Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 66 discussion

Actual exam question from ISC's CISSP
Question #: 66
Topic #: 1
[All CISSP Questions]

An organization has implemented a protection strategy to secure the network from unauthorized external access. The new Chief Information Security Officer
(CISO) wants to increase security by better protecting the network from unauthorized internal access. Which Network Access Control (NAC) capability BEST meets this objective?

  • A. Port security
  • B. Two-factor authentication (2FA)
  • C. Strong passwords
  • D. Application firewall
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
DERCHEF2009
Highly Voted 2 years, 2 months ago
Selected Answer: A
NAC = Port Security
upvoted 22 times
...
BDSec
Highly Voted 2 years, 2 months ago
“Internal access” is key here. Port security.
upvoted 9 times
cccispman
1 year, 10 months ago
You correctly identify 'internal access' as being key and I agree with you ! But ... Port 22 is routine open internally for legitimate access. 2FA is standard practice these days for securing access to network infrastructure.
upvoted 2 times
...
dev46
2 years, 2 months ago
Correct
upvoted 3 times
...
...
somsom
Most Recent 1 month ago
Always check the protocol involved it will help
upvoted 1 times
...
somsom
1 month ago
It read a NAC the answer is port security . Two factor is part of cloud security .
upvoted 1 times
...
deeden
3 months, 2 weeks ago
Selected Answer: B
In this context, I think Port security is a network security feature that restricts access to a network port by limiting the number of MAC addresses allowed on a specific port. It's a layer-2 security mechanism that helps prevent unauthorized devices from accessing the network. This focus more on unauthorized external access. Unauthorized internal access is more likely would be coming from insider threats e.g., a disgruntled employee, or social engineering attack, contractors, etc.
upvoted 1 times
...
Rachy
4 months, 1 week ago
Selected Answer: B
To increase the vote and not confuse people, I will go for B anytime any day. Port security is for external access control
upvoted 1 times
...
Ramye
6 months, 1 week ago
The objective of this question “protecting the network from unauthorized internal access” and to satisfy this requirements it is most likely 2FA ( MFA ). 2FA / MFA will be used for Authentication / Authorization, hence the answer is: B
upvoted 1 times
...
MP26
7 months, 1 week ago
MFA is not a capability of a NAC. So it should be A:
upvoted 1 times
...
marziparzi
7 months, 2 weeks ago
This says "An organization has implemented a protection strategy to secure the network from unauthorized external access." If it didn't say that I would have leaned to 2FA. But 2FA is relevant for both external and internal. We need to find something that's exclusive to internal. That's why I think it's Port security
upvoted 1 times
...
Hongjun
8 months, 3 weeks ago
Selected Answer: B
The key word - increase . The question told us that control already been implemented. Now they want to increase. B is increase which from 1 to 2 ACD are all basic control which is from 0 to 1.
upvoted 2 times
...
IntheZone
10 months, 1 week ago
Selected Answer: B
While Port security is good, 2FA is better as there are two steps to bypass. Also for port security, MAC spoofing is a thing which makes me doubt this could be the right answer
upvoted 1 times
...
AMANSUNAR
1 year ago
Selected Answer: A
Port security is a Network Access Control (NAC) feature that controls access to a network by limiting the number of devices that can be connected to a switch port. It helps prevent unauthorized devices from gaining access to the internal network by ensuring that only authorized devices are allowed to connect to specific network ports.
upvoted 1 times
...
InclusiveSTEAM
1 year, 1 month ago
Correction: The answer is B The NAC capability that would best help protect the network from unauthorized internal access is B - Two-factor authentication (2FA). Enforcing 2FA requires authorized users to provide an additional verification factor when accessing the network from internal locations. This enhances security beyond just passwords. Port security, strong passwords, and application firewalls help against external threats but don't directly address internal users.
upvoted 1 times
...
InclusiveSTEAM
1 year, 1 month ago
The answer is A The NAC capability that would best help protect the network from unauthorized internal access is B - Two-factor authentication (2FA). Enforcing 2FA requires authorized users to provide an additional verification factor when accessing the network from internal locations. This enhances security beyond just passwords. Port security, strong passwords, and application firewalls help against external threats but don't directly address internal users.
upvoted 1 times
...
Moose01
1 year, 1 month ago
hints - port security is so the NAC can authenticate the devices - MFA is for user to authenticate.
upvoted 1 times
...
Sledge_Hammer
1 year, 2 months ago
B. Two-factor authentication (2FA) is the correct answer
upvoted 1 times
...
Bach1968
1 year, 4 months ago
Selected Answer: B
Option B (Two-factor authentication) can indeed be an effective Network Access Control (NAC) capability to better protect the network from unauthorized internal access. Two-factor authentication adds an extra layer of security by requiring users to provide two different types of authentication factors, such as a password and a unique code sent to their mobile device, before gaining access to the network. By implementing two-factor authentication, even if an unauthorized individual gains access to a user's credentials (e.g., username and password), they would still need the second factor (e.g., the code sent to the user's mobile device) to successfully authenticate and gain access to the network. This helps mitigate the risk of unauthorized internal access, even if internal credentials are compromised. Therefore, both options A (Port security) and B (Two-factor authentication) can be valid choices to increase security and protect the network from unauthorized internal access. The choice between the two would depend on the specific requirements and context of the organization's network environment.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...