正解:C
Cisco TrustSec, as part of Cisco's Service Provider Network Core Technologies, enables more dynamic access controls by utilizing the contextual identity of endpoints rather than relying solely on IP addresses. This approach allows for more granular security policies that can adapt to the changing needs of a network environment. By identifying and classifying traffic based on the user, device, and application information, TrustSec can enforce consistent security policies across the network, making it particularly useful in dynamic networking environments and data centers where the traditional IP-based access control lists (ACLs) may not be sufficient.
The Cisco TrustSec solution simplifies the provisioning and management of network access control through the use of software-defined segmentation to classify network traffic and enforce policies for more flexible access controls. Traffic classification is based on endpoint identity, not IP address, enabling policy change without net-work redesign.