Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessEasy

A security administrator is configuring a new Cisco Router to enforce secure network access policies. The administrator needs to ensure that only authenticated users from specific departments can access the internal network segments. Which feature, when configured on the router, allows for dynamic policy assignment based on user identity and group membership, rather than static IP addresses or VLANs?

  1. AVirtual Routing and Forwarding (VRF)
  2. BAccess Control Lists (ACLs)
  3. CNetwork Address Translation (NAT)
  4. DSecurity Group Tagging (SGT)
Show answer & explanation

Correct answer: D. Security Group Tagging (SGT)

Security Group Tagging (SGT) allows for identity-based access control where policies are enforced based on the security group an endpoint or user belongs to, rather than static network attributes. This enables dynamic policy assignment and simplifies management in complex environments.

Why the other options are wrong

  • A. VRF creates multiple independent routing tables on a single router, segmenting traffic but not directly enforcing identity-based access control.
  • B. ACLs provide static packet filtering based on IP addresses, ports, and protocols, not dynamic identity-based policies.
  • C. NAT translates IP addresses, primarily for conserving public IP addresses or hiding internal network structures, and does not provide access control based on identity.

Security Group Tagging (SGT)

A technology used in Cisco TrustSec to classify network traffic based on the identity of the user or device, rather than IP address, allowing for dynamic, identity-based access control policies.

  • Enables micro-segmentation.
  • Simplifies policy management.
  • Part of Cisco TrustSec architecture.

Memory trick: Tag your users, not just their IPs, for dynamic access.

More Endpoint Security and Secure Network Access questions