700-765 · Question #65
Which TrustSec feature allows customers to simplify firewall administration, avoiding the common rule explosions that happen when new servers
The correct answer is C. Traffic tagging. Cisco TrustSec uses Security Group Tags (SGTs) to tag traffic, allowing firewall policies to reference tags instead of IP addresses and preventing rule explosions as infrastructure scales.
Question
Which TrustSec feature allows customers to simplify firewall administration, avoiding the common rule explosions that happen when new servers
Options
- AFirewall administration
- BPush policies
- CTraffic tagging
- DRegulate access
How the community answered
(36 responses)- A3% (1)
- C92% (33)
- D6% (2)
Why each option
Cisco TrustSec uses Security Group Tags (SGTs) to tag traffic, allowing firewall policies to reference tags instead of IP addresses and preventing rule explosions as infrastructure scales.
Firewall administration describes the problem TrustSec solves, not a TrustSec feature itself.
Push policies is not a defined TrustSec feature that directly addresses IP-based rule proliferation.
Traffic tagging is the core TrustSec mechanism where SGTs are assigned to users and devices and embedded in network traffic. Firewalls can then enforce policy based on tag values rather than IP addresses, meaning that adding new servers does not require new firewall rules - only tag assignments change, not the policy ruleset itself.
Regulate access is a generic outcome of many security technologies, not a specific TrustSec capability.
Concept tested: Cisco TrustSec SGT-based policy simplification
Source: https://www.cisco.com/c/en/us/solutions/enterprise-networks/trustsec/index.html
Topics
Community Discussion
No community discussion yet for this question.