Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium
A security administrator is implementing a system to prevent unauthorized devices from connecting to the corporate network, even if they have valid user credentials. This system should inspect device health and compliance before granting network access. Which endpoint security technology is being described?
- AEndpoint Detection and Response (EDR)
- BSecurity Information and Event Management (SIEM)
- CNetwork Access Control (NAC)
- DIntrusion Detection System (IDS)
Show answer & explanationAnswer & explanation
Correct answer: C. Network Access Control (NAC)
Network Access Control (NAC) solutions are designed to enforce policies that dictate which devices can connect to the network, often by checking their health, compliance, and user authentication before granting or denying access.
Why the other options are wrong
- A. EDR focuses on continuous monitoring and response to threats on endpoints *after* they are connected, not initial access control.
- B. SIEM aggregates and analyzes logs from various sources, aiding in detection, but it doesn't control real-time network access decisions.
- D. IDS monitors for malicious activity but doesn't control initial network access for devices.
Network Access Control (NAC)
A security solution that controls who and what can connect to a network, enforcing security policies and compliance requirements on devices before granting them access.
- Authenticates users and devices.
- Evaluates device health and compliance.
- Can quarantine non-compliant devices.
Memory trick: NAC is the bouncer checking IDs and health at the network's club entrance.