700-765 · Question #80
Which feature of Cisco ISE uses Cisco TrustSec Security Group Tags 10 edit networks dynamically rather than with VLANs?
The correct answer is B. Role and device segmentation. Cisco ISE uses TrustSec Security Group Tags (SGTs) in its role and device segmentation feature to enforce access policies dynamically based on user or device role, eliminating the need for static VLAN-based segmentation.
Question
Which feature of Cisco ISE uses Cisco TrustSec Security Group Tags 10 edit networks dynamically rather than with VLANs?
Options
- ADevice profiting and onboarding
- BRole and device segmentation
- CGuest Access
- DSecure remote access
How the community answered
(20 responses)- A5% (1)
- B70% (14)
- C20% (4)
- D5% (1)
Why each option
Cisco ISE uses TrustSec Security Group Tags (SGTs) in its role and device segmentation feature to enforce access policies dynamically based on user or device role, eliminating the need for static VLAN-based segmentation.
Device profiling and onboarding identifies and classifies devices connecting to the network but does not use SGTs to replace VLAN-based segmentation.
Role and device segmentation in Cisco ISE leverages TrustSec SGTs to tag traffic at ingress and enforce group-based policies throughout the network. This allows segmentation to follow the user or device identity dynamically rather than relying on fixed VLAN boundaries, making policy changes network-wide without reconfiguring VLANs.
Guest Access provides limited network access to unauthenticated or visitor users and is not the ISE feature associated with TrustSec SGT-based dynamic segmentation.
Secure remote access governs VPN and remote connectivity policies and does not use TrustSec SGTs to dynamically segment internal network traffic in place of VLANs.
Concept tested: Cisco ISE TrustSec SGT-based dynamic segmentation
Source: https://www.cisco.com/c/en/us/products/security/identity-services-engine/index.html
Topics
Community Discussion
No community discussion yet for this question.