Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium

A security team is implementing a new policy to restrict unauthorized devices from connecting to the corporate network. They want a solution that can automatically identify and control access for both wired and wireless devices based on their security posture before they are allowed to communicate with other internal resources. Which endpoint security technology best fits this requirement?

  1. ASecurity Information and Event Management (SIEM)
  2. BNetwork Access Control (NAC)
  3. CHost-based Firewall
  4. DData Loss Prevention (DLP)
Show answer & explanation

Correct answer: B. Network Access Control (NAC)

Network Access Control (NAC) is designed to enforce security policies on devices attempting to access the network. It can authenticate users and devices, assess their security posture (e.g., patch level, antivirus status), and grant or deny access accordingly, often placing non-compliant devices in a quarantine network.

Why the other options are wrong

  • A. SIEM collects and analyzes logs for security events, it doesn't control network access in real-time.
  • C. A host-based firewall protects an individual endpoint, but doesn't manage initial network access for all devices.
  • D. DLP prevents data exfiltration, not network access control for devices.

Network Access Control (NAC)

A security solution that restricts network access to devices that do not meet specified security policies. It authenticates users and devices, assesses their security posture, and enforces access control.

  • Prevents unauthorized devices from connecting to the network.
  • Can perform health checks on devices (e.g., AV status, patch levels).
  • Often integrates with identity management systems and can quarantine non-compliant devices.

Memory trick: NAC is the bouncer at the network's club, checking everyone's ID and dress code.

More Endpoint Security questions