CISSP · Question #1449
Which of the following is the MOST effective way to ensure the endpoint devices used by remote users are compliant with an organization's approved policies before being allowed on the network?
The correct answer is B. Network Access Control (NAC). Network Access Control (NAC) is designed specifically to evaluate endpoint compliance against policy before granting network access, making it the most effective pre-admission control mechanism for remote devices.
Question
Options
- AGroup Policy Object (GPO)
- BNetwork Access Control (NAC)
- CMobile Device Management (MDM)
- DPrivileged Access Management (PAM)
How the community answered
(56 responses)- A2% (1)
- B91% (51)
- C2% (1)
- D5% (3)
Why each option
Network Access Control (NAC) is designed specifically to evaluate endpoint compliance against policy before granting network access, making it the most effective pre-admission control mechanism for remote devices.
GPOs apply configuration and policy settings to devices already joined to an Active Directory domain, but they cannot evaluate or block non-compliant remote endpoints at the point of network entry.
NAC enforces posture assessment by inspecting endpoint devices for compliance with security policies-such as patch levels, antivirus status, and configuration-before admitting them to the network. If a device fails the posture check, NAC can quarantine it, deny access, or redirect it to a remediation VLAN, ensuring only compliant endpoints gain network entry. This pre-admission control is the core purpose of NAC solutions like Cisco ISE or Microsoft Network Policy Server.
MDM manages and enforces policies on enrolled mobile and endpoint devices, but it does not provide a network-level gate that blocks non-compliant devices before they connect to the network.
PAM controls and monitors privileged account access and credentials, which addresses insider and administrative account risk rather than endpoint compliance at the time of network admission.
Concept tested: Network Access Control endpoint posture compliance enforcement
Source: https://www.cisco.com/c/en/us/products/security/what-is-network-access-control-nac.html
Topics
Community Discussion
No community discussion yet for this question.