Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium
A security team is implementing a network segmentation strategy using Cisco TrustSec. The goal is to classify users and devices into logical groups and apply security policies based on these groups, rather than IP addresses or VLANs. Which key component of Cisco TrustSec is responsible for assigning a Security Group Tag (SGT) to each authenticated user or device?
- APolicy Enforcement Point (PEP)
- BSecurity Group Access (SGA) Fabric
- CIdentity Services Engine (ISE)
- DTrustSec-enabled Network Device
Show answer & explanationAnswer & explanation
Correct answer: C. Identity Services Engine (ISE)
Cisco Identity Services Engine (ISE) is the central policy engine for Cisco TrustSec. It authenticates users and devices, assesses their posture, and then assigns the appropriate Security Group Tag (SGT) based on configured policies.
Why the other options are wrong
- A. PEP (e.g., a switch) enforces the policy based on SGTs, but ISE assigns the SGT.
- B. SGA Fabric refers to the overall network infrastructure that supports TrustSec, not a component that assigns SGTs.
- D. TrustSec-enabled network devices (e.g., switches, routers) enforce policies based on SGTs, but ISE assigns them.
Cisco TrustSec
A security framework that uses identity and context to classify network traffic into Security Group Tags (SGTs) and enforce policy based on these tags.
- Decouples security policy from network topology.
- Uses Security Group Tags (SGTs) for group-based access control.
- Cisco ISE is the central policy and SGT assignment engine.
Memory trick: ISE is the 'bouncer' that hands out the 'VIP tags' (SGTs).