🔥 3-day streak
Cisco CCNP Data Center DCCOR (350-601)66 / 136
Question 66 of 136

A data center engineer is deploying Cisco TrustSec on a pair of Nexus 9000 switches to segment east-west traffic between application tiers. Endpoints are classified into Security Group Tags (SGTs) at the ingress switch, and the security policy must be enforced so that 'Web' servers (SGT 10) can never initiate connections to 'Database' servers (SGT 30). Where in the TrustSec architecture is this restriction actually enforced, and what construct defines the permit/deny behavior?

Reviewed for accuracy · Report an issueNext question