nerdexam
Cisco

300-320 · Question #730

You are designing a NAC security solution that must group machines into objects and provision security policies based on those objects. Which technology do you use?

The correct answer is C. RBAC. NAC solutions use RBAC to categorize endpoints into role-based objects and enforce distinct security policies per role. RBAC is the foundational technology that maps machine groups to policy assignments in a NAC architecture.

Security Services

Question

You are designing a NAC security solution that must group machines into objects and provision security policies based on those objects. Which technology do you use?

Options

  • AVXLAN
  • B802.1Q
  • CRBAC
  • DCisco TrustSec

How the community answered

(21 responses)
  • A
    5% (1)
  • C
    90% (19)
  • D
    5% (1)

Why each option

NAC solutions use RBAC to categorize endpoints into role-based objects and enforce distinct security policies per role. RBAC is the foundational technology that maps machine groups to policy assignments in a NAC architecture.

AVXLAN

VXLAN is a Layer 2 overlay encapsulation protocol designed for network virtualization and workload mobility in data centers, not a mechanism for grouping machines into policy objects.

B802.1Q

802.1Q is a VLAN tagging standard for trunk links that provides traffic segmentation but does not define role-based grouping or policy provisioning logic.

CRBACCorrect

RBAC (Role-Based Access Control) is the technology that groups machines into logical role objects - such as employee, guest, or contractor - and provisions security policies based on membership in those roles. The NAC policy engine evaluates endpoint identity and posture attributes to assign a role, then enforces the access policy associated with that role. This role-to-policy mapping model is the defining characteristic of RBAC as applied in network access control solutions.

DCisco TrustSec

Cisco TrustSec is an implementation framework that uses Security Group Tags (SGTs) to enforce policies but is built on top of RBAC principles rather than being the specific technology that defines the grouping and provisioning model.

Concept tested: RBAC for NAC endpoint grouping and policy provisioning

Source: https://www.cisco.com/c/en/us/solutions/enterprise-networks/identity-services-engine/index.html

Topics

#RBAC#NAC#security policy#access control

Community Discussion

No community discussion yet for this question.

Full 300-320 Practice