CompTIA Security+ (SY0-701)Security OperationsMedium

A company wants to ensure that only corporate laptops with up-to-date antivirus signatures and the latest OS patches are permitted to join the internal network, while non-compliant devices are automatically placed into a quarantine VLAN. Which technology should be implemented?

  1. AData loss prevention (DLP)
  2. BWeb application firewall (WAF)
  3. CVirtual private network (VPN)
  4. DNetwork access control (NAC)
Show answer & explanation

Correct answer: D. Network access control (NAC)

NAC evaluates device posture (patch level, AV status) before granting network access and can dynamically quarantine non-compliant devices to a restricted VLAN. VPN provides secure remote connectivity, DLP prevents sensitive data exfiltration, and a WAF protects web applications—none perform posture-based network admission control.

Why the other options are wrong

  • A. DLP monitors/prevents data exfiltration, unrelated to network admission.
  • B. WAF protects web apps from attacks, not endpoint compliance checks.
  • C. VPN secures remote traffic but doesn't check device posture for LAN admission.

Network Access Control (NAC)

A security solution that checks device compliance (patches, AV, configuration) before allowing network access, quarantining non-compliant devices.

  • Enforces posture assessment at connection time
  • Can use 802.1X for authentication
  • Non-compliant devices routed to remediation VLAN

Memory trick: NAC is a bouncer checking ID and health papers before letting you into the club.

More Security Operations questions