Which policy feature is used with TrustSec to provide endpoint entitlement?
Choose an answer
Tap an option to check your answer.
Correct answer: Security group tags.
Why this is the answer
Security Group Tags (SGTs) are a core component of Cisco TrustSec, used to classify and label network traffic based on the source endpoint's identity. This classification allows for identity-based access control, where policies are applied to SGTs rather than IP addresses, providing endpoint entitlement. When an endpoint authenticates, it's assigned an SGT, and network devices enforce policies based on these tags. Access Control Lists (ACLs) are IP-based and less scalable for identity-based policies. Virtual Local Area Networks (VLANs) segment broadcast domains but don't provide identity-based access control. Virtual Routing and Forwarding (VRF) creates separate routing tables, primarily for network virtualization, not endpoint entitlement.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed