Correct Answer: Consistent SGT classification applied at the point of authentication, SGACLs defined centrally in ISE and distributed to enforcement devices, SXP used where inline tagging is not supported, and a validation/monitoring phase before strict enforcement
Explanation: Consistent classification at authentication, centrally managed SGACLs, SXP for mapping propagation where needed, and a validation phase together provide effective, scalable TrustSec segmentation, unlike manually duplicating IP-based ACLs everywhere, random SGT assignment with no testing, assuming inline tagging works everywhere with no SXP fallback, skipping the monitoring phase, or treating VLAN-based segmentation as equivalent to TrustSec.
Correct Answer: Consistent SGT classification applied at the point of authentication, SGACLs defined centrally in ISE and distributed to enforcement devices, SXP used where inline tagging is not supported, and a validation/monitoring phase before strict enforcement
Explanation: Consistent classification at authentication, centrally managed SGACLs, SXP for mapping propagation where needed, and a validation phase together provide effective, scalable TrustSec segmentation, unlike manually duplicating IP-based ACLs everywhere, random SGT assignment with no testing, assuming inline tagging works everywhere with no SXP fallback, skipping the monitoring phase, or treating VLAN-based segmentation as equivalent to TrustSec.