Courseiva

SSCP Network and Communications Security Practice Question

A security engineer is implementing a Network Access Control (NAC) solution to enforce endpoint compliance before allowing devices onto the corporate network. Which TWO of the following are common NAC enforcement methods? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any access control mechanism, such as MAC filtering, qualifies as NAC, but NAC specifically involves authentication and posture assessment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

802.1X with RADIUS authentication

Common NAC enforcement methods include 802.1X with RADIUS authentication and captive portals with posture assessment. 802.1X provides port-based access control using authentication, while captive portals redirect users to a web page for authentication and compliance checks. Both methods can enforce endpoint compliance before granting network access. DHCP snooping, VLAN hopping prevention, and MAC filtering are security features but do not provide the identity and posture assessment typical of NAC.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    802.1X with RADIUS authentication

    Why this is correct

    802.1X is a port-based network access control standard that uses RADIUS for authentication. It is a common NAC enforcement method, allowing or denying network access based on credentials and endpoint posture. When a device connects, the switch port remains unauthorized until authentication succeeds. This method is widely used in enterprise NAC deployments to enforce compliance and identity-based access.

  • ✗

    VLAN hopping prevention

    Why it's wrong here

    VLAN hopping prevention is a security measure to stop attackers from sending traffic to other VLANs by exploiting trunking or double tagging. It is not a NAC enforcement method. NAC focuses on controlling access based on identity and compliance, not on preventing VLAN hopping. While important, it does not authenticate devices or enforce endpoint policies.

  • ✗

    MAC address filtering

    Why it's wrong here

    MAC address filtering allows or denies access based on the device's MAC address. It is not considered a robust NAC enforcement method because MAC addresses can be easily spoofed. NAC solutions require stronger authentication and posture assessment. MAC filtering lacks the ability to verify user identity or endpoint health, making it insufficient for modern NAC requirements.

  • ✓

    Captive portal with posture assessment

    Why this is correct

    A captive portal redirects users to a web page for authentication and can perform endpoint posture checks before granting access. It is a common NAC enforcement method, especially for guest networks or BYOD. The portal can assess device compliance, such as antivirus status or patch level, and then allow, deny, or remediate access. This method is flexible and does not require supplicant software on the endpoint.

  • ✗

    DHCP snooping with IP source guard

    Why it's wrong here

    DHCP snooping with IP source guard are Layer 2 security features that prevent rogue DHCP servers and IP spoofing. While they enhance network security, they are not NAC enforcement methods themselves. NAC typically involves authentication and posture assessment to control access. These features do not authenticate users or check endpoint compliance; they filter traffic based on DHCP bindings and IP-MAC mappings.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.