6% (1)

Explanation

Traffic tagging (SGT - Security Group Tags) is the TrustSec feature that prevents firewall rule explosions. Instead of writing rules based on individual IP addresses, TrustSec tags traffic at the source with a group identity (e.g., "Finance" or "Web-Servers"). Firewalls then enforce policies based on these tags, so when a new server is added to a group, it inherits existing policies automatically - no new rules needed.

Why the distractors are wrong:

  • A (Firewall administration) - This describes the problem being solved, not a TrustSec feature.
  • B (Push policies) - TrustSec does propagate policies, but "push policies" isn't the mechanism that eliminates IP-based rule sprawl; that's a side effect of tagging.
  • D (Regulate access) - A generic description of access control, not a specific TrustSec capability.

Memory tip: Think of SGT traffic tagging like airport security badges - rather than listing every employee's name at every door, you just check their badge color (tag). New employees get a badge, and all existing doors automatically apply to them.

Topics

#TrustSec#Traffic tagging#Firewall rules#Policy simplification

Community Discussion

No community discussion yet for this question.

Full 500-651 Practice