Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementHard

A security auditor is reviewing the access control policies for a critical server farm. The current policy uses standard ACLs to permit specific source IPs to access designated server ports. The auditor recommends moving to a more granular and scalable access control mechanism that can dynamically adapt to changes in network topology and application requirements, without requiring manual ACL updates across many devices. Which access control solution aligns best with this recommendation?

  1. AFirewall object groups combined with network address translation (NAT).
  2. BExtended ACLs on network devices.
  3. CPort security on access layer switches.
  4. DRole-based access control (RBAC) integrated with a centralized policy engine.
Show answer & explanation

Correct answer: D. Role-based access control (RBAC) integrated with a centralized policy engine.

Role-based access control (RBAC) integrated with a centralized policy engine (like Cisco ISE) allows for dynamic, scalable, and granular access control based on user roles and device posture, which can adapt without manual ACL updates. This is a significant improvement over static, IP-based ACLs.

Why the other options are wrong

  • A. Firewall object groups improve readability and manageability of ACLs but do not provide dynamic, role-based access control or eliminate the need for manual updates for new application requirements.
  • B. Extended ACLs are still static and IP-based, requiring manual updates and not scaling well with dynamic environments.
  • C. Port security controls which MAC addresses can connect to a port, not granular access to server applications.

Role-Based Access Control (RBAC) with Centralized Policy

An access control model where permissions are associated with roles, and users are assigned to appropriate roles. When integrated with a centralized policy engine, it enables dynamic, scalable, and consistent access policy enforcement across the network based on identity and context.

  • Permissions are granted based on roles, not individual users.
  • Centralized policy engine (e.g., NAC) manages roles and permissions.
  • Dynamically assigns access based on user, device, and context.
  • Reduces administrative overhead compared to static ACLs.

Memory trick: For dynamic access, roles and a central brain are key.

More Visibility and Enforcement questions