Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityEasy
A security administrator is implementing a new policy to restrict unauthorized devices from connecting to the corporate network. The goal is to ensure that only compliant and approved endpoints can access network resources. Which endpoint security technology is best suited to achieve this objective?
- AEndpoint Detection and Response (EDR)
- BNetwork Access Control (NAC)
- CData Loss Prevention (DLP)
- DHost-based Firewall
Show answer & explanationAnswer & explanation
Correct answer: B. Network Access Control (NAC)
Network Access Control (NAC) is designed to enforce security policies on devices attempting to access the network, allowing only authorized and compliant endpoints to connect. It performs checks before granting network access.
Why the other options are wrong
- A. EDR focuses on detecting and responding to threats on endpoints after they have connected.
- C. DLP focuses on preventing sensitive data from leaving the organization, not controlling network access.
- D. A host-based firewall protects an individual endpoint, but doesn't control initial network access for unauthorized devices.
Network Access Control (NAC)
A security solution that restricts network access to devices that do not meet specified security policies.
- Ensures only authorized and compliant devices connect.
- Can perform pre-admission and post-admission checks.
- Integrates with other security systems.
Memory trick: NAC guards the network gate, only compliant devices can pass.