700-760 · Question #55
Which two attack vectors are protected by identity and access control? (Choose two.)
The correct answer is A. campus and home E. cloud apps. Identity and access control secures the user as the attack vector - governing who is allowed onto the network and what cloud resources they can reach. Campus and home (A) represent user-initiated network access points where technologies like 802.1X, NAC, and MFA authenticate…
Question
Which two attack vectors are protected by identity and access control? (Choose two.)
Options
- Acampus and home
- Bvoicemail
- Cendpoints
- Ddata center
- Ecloud apps
How the community answered
(27 responses)- A89% (24)
- B4% (1)
- C7% (2)
Explanation
Identity and access control secures the user as the attack vector - governing who is allowed onto the network and what cloud resources they can reach. Campus and home (A) represent user-initiated network access points where technologies like 802.1X, NAC, and MFA authenticate users before granting entry, and cloud apps (E) rely entirely on identity mechanisms (SSO, MFA, CASB) because there is no perimeter firewall to fall back on.
Why the distractors are wrong:
- B (Voicemail) - a communications/voice attack vector, addressed by separate voice security controls, not IAC.
- C (Endpoints) - protected by endpoint security platforms (AV, EDR, XDR), not identity controls specifically.
- D (Data center) - protected by network segmentation, next-gen firewalls, and micro-segmentation, not IAC as the primary control.
Memory tip: Think "Who logs in from where?" - Identity and access control answers the question of who the user is (campus, home, or cloud). If the vector is about a device, a place in the network, or a communication channel rather than a user's identity, another security domain owns it.
Topics
Community Discussion
No community discussion yet for this question.