CCNP Security 300-715 SISE Practice Test 9

CCNP Security 300-715 SISE Practice Test 9 (Hard) - Configuring Cisco TrustSec

CISCO CCNP Security Exam Logo

1 / 10

Which Cisco TrustSec concept assigns a tag representing a device or user's security classification, which can then be used for policy enforcement independent of IP address or VLAN?

2 / 10

Which Cisco ISE role does the Policy Administration Node typically play in a TrustSec deployment regarding the distribution of SGT and security group ACL (SGACL) policy information to network devices?

3 / 10

Which enforcement mechanism uses SGTs on both the source and destination of traffic to determine whether that traffic should be permitted or denied, independent of the underlying IP addressing?

4 / 10

Which network element is responsible for tagging traffic with the appropriate SGT as it enters a TrustSec-enabled network, based on the result of authentication and authorization?

5 / 10

Which mechanism allows an SGT to be propagated between TrustSec-capable network devices when the underlying data-plane hardware supports inline tagging?

6 / 10

Which alternative propagation mechanism can be used to communicate SGT-to-IP-address mapping information between devices when inline tagging is not supported end to end?

7 / 10

Which business benefit does TrustSec-based segmentation using SGTs and SGACLs provide compared to relying solely on traditional VLAN- and IP-based segmentation?

8 / 10

Which planning step is important before deploying SGACLs widely across a TrustSec-enabled network to avoid unintentionally blocking legitimate business traffic?

9 / 10

Which scenario illustrates an appropriate practical use of TrustSec SGACLs in a segmented enterprise network?

10 / 10

Which combination of TrustSec design elements would provide effective, scalable segmentation for a large enterprise migrating away from complex VLAN-based ACLs?

Your score is

The average score is 0%

0%