https://community.cisco.com/t5/security-knowledge-base/segmentation-policy-using-sgt-in-pbr-pdf/ta-p/3651240?attachment-id=155316
PBR and Firewall can allocate SGT and then segment the traffic
it's a very very strange question!! if for "mutilayer segmentation" they mean microsgmentation inside a VLAN, thinking about Trustsec model, I think the answers are data plane marking (SGT) and filter list (permit/deny matrix). The other options (PBR, firewall, segment routing) seem to be related more to routing than to segmentation...
I'm going to go on a limb and say A&C. that's how you traditionally segment your network. this says the same thing (assuming filter lists = ACLs)
https://www.cisco.com/c/en/us/products/security/what-is-network-segmentation.html
"Some traditional technologies for segmentation included internal firewalls, and Access Control List (ACL) and Virtual Local Area Network (VLAN) configurations on networking equipment."
Guys, B&D looks correct. Segment Routing provides flexibility in defining and managing segments, and can be used in conjunction with VLANs, VRFs, or other data plane markings to create and enforce logical boundaries between different layers or segments of the network. Firewalls can segment but are not multilayer. PBR and filter lists can't be the answer, come on. You expect a CCDE to recommend using PBR everywhere to segment your traffic?
This question has three valid answers. AB (Vanguard Method) and AE (Legacy Method)
Which gives more points?
Please check page 14 of this document.
https://www.cisco.com/c/dam/en/us/solutions/collateral/design-zone/cisco-validated-profiles/secure-dc-design-guide-cvd.pdf
This section is not available anymore. Please use the main Exam Page.400-007 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
pizdecvsemu
Highly Voted 2 years, 2 months agobiddid
2 years, 1 month agoying162
Highly Voted 2 years, 2 months agoLordAndy
Most Recent 1 month agosandccie
2 months, 3 weeks agonoxkrugger
8 months agoSeawanderer
11 months, 2 weeks ago8be7437
11 months, 3 weeks agoTKCA
1 year, 3 months agoRollizo
1 year, 3 months agoAndrew66r
1 year, 10 months agoJamesBlunt
1 year, 10 months agoWuHu
1 year, 11 months agoCastleMagic
1 year, 11 months agobdp123
1 year, 11 months agosmokey98
2 years agogreensheep
2 years agogcpengineer
2 years, 2 months ago