300-365 · Question #62
Which three security features can be gained by installing a Cisco NAC Appliance into the network? (Choose three.)
The correct answer is A. in-band or out-of-band deployment options C. bandwidth and traffic filtering controls D. posture assessment. Cisco NAC Appliance provides network access control through flexible deployment, traffic enforcement, and client health checks - not intrusion detection or rogue wireless detection.
Question
Which three security features can be gained by installing a Cisco NAC Appliance into the network? (Choose three.)
Options
- Ain-band or out-of-band deployment options
- Bintrusion detection
- Cbandwidth and traffic filtering controls
- Dposture assessment
- Eaccurate identification, classification, and stopping of malicious traffic
- Fdetection and containment of rogue clients
How the community answered
(64 responses)- A94% (60)
- B2% (1)
- E5% (3)
Why each option
Cisco NAC Appliance provides network access control through flexible deployment, traffic enforcement, and client health checks - not intrusion detection or rogue wireless detection.
NAC Appliance supports both in-band deployment (traffic flows through the NAC device) and out-of-band deployment (NAC redirects only during remediation), giving architects flexibility in how they integrate it into the network.
Intrusion detection is the function of an IDS/IPS device, not a NAC appliance, which focuses on access control and posture rather than monitoring traffic for attack signatures.
NAC Appliance can enforce bandwidth policies and filter specific types of traffic as part of its role-based access control, allowing network policies to restrict what authenticated or quarantined clients can do.
Posture assessment is the core function of NAC - it evaluates whether a client meets health requirements (antivirus, patch level, etc.) before granting network access, quarantining non-compliant endpoints.
Accurate identification and stopping of malicious traffic describes IPS functionality, not NAC - NAC controls access based on identity and posture, not real-time traffic analysis.
Detection and containment of rogue clients is primarily a function of a Wireless Intrusion Prevention System (WIPS), not a NAC appliance.
Concept tested: Cisco NAC Appliance core security capabilities
Source: https://www.cisco.com/c/en/us/products/security/nac-appliance-clean-access/index.html
Topics
Community Discussion
No community discussion yet for this question.