CompTIA Security+ (SY0-701)Security OperationsMedium
A company wants to ensure that only corporate laptops with up-to-date antivirus signatures and the latest OS patches are permitted to join the internal network, while non-compliant devices are automatically placed into a quarantine VLAN. Which technology should be implemented?
- AData loss prevention (DLP)
- BWeb application firewall (WAF)
- CVirtual private network (VPN)
- DNetwork access control (NAC)
Show answer & explanationAnswer & explanation
Correct answer: D. Network access control (NAC)
NAC evaluates device posture (patch level, AV status) before granting network access and can dynamically quarantine non-compliant devices to a restricted VLAN. VPN provides secure remote connectivity, DLP prevents sensitive data exfiltration, and a WAF protects web applications—none perform posture-based network admission control.
Why the other options are wrong
- A. DLP monitors/prevents data exfiltration, unrelated to network admission.
- B. WAF protects web apps from attacks, not endpoint compliance checks.
- C. VPN secures remote traffic but doesn't check device posture for LAN admission.
Network Access Control (NAC)
A security solution that checks device compliance (patches, AV, configuration) before allowing network access, quarantining non-compliant devices.
- Enforces posture assessment at connection time
- Can use 802.1X for authentication
- Non-compliant devices routed to remediation VLAN
Memory trick: NAC is a bouncer checking ID and health papers before letting you into the club.