Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2ArchitectureMedium

A network administrator is configuring a new switch for a small branch office. The switch needs to provide network access to both trusted corporate devices and untrusted guest devices, with strict isolation between the two groups. Furthermore, the switch must prevent unauthorized devices from connecting to either network. Which combination of network segmentation and access control technologies should be implemented at the access layer?

  1. AVLANs for segmentation and 802.1X with NAC for access control
  2. BVRFs for segmentation and Port Security for access control
  3. CFirewall rules for segmentation and DHCP snooping for access control
  4. DVLANs for segmentation and MAC address filtering for access control
Show answer & explanation

Correct answer: A. VLANs for segmentation and 802.1X with NAC for access control

VLANs provide effective Layer 2 segmentation to isolate trusted and untrusted networks. Combining this with 802.1X and a Network Access Control (NAC) solution (like Cisco Identity Services Engine - ISE) offers robust, dynamic access control. 802.1X authenticates users/devices before granting network access, and NAC can dynamically assign them to appropriate VLANs and apply policies based on identity and posture, preventing unauthorized access.

Why the other options are wrong

  • B. VRFs are Layer 3 segmentation, typically on routers, and not primarily for access layer device isolation; Port Security is basic and can be bypassed.
  • C. Firewall rules are typically for inter-VLAN routing or perimeter security, not direct access layer device segmentation and prevention of unauthorized physical connections; DHCP snooping is for security against rogue DHCP servers, not general access control.
  • D. MAC address filtering is easily spoofed and not scalable for dynamic environments, making it insufficient for strict unauthorized device prevention.

802.1X with NAC

A robust network access control mechanism that authenticates users and devices before granting network access, often dynamically assigning them to appropriate VLANs and applying security policies.

  • Requires an authentication server (e.g., RADIUS/TACACS+).
  • Authenticates based on user credentials or device certificates.
  • Enables dynamic VLAN assignment and policy enforcement.

Memory trick: VLANs divide 'rooms', 802.1X/NAC is the 'bouncer' at the door.

More Architecture questions