300-415 Question 232
Single answerAn enterprise network is implementing Cisco SD-WAN with TrustSec to enhance security by segmenting traffic based on Security Group Tags (SGTs). The administrator needs to ensure that security policies based on SGTs are enforced across the SD-WAN fabric. Which critical step must the administrator take to enable TrustSec in this scenario?
- A
Configure SGT propagation in the SD-WAN control policies.
- B
Enable TrustSec enforcement on the WAN Edge devices.
- C
Deploy Cisco Identity Services Engine (ISE) to assign SGTs.
- D
Apply SGTs to specific VPNs on the SD-WAN fabric.
Show answer and explanation
Correct answer: C
Explanation
Cisco TrustSec relies on Security Group Tags (SGTs) to enforce segmentation policies across the network. In an SD-WAN environment, SGTs are dynamically assigned by Cisco Identity Services Engine (ISE) based on user or device identity. Without ISE, SGTs cannot be effectively assigned or propagated, making it a prerequisite for implementing TrustSec in the SD-WAN fabric.
- A. Incorrect.
SGT propagation is necessary for TrustSec, but it is handled by underlying protocols like CTS (Cisco TrustSec) and not directly configured in SD-WAN control policies.
- B. Incorrect.
TrustSec enforcement is crucial, but enabling it on WAN Edge devices alone does not assign or propagate SGTs.
- C. Correct.
Cisco Identity Services Engine (ISE) is required to dynamically assign and manage SGTs based on user or device identity, making it a critical step for implementing TrustSec in the SD-WAN fabric.
- D. Incorrect.
Applying SGTs to specific VPNs on the SD-WAN fabric is part of policy enforcement but depends on the initial assignment and propagation of SGTs, which requires Cisco ISE.