Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium

A network security administrator needs to implement a security solution that restricts network access based on user identity, device posture (e.g., up-to-date antivirus, OS patch level), and location. This solution should dynamically assign users to appropriate network segments or enforce specific access policies. Which security technology is best suited for these requirements?

  1. ARole-Based Access Control (RBAC)
  2. BIntrusion Prevention System (IPS)
  3. CSecurity Information and Event Management (SIEM)
  4. DNetwork Access Control (NAC)
Show answer & explanation

Correct answer: D. Network Access Control (NAC)

Network Access Control (NAC) is explicitly designed to restrict network access based on user identity, device posture, and location. It authenticates users/devices, assesses their compliance with security policies, and then dynamically assigns them to appropriate network segments or enforces specific access policies. RBAC defines permissions by role but doesn't handle device posture. SIEM is for log analysis. IPS detects and prevents intrusions.

Why the other options are wrong

  • A. RBAC defines permissions based on user roles but does not typically assess device posture or dynamically assign network segments based on real-time compliance.
  • B. IPS detects and prevents network intrusions based on signatures or anomalies, but it does not manage user identity, device posture, or dynamic access assignment.
  • C. SIEM aggregates and analyzes security logs for threat detection and compliance reporting, but it does not directly control network access based on posture.

Network Access Control (NAC)

Network Access Control (NAC) is a security solution that restricts network access based on user identity, device posture, and compliance with security policies, dynamically onboarding or isolating devices as needed.

  • Authenticates users and devices.
  • Assesses device health/compliance (posture).
  • Enforces dynamic access policies or network segmentation.

Memory trick: Who gets in, and what condition is their 'ticket' in?

More Network Security questions