SSCP Systems Security Certified PractitionerSecurity Operations and AdministrationMedium
A security manager is tasked with establishing a new security policy for remote access. The policy must ensure that all devices connecting to the corporate network from outside the perimeter meet specific security benchmarks, such as up-to-date antivirus definitions and operating system patches, before being granted access. Which technology is BEST suited to enforce this policy?
- ASecurity Information and Event Management (SIEM)
- BIntrusion Prevention System (IPS)
- CNetwork Access Control (NAC)
- DVirtual Private Network (VPN)
Show answer & explanationAnswer & explanation
Correct answer: C. Network Access Control (NAC)
Network Access Control (NAC) systems are designed to authenticate users and devices and assess their security posture (e.g., antivirus, patches) before granting them access to the network, making it ideal for enforcing compliance with remote access security benchmarks.
Why the other options are wrong
- A. SIEM collects and analyzes security logs but doesn't actively enforce access based on device health.
- B. IPS detects and prevents intrusions but doesn't check the health or compliance of connecting endpoints.
- D. VPN establishes a secure tunnel but doesn't inherently check the security posture of the connecting device before allowing the connection.
Network Access Control (NAC)
Network Access Control (NAC) is a security solution that restricts the availability of network resources to endpoint devices that comply with a defined security policy. It authenticates users and devices and assesses their security posture before granting network access.
- Authenticates users and devices.
- Evaluates device security posture (e.g., AV, patches).
- Grants, denies, or restricts network access based on compliance.
- Crucial for BYOD and remote access security.
Memory trick: NAC: Check your papers before you enter the network party.