Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium

A network security team is designing a secure network access solution for a new research and development (R&D) facility. The design requires that network devices (switches, routers) automatically apply appropriate security policies (e.g., VLAN assignments, ACLs) to connected endpoints based on their role and compliance status, without manual intervention. This dynamic policy assignment must be achieved through integration with a centralized authentication and authorization server. Which protocol is primarily used by the network devices to communicate with the centralized server for this dynamic policy enforcement?

  1. ARADIUS (Remote Authentication Dial-In User Service)
  2. BDNS (Domain Name System)
  3. CSSH (Secure Shell)
  4. DSNMP (Simple Network Management Protocol)
Show answer & explanation

Correct answer: A. RADIUS (Remote Authentication Dial-In User Service)

RADIUS is the industry-standard protocol used by network devices (clients) to send authentication and authorization requests to a centralized server (e.g., Cisco ISE). The server then responds with authorization attributes, such as VLAN assignments or downloadable ACLs, which the network device dynamically applies to the connecting endpoint. SNMP is for network management, SSH for secure remote access, and DNS for name resolution.

Why the other options are wrong

  • B. DNS translates domain names to IP addresses and is not involved in authentication or dynamic policy assignment.
  • C. SSH provides a secure command-line interface for remote access to network devices and does not facilitate dynamic policy assignment based on endpoint authentication.
  • D. SNMP is used for monitoring and managing network devices, not for authentication and dynamic policy enforcement for connecting endpoints.

RADIUS for Dynamic Policy

Remote Authentication Dial-In User Service (RADIUS) is a client/server protocol that enables network devices to communicate with a centralized AAA server for authentication and to receive dynamic authorization attributes (like VLANs or ACLs) for policy enforcement.

  • Centralizes AAA services.
  • Enables dynamic policy assignment.
  • Widely used in 802.1X and VPN deployments.

Memory trick: The network device asks RADIUS for the rules, and RADIUS sends them back to enforce.

More Endpoint Security and Secure Network Access questions