nerdexam
(ISC)2

CISSP · Question #1449

Which of the following is the MOST effective way to ensure the endpoint devices used by remote users are compliant with an organization's approved policies before being allowed on the network?

The correct answer is B. Network Access Control (NAC). Network Access Control (NAC) is designed specifically to evaluate endpoint compliance against policy before granting network access, making it the most effective pre-admission control mechanism for remote devices.

Submitted by takeshi77· Mar 5, 2026Communication and Network Security

Question

Which of the following is the MOST effective way to ensure the endpoint devices used by remote users are compliant with an organization's approved policies before being allowed on the network?

Options

  • AGroup Policy Object (GPO)
  • BNetwork Access Control (NAC)
  • CMobile Device Management (MDM)
  • DPrivileged Access Management (PAM)

How the community answered

(56 responses)
  • A
    2% (1)
  • B
    91% (51)
  • C
    2% (1)
  • D
    5% (3)

Why each option

Network Access Control (NAC) is designed specifically to evaluate endpoint compliance against policy before granting network access, making it the most effective pre-admission control mechanism for remote devices.

AGroup Policy Object (GPO)

GPOs apply configuration and policy settings to devices already joined to an Active Directory domain, but they cannot evaluate or block non-compliant remote endpoints at the point of network entry.

BNetwork Access Control (NAC)Correct

NAC enforces posture assessment by inspecting endpoint devices for compliance with security policies-such as patch levels, antivirus status, and configuration-before admitting them to the network. If a device fails the posture check, NAC can quarantine it, deny access, or redirect it to a remediation VLAN, ensuring only compliant endpoints gain network entry. This pre-admission control is the core purpose of NAC solutions like Cisco ISE or Microsoft Network Policy Server.

CMobile Device Management (MDM)

MDM manages and enforces policies on enrolled mobile and endpoint devices, but it does not provide a network-level gate that blocks non-compliant devices before they connect to the network.

DPrivileged Access Management (PAM)

PAM controls and monitors privileged account access and credentials, which addresses insider and administrative account risk rather than endpoint compliance at the time of network admission.

Concept tested: Network Access Control endpoint posture compliance enforcement

Source: https://www.cisco.com/c/en/us/products/security/what-is-network-access-control-nac.html

Topics

#Endpoint security#Network Access Control (NAC)#Remote access#Compliance

Community Discussion

No community discussion yet for this question.

Full CISSP Practice