A community college district wants payment kiosks micro-segmented inside the SD-Access fabric using scalable group tags. What role do SGTs play in that design?
Select an answer to reveal the explanation.
Short Explanation
An SGT is a nametag on the laptop or kiosk—“cashier device,” “student BYOD”—so policy can say who talks to whom without carving a VLAN per device. In the fabric, those tags ride with the traffic and enforce micro-segmentation. That’s TrustSec thinking inside SD-Access.
Full Explanation
Scalable Group Tags (SGTs) from Cisco TrustSec identify security groups assigned during authentication/authorization and are carried in the fabric to enforce group-based policies. This enables micro-segmentation that is decoupled from pure IP or VLAN constructs, which suits shared VNs that still need kiosk isolation. SGTs do not replace VXLAN VNIs or underlay IGP mechanics; they complement VN segmentation with policy granularity.