PCNSE · Question #629
A network security engineer needs to enable Zone Protection in an environment that makes use of Cisco TrustSec Layer 2 protections. What should the engineer configure within a Zone Protection…
The correct answer is C. Ethernet SGT Protection. Cisco TrustSec embeds Security Group Tags (SGTs) directly into Ethernet frames to carry identity and policy metadata at Layer 2. PAN-OS Zone Protection profiles include an 'Ethernet SGT Protection' option specifically designed to identify SGT-tagged Ethernet frames and apply…
Question
A network security engineer needs to enable Zone Protection in an environment that makes use of Cisco TrustSec Layer 2 protections. What should the engineer configure within a Zone Protection profile to ensure that the TrustSec packets are identified and actions are taken upon them?
Options
- AStream ID in the IP Option Drop options
- BRecord Route in IP Option Drop options
- CEthernet SGT Protection
- DTCP Fast Open in the Strip TCP options
How the community answered
(24 responses)- A8% (2)
- B4% (1)
- C71% (17)
- D17% (4)
Explanation
Cisco TrustSec embeds Security Group Tags (SGTs) directly into Ethernet frames to carry identity and policy metadata at Layer 2. PAN-OS Zone Protection profiles include an 'Ethernet SGT Protection' option specifically designed to identify SGT-tagged Ethernet frames and apply configured actions to them. The IP Option Drop and TCP Strip settings address different protocol fields (Layer 3/4 headers) and have no awareness of TrustSec SGT fields in the Ethernet header.
Topics
Community Discussion
No community discussion yet for this question.