SSCP Systems Security Certified PractitionerNetwork and Communications SecurityMedium

A security team is implementing a network access control (NAC) solution. The primary goal is to ensure that only devices compliant with the organization's security posture (e.g., up-to-date antivirus, OS patches) are allowed to connect to the corporate network. Which NAC deployment model is best suited for real-time assessment and enforcement before granting full network access?

  1. AOut-of-band NAC
  2. BIn-band NAC
  3. CPost-admission NAC
  4. DAgentless NAC
Show answer & explanation

Correct answer: B. In-band NAC

In-band NAC (also known as inline NAC) places the NAC appliance directly in the network path, allowing it to intercept and enforce policies on traffic in real-time before granting full network access. This is ideal for pre-admission assessment and enforcement.

Why the other options are wrong

  • A. Out-of-band NAC uses existing network infrastructure (e.g., switches with 802.1X) to enforce policies, but it often relies on redirection or VLAN assignment, which might not offer the same granular, real-time traffic interception as in-band.
  • C. Post-admission NAC focuses on continuous monitoring and enforcement after a device has already gained some level of network access, rather than strictly before granting full access based on real-time assessment.
  • D. Agentless NAC refers to the method of assessment (without an agent on the endpoint) and can be used in both in-band and out-of-band deployments, but it's not a deployment model itself for real-time enforcement.

In-band NAC

A Network Access Control deployment model where the NAC appliance is placed directly in the network's data path.

  • Intercepts and controls all network traffic in real-time.
  • Enforces policies before granting full network access.
  • Provides strict control over device admission.

Memory trick: NAC Models: In-band is Inline, Out-of-band is Off-path.

More Network and Communications Security questions