nerdexam
Cisco

700-765 · Question #65

Which TrustSec feature allows customers to simplify firewall administration, avoiding the common rule explosions that happen when new servers

The correct answer is C. Traffic tagging. Cisco TrustSec uses Security Group Tags (SGTs) to tag traffic, allowing firewall policies to reference tags instead of IP addresses and preventing rule explosions as infrastructure scales.

Cisco Security Product Solutions

Question

Which TrustSec feature allows customers to simplify firewall administration, avoiding the common rule explosions that happen when new servers

Options

  • AFirewall administration
  • BPush policies
  • CTraffic tagging
  • DRegulate access

How the community answered

(36 responses)
  • A
    3% (1)
  • C
    92% (33)
  • D
    6% (2)

Why each option

Cisco TrustSec uses Security Group Tags (SGTs) to tag traffic, allowing firewall policies to reference tags instead of IP addresses and preventing rule explosions as infrastructure scales.

AFirewall administration

Firewall administration describes the problem TrustSec solves, not a TrustSec feature itself.

BPush policies

Push policies is not a defined TrustSec feature that directly addresses IP-based rule proliferation.

CTraffic taggingCorrect

Traffic tagging is the core TrustSec mechanism where SGTs are assigned to users and devices and embedded in network traffic. Firewalls can then enforce policy based on tag values rather than IP addresses, meaning that adding new servers does not require new firewall rules - only tag assignments change, not the policy ruleset itself.

DRegulate access

Regulate access is a generic outcome of many security technologies, not a specific TrustSec capability.

Concept tested: Cisco TrustSec SGT-based policy simplification

Source: https://www.cisco.com/c/en/us/solutions/enterprise-networks/trustsec/index.html

Topics

#TrustSec#traffic tagging#SGT#firewall administration

Community Discussion

No community discussion yet for this question.

Full 700-765 Practice