Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessHard
A security engineer is implementing a secure network access solution for IoT devices. These devices have limited processing power and do not support 802.1X or complex authentication protocols. The solution must provide secure network access and allow for device profiling to assign appropriate network segments. Which approach is most suitable for authenticating and authorizing these constrained IoT devices?
- AWeb Authentication with a captive portal
- BMAC Authentication Bypass (MAB) with profiling
- CPre-Shared Key (PSK) with strong password policies
- DEAP-TLS with client certificates
Show answer & explanationAnswer & explanation
Correct answer: B. MAC Authentication Bypass (MAB) with profiling
MAC Authentication Bypass (MAB) is suitable for devices that cannot perform 802.1X. When combined with device profiling (e.g., using Cisco ISE), the MAC address can be used to identify the device type, and then appropriate policies and network segments can be assigned, addressing the requirements for constrained IoT devices.
Why the other options are wrong
- A. Web authentication requires user interaction, which is often not feasible for headless IoT devices.
- C. PSK is a shared secret and offers less granular control and no inherent device profiling capabilities for dynamic segmentation.
- D. EAP-TLS requires certificates and 802.1X support, which constrained IoT devices typically lack.
IoT Device Network Access
Securely onboarding and segmenting IoT devices with limited capabilities, often requiring non-802.1X authentication methods combined with device profiling.
- IoT devices may lack complex authentication protocol support.
- MAC Authentication Bypass (MAB) is a common method.
- Device profiling is crucial for identifying and segmenting IoT based on type/function.
Memory trick: For 'dumb' IoT, check their 'address' and 'who' they are.