CCNP Security 350-701 SCOR Practice Test 28

CCNP Security 350-701 SCOR Practice Test 28 (Hard) - Cisco TrustSec and Security Group Tags (SGTs)

CISCO CCNP Security Exam Logo

1 / 10

Which Cisco TrustSec concept assigns a tag to traffic based on the identity and context of the source, rather than its IP address, allowing policy enforcement independent of network topology?

2 / 10

Which core benefit does TrustSec's SGT-based segmentation provide compared to traditional VLAN- and subnet-based segmentation for enforcing policy between groups of users?

3 / 10

Which TrustSec component defines the actual permit/deny rules governing what traffic is allowed between a given source SGT and destination SGT?

4 / 10

Which TrustSec mechanism carries the SGT value alongside a data frame as it traverses TrustSec-capable network devices, allowing downstream devices to enforce policy based on that tag?

5 / 10

Which mechanism allows a device that cannot directly tag traffic with an SGT (such as a legacy switch) to still have its traffic associated with the correct SGT based on other identifying information, such as IP address?

6 / 10

Which centralized component typically defines and distributes the SGACL policy matrix to TrustSec-enabled enforcement devices across the network?

7 / 10

Which scenario best illustrates a practical use case for TrustSec SGT-based segmentation in an enterprise network?

8 / 10

Which advantage does TrustSec segmentation provide during a network merger or reorganization where IP addressing schemes from two previously separate networks must be integrated?

9 / 10

Which TrustSec deployment consideration would most directly affect whether inline SGT tagging can be used end-to-end across a given network path, versus requiring SXP mapping as a workaround?

10 / 10

Which combination of TrustSec components together enables consistent, identity-based segmentation policy across a large enterprise network with a mix of modern and legacy switching hardware?

Your score is

The average score is 0%

0%