Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessHard

A manufacturing company is integrating IoT devices into its production network. These devices have limited computational resources, do not support complex authentication protocols like 802.1X, and need to communicate only with specific industrial control systems (ICS). The security team needs to implement a secure network access solution that segments these IoT devices, restricts their communication, and provides a robust alternative to traditional authentication. Which secure network access protocol or method is best suited for securing these resource-constrained IoT devices?

  1. AMAC Authentication Bypass (MAB) with profiling
  2. BEAP-TLS with client certificates
  3. CCaptive Portal authentication
  4. DRADIUS with PAP/CHAP authentication
Show answer & explanation

Correct answer: A. MAC Authentication Bypass (MAB) with profiling

MAC Authentication Bypass (MAB) with profiling is ideal for resource-constrained IoT devices. MAB allows devices to authenticate based on their MAC address, and profiling (often done by NAC solutions like Cisco ISE) then identifies the device type and assigns appropriate access policies (e.g., VLANs, ACLs) to restrict communication. EAP-TLS is too complex. RADIUS with PAP/CHAP is not identity-based for devices, and Captive Portal is for user interaction, not headless IoT devices.

Why the other options are wrong

  • B. EAP-TLS requires client certificates and more sophisticated cryptographic capabilities, which are typically not available on resource-constrained IoT devices.
  • C. Captive Portal authentication requires user interaction through a web browser, which is impossible for most IoT devices that operate autonomously without a display or user input.
  • D. RADIUS with PAP/CHAP provides username/password authentication, which is not suitable for headless IoT devices that don't have users or interfaces for entering credentials.

MAB with Profiling for IoT

A secure network access method for resource-constrained IoT devices where devices are authenticated based on their MAC address (MAB), and then network profiling identifies the device type to apply specific, restrictive access policies.

  • Suitable for devices without 802.1X support.
  • Leverages device profiling for identification.
  • Enables granular policy enforcement for IoT.

Memory trick: For 'dumb' IoT, let their MAC be their ID, and then profile them harshly.

More Endpoint Security and Secure Network Access questions