nerdexam
Palo_Alto_Networks

PCNSE · Question #629

A network security engineer needs to enable Zone Protection in an environment that makes use of Cisco TrustSec Layer 2 protections. What should the engineer configure within a Zone Protection…

The correct answer is C. Ethernet SGT Protection. Cisco TrustSec embeds Security Group Tags (SGTs) directly into Ethernet frames to carry identity and policy metadata at Layer 2. PAN-OS Zone Protection profiles include an 'Ethernet SGT Protection' option specifically designed to identify SGT-tagged Ethernet frames and apply…

Submitted by anjalisingh· Apr 18, 2026Deploy and Configure

Question

A network security engineer needs to enable Zone Protection in an environment that makes use of Cisco TrustSec Layer 2 protections. What should the engineer configure within a Zone Protection profile to ensure that the TrustSec packets are identified and actions are taken upon them?

Options

  • AStream ID in the IP Option Drop options
  • BRecord Route in IP Option Drop options
  • CEthernet SGT Protection
  • DTCP Fast Open in the Strip TCP options

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    71% (17)
  • D
    17% (4)

Explanation

Cisco TrustSec embeds Security Group Tags (SGTs) directly into Ethernet frames to carry identity and policy metadata at Layer 2. PAN-OS Zone Protection profiles include an 'Ethernet SGT Protection' option specifically designed to identify SGT-tagged Ethernet frames and apply configured actions to them. The IP Option Drop and TCP Strip settings address different protocol fields (Layer 3/4 headers) and have no awareness of TrustSec SGT fields in the Ethernet header.

Topics

#Zone Protection Profiles#Cisco TrustSec#SGT Protection#Layer 2 Security

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice