ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityHard
A security auditor is performing a vulnerability assessment on a company's internal network. During the scan, the auditor discovers several network switches that have not been configured with any security measures to prevent unauthorized devices from connecting to their ports. Specifically, an attacker could easily plug in a rogue device, spoof a legitimate MAC address, and potentially gain network access. Which feature should the network administrator implement on the switches to mitigate this risk?
- AVLAN tagging
- BARP Inspection
- C802.1X Port-Based Authentication
- DDHCP Snooping
Show answer & explanationAnswer & explanation
Correct answer: C. 802.1X Port-Based Authentication
802.1X port-based authentication is the most comprehensive solution for preventing unauthorized devices from connecting to switch ports. It requires devices to authenticate before gaining network access, often integrating with a RADIUS server, and can be configured to dynamically assign VLANs or apply security policies.
Why the other options are wrong
- A. VLAN tagging segments networks logically but doesn't prevent unauthorized devices from connecting to a port and spoofing MAC addresses within a VLAN.
- B. ARP Inspection protects against ARP poisoning attacks but doesn't prevent unauthorized devices from initially connecting to a switch port and attempting to spoof MACs to gain access.
- D. DHCP Snooping prevents rogue DHCP servers and ensures legitimate DHCP traffic, but doesn't address unauthorized device connection or MAC spoofing directly.
802.1X Port-Based Authentication
An IEEE standard for port-based network access control that provides an authentication mechanism to devices wishing to attach to a LAN port or to establish a wireless connection.
- Requires authentication before network access is granted.
- Often integrates with RADIUS servers.
- Can dynamically assign VLANs or apply policies post-authentication.
Memory trick: 802.1X asks 'Who are you?' before connecting.