Correct Answer: ISE as the centralized policy server defining SGTs and SGACLs, inline tagging on TrustSec-capable devices, and SXP mapping to extend SGT association to legacy devices that cannot tag natively
Explanation: Consistent TrustSec segmentation across mixed hardware combines a centralized policy server (ISE), inline tagging where supported, and SXP for legacy devices, unlike relying on inline tagging alone, SXP alone, a policy server with no enforcement mechanism, plain VLAN-based segmentation with no SGT concept, or fully manual per-switch ACLs with no coordination.
Correct Answer: ISE as the centralized policy server defining SGTs and SGACLs, inline tagging on TrustSec-capable devices, and SXP mapping to extend SGT association to legacy devices that cannot tag natively
Explanation: Consistent TrustSec segmentation across mixed hardware combines a centralized policy server (ISE), inline tagging where supported, and SXP for legacy devices, unlike relying on inline tagging alone, SXP alone, a policy server with no enforcement mechanism, plain VLAN-based segmentation with no SGT concept, or fully manual per-switch ACLs with no coordination.