Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 300-745 Exam - Topic 2 Question 14 Discussion

A global hotel chain is using Cisco ISE and Cisco switches to manage the network. The hotel company wants to enhance network security by segmenting users and endpoints. The company must ensure that devices within the same VLAN cannot communicate with each other. The goal is to prevent cross-communication without the use of dynamic access control lists. Which action must be taken using Cisco ISE to meet the requirement?
D) Configure TrustSec.
A) Implement device posturing.
B) Set up endpoint profiling.
C) Enable identity groups.

Cisco 300-745 Exam - Topic 2 Question 14 Discussion

Actual exam question for Cisco's 300-745 exam
Question #: 14
Topic #: 2
[All 300-745 Questions]

A global hotel chain is using Cisco ISE and Cisco switches to manage the network. The hotel company wants to enhance network security by segmenting users and endpoints. The company must ensure that devices within the same VLAN cannot communicate with each other. The goal is to prevent cross-communication without the use of dynamic access control lists. Which action must be taken using Cisco ISE to meet the requirement?

Show Suggested Answer Hide Answer
Suggested Answer: D

Cisco TrustSec is a next-generation security architecture that provides software-defined segmentation to simplify the provisioning of network access control. In a hotel environment where guest privacy is paramount, TrustSec is the ideal solution to prevent 'peer-to-peer' or cross-communication between devices located within the same VLAN. Traditional methods for this isolation, such as Private VLANs (PVLANs) or complex, manually managed Access Control Lists (ACLs), can be extremely difficult to maintain at scale across a global infrastructure.

TrustSec replaces these IP-based or VLAN-based restrictions with Scalable Group Tags (SGTs). When a device connects to the network, Cisco Identity Services Engine (ISE) authenticates the endpoint and assigns it a specific SGT based on its role, identity, or security posture. The network infrastructure (switches) then enforces policy based on these tags. To meet the requirement of preventing communication between devices in the same VLAN without using dynamic ACLs (dACLs), ISE can be configured to assign the same SGT to guest devices and then apply a Security Group ACL (SGACL) that denies traffic where both the source and destination tags are identical. This 'intra-SGT' isolation effectively blocks devices from communicating with their neighbors on the same local segment. This approach aligns with the Cisco SAFE architecture by providing granular, identity-aware segmentation that is topology-independent, allowing the hotel chain to maintain a simplified network structure while ensuring robust client security.

========


Contribute your Thoughts:

0/2000 characters
Casie
2 days ago
I agree, but A) Implement device posturing could also help with security.
upvoted 0 times
...
Elly
7 days ago
I think D) Configure TrustSec is the best choice. It allows for segmentation without ACLs.
upvoted 0 times
...
Jenise
12 days ago
I thought device posturing was more about compliance than segmentation?
upvoted 0 times
...
Elbert
17 days ago
Endpoint profiling might help, but not sure it’s enough.
upvoted 0 times
...
Enola
23 days ago
Wait, can TrustSec really prevent all VLAN communication?
upvoted 0 times
...
Refugia
28 days ago
Totally agree, TrustSec is perfect for segmentation!
upvoted 0 times
...
Sharee
1 month ago
I think enabling TrustSec is the way to go here.
upvoted 0 times
...
Jolanda
1 month ago
I keep thinking about device posturing, but I don't see how that would directly address the requirement of blocking communication in the same VLAN.
upvoted 0 times
...
Shaquana
1 month ago
I feel like enabling identity groups could help with segmentation, but I can't recall if it actually prevents communication between devices.
upvoted 0 times
...
Alesia
2 months ago
I remember practicing a similar question where we discussed endpoint profiling, but I don't think that's the right choice here.
upvoted 0 times
...
Danilo
2 months ago
I think the answer might be D) Configure TrustSec, but I'm not entirely sure how it specifically prevents communication between devices in the same VLAN.
upvoted 0 times
...

Save Cancel