nerdexam
Isaca

CISA · Question #39

Which of the following is the BEST way to mitigate risk to an organization's network associated with devices permitted under a bring your own device (BYOD) policy?

The correct answer is A. Implement a network access control system.. Implementing a network access control (NAC) system is the best way to mitigate BYOD risks by enforcing security policies and controlling device access to the network. NAC ensures only compliant and authorized devices can connect, limiting the attack surface presented by personal

Submitted by diego_uy· Apr 18, 2026Protection of Information Assets

Question

Which of the following is the BEST way to mitigate risk to an organization's network associated with devices permitted under a bring your own device (BYOD) policy?

Options

  • AImplement a network access control system.
  • BRequire personal devices to be reviewed by IT staff.
  • CEnable port security on all network switches.
  • DEnsure the policy requires antivirus software on devices.

How the community answered

(59 responses)
  • A
    73% (43)
  • B
    3% (2)
  • C
    17% (10)
  • D
    7% (4)

Why each option

Implementing a network access control (NAC) system is the best way to mitigate BYOD risks by enforcing security policies and controlling device access to the network. NAC ensures only compliant and authorized devices can connect, limiting the attack surface presented by personal devices.

AImplement a network access control system.Correct

A Network Access Control (NAC) system is the most comprehensive solution for BYOD risk mitigation because it can dynamically assess the security posture of personal devices (e.g., antivirus status, patch level, encryption) before granting or restricting network access. NAC enforces policies, isolates non-compliant devices, and provides granular control over what resources BYOD devices can access, significantly reducing the attack surface.

BRequire personal devices to be reviewed by IT staff.

Requiring devices to be reviewed by IT staff is often impractical for large organizations and provides only a point-in-time check, not continuous enforcement.

CEnable port security on all network switches.

Enabling port security on network switches primarily limits the number of MAC addresses per port and restricts unauthorized devices from plugging in, but doesn't address the security posture of authorized wireless BYOD devices or their software.

DEnsure the policy requires antivirus software on devices.

Requiring antivirus software is an important security control but is only one component of a holistic security posture; NAC can enforce this and many other requirements.

Concept tested: BYOD risk mitigation (NAC)

Source: https://www.cisco.com/c/en/us/products/security/network-access-control-nac/index.html

Topics

#BYOD#Network Access Control#Risk Mitigation#Network Security

Community Discussion

No community discussion yet for this question.

Full CISA Practice