HPE7-A08 · Question #144
Drag and Drop Question Match each Group Based Policy (GBP) role description to its respective role ID. Answer:
The correct answer is GBP role ID = 0; GBP role ID = 2; GBP role ID = <100-8191>. Group Based Policy (GBP) Role IDs - Explanation The question asks you to match role descriptions to their corresponding GBP role IDs. The descriptions are implied by standard Cisco TrustSec/SD-Access GBP conventions. Here's what each ID means and why the arrangement is correct…
Question
Drag and Drop Question Match each Group Based Policy (GBP) role description to its respective role ID. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- GBP role ID = 0
- GBP role ID = 2
- GBP role ID = <100-8191>
Explanation
Group Based Policy (GBP) Role IDs - Explanation
The question asks you to match role descriptions to their corresponding GBP role IDs. The descriptions are implied by standard Cisco TrustSec/SD-Access GBP conventions. Here's what each ID means and why the arrangement is correct.
Position 1 → GBP Role ID = 0 (Unknown / Unclassified)
What it is: The reserved ID for unknown or unclassified traffic - traffic that has not been assigned to any security group.
Why it's ID 0: Zero is universally the "null" or default value. Any endpoint that hasn't been authenticated or classified falls into this group automatically. It's the baseline catch-all.
Common misconception: Students sometimes think ID 0 means "no policy applies." It still has policy applied - it just uses the default/unknown group policy, which is typically the most restrictive.
Position 2 → GBP Role ID = 2 (Network Devices / TrustSec Infrastructure)
What it is: Reserved for TrustSec-capable network infrastructure devices (switches, routers, WLCs) that are part of the policy domain.
Why it's ID 2: Cisco reserves IDs 1–15 for system use. ID 2 specifically designates trusted network devices so that device-to-device traffic can be handled with elevated trust without user-defined policy interference.
Common misconception: Students confuse this with "admin users." ID 2 is for devices, not human administrators.
Position 3 → GBP Role ID = <100–8191> (User-Defined Security Groups)
What it is: The range available to administrators to create custom security group tags (SGTs) - e.g., Employees, Contractors, Guests, PCI Servers, IoT Devices.
Why this range: IDs 0–99 are reserved by Cisco for system/infrastructure use. The 100–8191 range is the safe, user-configurable space.
Common misconception: Students sometimes try to assign low-numbered IDs (like 5 or 10) to custom groups, not realizing those are reserved and can conflict with Cisco system groups.
Summary Table
| Position | Role ID | Represents |
|---|---|---|
| 1 | 0 | Unknown / Unclassified traffic |
| 2 | 2 | TrustSec network infrastructure devices |
| 3 | 100–8191 | Administrator-defined custom groups |
Key rule to remember: Reserved IDs (0–99) are Cisco-controlled; user-defined groups always start at 100.
Topics
Community Discussion
No community discussion yet for this question.
