nerdexam
Cisco

400-007 · Question #237

A security architect receives reports of these incidents: - An attacker exploits printers and medical devices in the organization to gain control of the network. - An attacker disrupts operations…

The correct answer is C. Apply a context-based network access control policy. After discovering and classifying IoT and OT devices on the network, applying a context-based network access control policy is the immediate next step to contain lateral movement and isolate vulnerable devices.

Designing Security

Question

A security architect receives reports of these incidents:

  • An attacker exploits printers and medical devices in the organization

to gain control of the network.

  • An attacker disrupts operations through attacks on networked business

infrastructure. What is the next step to address these issues after discovery and classification of devices?

Options

  • AEnsure trustworthiness of devices
  • BAssess continuous security health monitoring
  • CApply a context-based network access control policy
  • DEnforce risk-based and adaptive access policies

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    11% (4)
  • C
    71% (27)
  • D
    13% (5)

Why each option

After discovering and classifying IoT and OT devices on the network, applying a context-based network access control policy is the immediate next step to contain lateral movement and isolate vulnerable devices.

AEnsure trustworthiness of devices

Ensuring device trustworthiness is part of the discovery and classification phase itself, not the step that follows it.

BAssess continuous security health monitoring

Continuous security health monitoring is an ongoing operational activity that comes after foundational access control policies are in place, not the immediate post-classification step.

CApply a context-based network access control policyCorrect

Context-based NAC uses device identity, type, location, and behavior - gathered during discovery and classification - to enforce granular segmentation policies. This directly addresses the attack vectors described by isolating printers, medical devices, and business infrastructure into appropriate network segments with limited communication paths, preventing attackers from using compromised devices to pivot across the network.

DEnforce risk-based and adaptive access policies

Risk-based and adaptive access policies are a more advanced, dynamic control layer that builds on top of baseline context-based NAC, making C the prerequisite step.

Concept tested: IoT/OT network segmentation via context-based NAC

Source: https://www.cisco.com/c/en/us/solutions/internet-of-things/iot-security.html

Topics

#IoT security#network access control#device classification#network segmentation

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice