exam questions

Exam 300-715 All Questions

View all questions & answers for the 300-715 exam

Exam 300-715 topic 1 question 199 discussion

Actual exam question from Cisco's 300-715
Question #: 199
Topic #: 1
[All 300-715 Questions]

An engineer is configuring static SGT classification. Which configuration should be used when authentication is disabled and third-party switches are in use?

  • A. VLAN to SGT mapping
  • B. IP Address to SGT mapping
  • C. L3IF to SGT mapping
  • D. Subnet to SGT mapping
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Frankie_Boy
Highly Voted 1 year, 9 months ago
B: IP-SGT: https://community.cisco.com/t5/security-knowledge-base/segmentation-strategy/ta-p/3757424: "The method of sending out IP to SGT mappings from ISE is particularly useful if the access switch does not support TrustSec"
upvoted 9 times
...
Cachaman
Most Recent 1 month, 1 week ago
Selected Answer: A
Overview of VLAN-to-SGT Mapping The VLAN-to-SGT mapping feature binds an SGT to packets from a specified VLAN. This simplifies the migration from legacy to Cisco TrustSec-capable networks as follows: Supports devices that are not Cisco TrustSec-capable but are VLAN-capable, such as, legacy switches, wireless controllers, access points, VPNs, etc. The VLAN-to-SGT binding is configured with the cts role-based sgt-map vlan-list global configuration command. https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9400/software/release/16-10/configuration_guide/cts/b_1610_cts_9400_cg/m9-1610-trustsec-sgt.html
upvoted 1 times
...
kerimeba
8 months, 1 week ago
Security Group Tag (SGT)—TrustSec service assigns to each security group a unique 16-bit security group number whose scope is global within a TrustSec domain. The number of security groups in the Segmentation TrustSec Components switch is limited to the number of authenticated network entities. You do not have to manually configure security group numbers. They are automatically generated, but you have the option to reserve a range of SGTs for IP-to-SGT mapping.
upvoted 1 times
...
XBfoundX
10 months, 2 weeks ago
It can be B but cause authentication is disabled the right answer is A When users authenticate onto the network, ISE learns of the user IP and assigns an SGT via the authorization table. So, ISE is the first platform in the network which learns of the IP to SGT mapping for dynamically authenticated endpoints. The method of sending out IP to SGT mappings from ISE is particularly useful if the access switch does not support TrustSec. CAUSED HERE AUTHENTICATION IS NOT ENABLED WE NEED TO USE THE VLAN TO SGT MAPPING
upvoted 3 times
XBfoundX
10 months, 2 weeks ago
Overview of VLAN-to-SGT Mapping The VLAN-to-SGT mapping feature binds an SGT to packets from a specified VLAN. This simplifies the migration from legacy to Cisco TrustSec-capable networks as follows: Supports devices that are not Cisco TrustSec-capable but are VLAN-capable, such as, legacy switches, wireless controllers, access points, VPNs, etc. Provides backward compatibility for topologies where VLANs and VLAN ACLs segment the network, such as, server segmentation in data centers.
upvoted 1 times
...
...
IETF1
12 months ago
B: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9400/software/release/16-10/configuration_guide/cts/b_1610_cts_9400_cg/m9-1610-trustsec-sgt.html
upvoted 1 times
...
faridh
1 year, 2 months ago
Selected Answer: A
Hosts in a specific VLAN can be mapped to a specific static SGT. This method can be used when there are third-party switches or Cisco switches that do not support TrustSec. ciscopress page 576
upvoted 2 times
...
ElCobra90
1 year, 3 months ago
Selected Answer: A
A should be the correct answer, if i remember well, you configure vlan to sgt, then vlan to sgt mapping the ip, but methos used is vlan-to-sgt
upvoted 2 times
...
rhylos
1 year, 5 months ago
Selected Answer: B
The method of sending out IP to SGT mappings from ISE is particularly useful if the access switch does not support TrustSec.
upvoted 3 times
...
denverfly
1 year, 5 months ago
Selected Answer: A
The other options are not as feasible because: IP Address to SGT mapping is not supported by all switches. L3IF to SGT mapping requires layer-3 switching, which is not supported by all switches. Subnet to SGT mapping requires that the switch be able to perform subnetting, which is not supported by all switches. VLAN to SGT mapping is the most reliable and efficient way to implement static SGT classification when authentication is disabled and third-party switches are in use.
upvoted 2 times
...
Cnoteone
1 year, 7 months ago
Selected Answer: B
As per Frankie_boy
upvoted 1 times
...
Cnoteone
1 year, 8 months ago
If the answer is B, does this apply to non Cisco L2 switches?
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago