Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CCIE Security

Domain 2Objective 6

2.6 Microsegmentation with Cisco TrustSec Using SFT and SXP CCIE-SECURITY Practice Questions (Page 10)

Part of the 2.0 Secure Connectivity and Segmentation domain, which accounts for 20% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 2–3 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)

56questions here
12free pages
11concepts
20%of the exam

Questions 46–50

  1. 46expert · hard

    A large enterprise is designing a TrustSec deployment with a mix of SFT-capable and legacy devices. They want to ensure that SGACLs are enforced consistently, but they are concerned about the scalability of SXP in the core. Which design approach best balances scalability and consistency?

    Select an answer first
  2. 47expert · hard

    A network engineer is troubleshooting a TrustSec issue where a user is able to access a resource that should be denied by SGACL. The user's traffic is being forwarded through an SFT-capable switch, and the SGT is correctly embedded. The SGACL is downloaded from ISE. Which command should the engineer use to verify that the correct SGACL is being enforced on the switch?

    Select an answer first
  3. 48expert · hard

    A network architect is designing a TrustSec deployment for a high-performance data center. They want to enforce microsegmentation between virtual machines (VMs) on the same physical host. The hypervisor supports SFT. What is the best way to enforce SGACLs for VM-to-VM traffic?

    Select an answer first
  4. 49application · medium

    A university has a mixed network with Cisco TrustSec-capable switches in the new building, but older legacy switches in the administrative building that do not support inline SGT tagging. The security team wants to enforce group-based policies for users in both buildings. What should they implement to propagate SGT information to the legacy switches?

    Select an answer first
  5. 50application · medium

    A healthcare organization is implementing TrustSec to enforce microsegmentation between its electronic health record (EHR) system and other internal networks. They have defined security group tags (SGTs) for different user roles and want to enforce access control based on these tags. Which component is responsible for defining the actual permissions between SGTs?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.