正解:B
Cisco TrustSec classifies traffic using Security Group Tags, commonly called SGTs. An SGT represents the security group identity assigned to a user, device, or endpoint session. Instead of relying only on VLANs, IP subnets, or ACLs tied to topology, TrustSec allows policy to follow the identity of the endpoint. That makes option B correct. VLAN-based classification is less flexible because VLANs are tied to Layer 2 segmentation and network placement. MAC addresses can identify devices but are not the TrustSec policy classification mechanism. IP addresses are commonly used in traditional ACLs, but TrustSec's purpose is to reduce dependence on IP-based segmentation by using group-based policy.
Once traffic is tagged with an SGT, network devices can enforce Security Group ACLs, also called SGACLs, based on source and destination security groups. This supports scalable segmentation across campus and enterprise networks. The ENCOR concept is identity-based segmentation and policy abstraction. References/topics: ENCOR Security, Cisco TrustSec, Security Group Tag, SGACL, identity-based access control, scalable group-based segmentation.