Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessEasy

A financial institution is implementing a bring-your-own-device (BYOD) policy and requires a solution to ensure that all personal devices connecting to the corporate network comply with security policies, such as having up-to-date antivirus software and a locked screen. If a device is non-compliant, it should be placed in a restricted network segment. Which technology is best suited for this requirement?

  1. AFirewall
  2. BNetwork Access Control (NAC)
  3. CData Loss Prevention (DLP)
  4. DIntrusion Prevention System (IPS)
Show answer & explanation

Correct answer: B. Network Access Control (NAC)

Network Access Control (NAC) is specifically designed to enforce security policies on devices attempting to access the network. It can assess device posture, authenticate users, and provision appropriate network access based on compliance, making it ideal for BYOD scenarios.

Why the other options are wrong

  • A. A firewall primarily controls traffic based on rules, not device posture or user identity.
  • C. DLP focuses on preventing sensitive data from leaving the organization, not controlling device access based on posture.
  • D. An IPS focuses on detecting and preventing network intrusions, not device compliance for initial access.

Network Access Control (NAC)

A security solution that restricts network access to endpoints that do not comply with predefined security policies.

  • Authenticates users and devices.
  • Assesses device security posture (e.g., antivirus, patches).
  • Enforces granular access policies based on compliance.

Memory trick: NAC is the bouncer checking IDs and dress code at the network club.

More Endpoint Security and Secure Network Access questions