easyMultiple ChoiceObjective-mapped
CISSP Practice Question: Is implementing a bring-your-own-device (BYOD)…
An organization is implementing a bring-your-own-device (BYOD) policy. Which security control should be enforced to ensure that only compliant devices can access corporate resources?
⚠ Common exam trap
Many exam-takers confuse authentication controls (like strong passwords or VPN) with device compliance enforcement, but NAC is the only option that actively checks and enforces a security posture before granting network access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing network access control (NAC)
Network access control (NAC) is the correct control because it evaluates device posture (e.g., OS patch level, antivirus status, disk encryption) against a compliance policy before granting network access. NAC can quarantine non-compliant devices to a remediation VLAN or deny access entirely, ensuring only trusted endpoints reach corporate resources. This is distinct from generic encryption or authentication controls, as NAC enforces a dynamic, policy-based admission decision at the network layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using a VPN concentrator
Why it's wrong here
While a VPN concentrator establishes a secure, encrypted tunnel for remote access, its primary function is secure communication, not endpoint security posture assessment. It does not inherently inspect the connecting device for malware, patch levels, or compliance with security policies before granting network access, making it insufficient for comprehensive BYOD security management on its own.
- ✗
Requiring strong passwords
Why it's wrong here
Requiring strong passwords is a fundamental security practice for user authentication, ensuring that only authorized individuals can access accounts or resources. However, strong passwords do not provide any mechanism to verify the security configuration, health, or compliance of the *device* itself. They protect user credentials, not the device's adherence to organizational BYOD security policies.
- ✓
Implementing network access control (NAC)
Why this is correct
Implementing Network Access Control (NAC) is the most effective solution for managing BYOD security by dynamically assessing the security posture of devices attempting to connect to the network. NAC verifies device compliance with organizational policies, checking for up-to-date antivirus, patch levels, and configuration settings before granting or restricting network access. This allows for granular control and automated remediation, ensuring only healthy and compliant devices can access corporate resources.
- ✗
Enabling full disk encryption
Why it's wrong here
Enabling full disk encryption (FDE) is a critical control for protecting data at rest on a device, rendering information unreadable if the device is lost or stolen. However, FDE does not actively monitor or enforce the device's security posture or compliance *at the point of network access*. It secures stored data but does not verify the operating system's health, running processes, or adherence to access policies in real-time.
Visual reference
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Compliance policy
A compliance policy is a set of rules that ensures devices, users, and applications meet an organization's security and regulatory requirements before they can access corporate resources.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.