Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessHard

A network administrator is deploying a new wireless network that must support both corporate devices using 802.1X with EAP-TLS for strong authentication and guest devices requiring a simple, temporary access method. The solution needs to dynamically assign different VLANs and access policies based on the authentication method and device type. Which secure network access design best accommodates these diverse requirements?

  1. ASeparate SSIDs with WPA2-Personal for corporate and an open network for guests.
  2. BA single SSID with 802.1X EAP-TLS for corporate and a separate captive portal for guests, managed by a central NAC.
  3. CSeparate SSIDs for corporate and guest networks with pre-shared keys for both.
  4. DA single SSID using MAC Address Bypass (MAB) for all devices.
Show answer & explanation

Correct answer: B. A single SSID with 802.1X EAP-TLS for corporate and a separate captive portal for guests, managed by a central NAC.

Using a single SSID with 802.1X EAP-TLS for corporate devices provides strong, certificate-based authentication and allows for dynamic VLAN assignment. Integrating a captive portal on the same SSID (or a separate one, but often combined for simplicity) allows for easy, temporary access for guests, while a central NAC (like Cisco ISE) can manage policies and assign appropriate VLANs based on the authentication method used, meeting all requirements.

Why the other options are wrong

  • A. WPA2-Personal is not as strong as EAP-TLS, and an open guest network is insecure and lacks policy enforcement.
  • C. Pre-shared keys (PSKs) offer weaker security than EAP-TLS and don't allow for dynamic policy/VLAN assignment based on identity.
  • D. MAB is less secure than EAP-TLS and is primarily used for non-802.1X capable devices, not as a primary strong authentication method for corporate users.

Dual-Mode Wireless Access (EAP-TLS & Captive Portal)

A wireless network design that supports both strong, certificate-based authentication (EAP-TLS for corporate users) and simpler, web-based authentication (captive portal for guests) on the same or related infrastructure, typically managed by a NAC.

  • Provides secure access for corporate devices.
  • Offers user-friendly access for guests.
  • Enables dynamic policy and VLAN assignment via NAC.

Memory trick: One Wi-Fi, Two Doors: EAP-TLS for the 'VIPs', Captive Portal for the 'Visitors'.

More Endpoint Security and Secure Network Access questions