An animal-control HQ wants fabric edges to enforce Scalable Group Tags that reflect how each endpoint authenticated. Which companion platform normally classifies those endpoints into SGTs for the fabric to consume?
Select an answer to reveal the explanation.
Short Explanation
The fabric is great at carrying and enforcing tags, but something still has to decide which badge each device earns. That classifier is ISE during auth—802.1X, MAB, whatever you use. ISE hands back the SGT, and the fabric policy plane consumes it instead of guessing from NetFlow or multicast.
Full Explanation
Cisco Identity Services Engine commonly acts as the policy and classification companion for SD-Access: during wired or wireless authentication it authorizes the session and assigns an SGT. Fabric edge/policy enforcement points then use those tags with group-based policy. NetFlow collectors, PIM RPs, and SD-WAN AAR are not the standard SGT classification path for campus fabric host onboarding.