Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium
A company is implementing a bring-your-own-device (BYOD) policy and needs to ensure that personal mobile devices accessing corporate Wi-Fi meet minimum security requirements, such as having a screen lock enabled and a specific antivirus app installed. Which endpoint security technology is best suited to assess and enforce these compliance checks dynamically before granting network access?
- ANetwork Access Control (NAC)
- BMobile Device Management (MDM)
- CHost-based Firewall
- DEndpoint Detection and Response (EDR)
Show answer & explanationAnswer & explanation
Correct answer: A. Network Access Control (NAC)
Network Access Control (NAC) systems are designed to assess the security posture of endpoints connecting to the network and enforce compliance with defined policies, making them ideal for BYOD scenarios requiring dynamic checks before granting access.
Why the other options are wrong
- B. MDM manages and secures mobile devices, but NAC is specifically designed for network admission control based on endpoint posture.
- C. A host-based firewall protects a single endpoint but doesn't manage or enforce compliance for network access of other devices.
- D. EDR focuses on detecting and responding to threats post-compromise on an endpoint, not pre-admission compliance checks.
Network Access Control (NAC)
A security solution that restricts network access to endpoints that comply with a defined security policy.
- Performs endpoint posture assessment.
- Enforces policies before and after network admission.
- Supports various authentication methods (802.1X, MAC, WebAuth).
Memory trick: NAC checks the 'health' of endpoints before letting them in the network 'party'.