QuestionQ12

Security Operations

A company implemented a new NAC solution based on 802.1X. However, the IT support team notices that some devices are not being enrolled in the new policies, causing access disruptions for key users. Which of the following solutions will most likely solve this issue and prevent reoccurrence?

Explanation

Devices fail to enroll in 802.1X NAC most often because they lack a valid supplicant/monitoring agent or an up-to-date machine certificate; folding certificate issuance and agent deployment into the existing patch/update management workflow ensures every corporate device is automatically kept current and enrolled, which both fixes the immediate disruption and prevents it from recurring. Manually re-enrolling only the currently affected devices (option C) or manually deploying certificates (option B) are one-time fixes that do not stop the problem from happening again, and using default credentials (option D) undermines the security of the NAC deployment.

Community Discussion

No comments yet. Be the first to start the discussion!