SSCP Systems Security Certified PractitionerNetwork and Communications SecurityMedium
A security team is implementing a network access control (NAC) solution. The primary goal is to ensure that only devices compliant with the organization's security posture (e.g., up-to-date antivirus, OS patches) are allowed to connect to the corporate network. Which NAC deployment model is best suited for real-time assessment and enforcement before granting full network access?
- AOut-of-band NAC
- BIn-band NAC
- CPost-admission NAC
- DAgentless NAC
Show answer & explanationAnswer & explanation
Correct answer: B. In-band NAC
In-band NAC (also known as inline NAC) places the NAC appliance directly in the network path, allowing it to intercept and enforce policies on traffic in real-time before granting full network access. This is ideal for pre-admission assessment and enforcement.
Why the other options are wrong
- A. Out-of-band NAC uses existing network infrastructure (e.g., switches with 802.1X) to enforce policies, but it often relies on redirection or VLAN assignment, which might not offer the same granular, real-time traffic interception as in-band.
- C. Post-admission NAC focuses on continuous monitoring and enforcement after a device has already gained some level of network access, rather than strictly before granting full access based on real-time assessment.
- D. Agentless NAC refers to the method of assessment (without an agent on the endpoint) and can be used in both in-band and out-of-band deployments, but it's not a deployment model itself for real-time enforcement.
In-band NAC
A Network Access Control deployment model where the NAC appliance is placed directly in the network's data path.
- Intercepts and controls all network traffic in real-time.
- Enforces policies before granting full network access.
- Provides strict control over device admission.
Memory trick: NAC Models: In-band is Inline, Out-of-band is Off-path.