SSCP Network and Communications Security Practice Question
A security engineer is implementing a Network Access Control (NAC) solution to enforce endpoint compliance before allowing devices onto the corporate network. Which TWO of the following are common NAC enforcement methods? (Choose two.)
⚠ Common exam trap
The trap here is assuming that any access control mechanism, such as MAC filtering, qualifies as NAC, but NAC specifically involves authentication and posture assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
802.1X with RADIUS authentication
Common NAC enforcement methods include 802.1X with RADIUS authentication and captive portals with posture assessment. 802.1X provides port-based access control using authentication, while captive portals redirect users to a web page for authentication and compliance checks. Both methods can enforce endpoint compliance before granting network access. DHCP snooping, VLAN hopping prevention, and MAC filtering are security features but do not provide the identity and posture assessment typical of NAC.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
802.1X with RADIUS authentication
Why this is correct
802.1X is a port-based network access control standard that uses RADIUS for authentication. It is a common NAC enforcement method, allowing or denying network access based on credentials and endpoint posture. When a device connects, the switch port remains unauthorized until authentication succeeds. This method is widely used in enterprise NAC deployments to enforce compliance and identity-based access.
- ✗
VLAN hopping prevention
Why it's wrong here
VLAN hopping prevention is a security measure to stop attackers from sending traffic to other VLANs by exploiting trunking or double tagging. It is not a NAC enforcement method. NAC focuses on controlling access based on identity and compliance, not on preventing VLAN hopping. While important, it does not authenticate devices or enforce endpoint policies.
- ✗
MAC address filtering
Why it's wrong here
MAC address filtering allows or denies access based on the device's MAC address. It is not considered a robust NAC enforcement method because MAC addresses can be easily spoofed. NAC solutions require stronger authentication and posture assessment. MAC filtering lacks the ability to verify user identity or endpoint health, making it insufficient for modern NAC requirements.
- ✓
Captive portal with posture assessment
Why this is correct
A captive portal redirects users to a web page for authentication and can perform endpoint posture checks before granting access. It is a common NAC enforcement method, especially for guest networks or BYOD. The portal can assess device compliance, such as antivirus status or patch level, and then allow, deny, or remediate access. This method is flexible and does not require supplicant software on the endpoint.
- ✗
DHCP snooping with IP source guard
Why it's wrong here
DHCP snooping with IP source guard are Layer 2 security features that prevent rogue DHCP servers and IP spoofing. While they enhance network security, they are not NAC enforcement methods themselves. NAC typically involves authentication and posture assessment to control access. These features do not authenticate users or check endpoint compliance; they filter traffic based on DHCP bindings and IP-MAC mappings.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.