nerdexam
Cisco

500-651 · Question #80

Which feature of Cisco ISE uses Cisco TrustSec Security Group Tags 10 edit networks dynamically rather than with VLANs?

The correct answer is B. Role and device segmentation. Role and device segmentation (B) is correct because Cisco ISE leverages TrustSec Security Group Tags (SGTs) to enforce policy-based access control by tagging traffic with a user/device role, allowing network segmentation to be defined by identity rather than by physical VLAN…

Network Security

Question

Which feature of Cisco ISE uses Cisco TrustSec Security Group Tags 10 edit networks dynamically rather than with VLANs?

Options

  • ADevice profiting and onboarding
  • BRole and device segmentation
  • CGuest Access
  • DSecure remote access

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    83% (20)
  • C
    4% (1)
  • D
    4% (1)

Explanation

Role and device segmentation (B) is correct because Cisco ISE leverages TrustSec Security Group Tags (SGTs) to enforce policy-based access control by tagging traffic with a user/device role, allowing network segmentation to be defined by identity rather than by physical VLAN topology - this is the core function of role and device segmentation.

Device profiling and onboarding (A) is about identifying and classifying devices when they connect to the network, not about dynamic segmentation via SGTs.

Guest Access (C) manages temporary, limited network access for visitors - typically using portals and VLANs/ACLs, not SGT-based dynamic segmentation.

Secure remote access (D) covers VPN and remote connectivity policies, which is outside the scope of TrustSec's internal network segmentation model.

Memory tip: Think "SGT = Segment by Group Tag" - the word group maps directly to role, so whenever you see SGTs, think role-based segmentation, not onboarding, guests, or remote access.

Topics

#Cisco ISE#TrustSec#Security Group Tags#Network Segmentation

Community Discussion

No community discussion yet for this question.

Full 500-651 Practice