Which two SGT propagation methods does Cisco TrustSec support? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: SXP, inline tagging.
Why this is the answer
Cisco TrustSec supports two primary SGT propagation methods: SXP (Security Group Tag Exchange Protocol) and inline tagging. SXP is a control plane protocol used to propagate SGTs between network devices that do not directly support inline tagging, such as legacy devices or Layer 2 switches. It maps IP addresses to SGTs and shares this information. Inline tagging, on the other hand, is a data plane method where the SGT is directly embedded into the packet header (e.g., in the Cisco MetaData field for Ethernet frames or as a shim header for IP packets) as it traverses TrustSec-enabled devices. This allows devices to enforce policies based on the SGT without needing a separate protocol exchange. Key chain and reconciliation are not SGT propagation methods. Offline tagging is not a standard TrustSec propagation method.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed