N10-009 exam dumps

N10-009 practice question 244 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 244

Single answer4.1 Explain the importance of basic network security concepts.

A company allows employees to connect personal smartphones and tablets to the corporate Wi-Fi for email and internal web applications. After a recent incident, the network administrator discovers that several employee-owned devices are missing security updates and one infected device attempted to scan internal servers after connecting. Management wants to continue allowing personal devices but reduce the risk of compromised endpoints accessing sensitive internal resources. Which solution would BEST address this requirement?

  1. A

    Implement network access control (NAC) to validate device security posture before granting the device appropriate network access

  2. B

    Disable SSID broadcasting on the wireless network so unauthorized devices cannot find the corporate Wi-Fi

  3. C

    Configure port security on the wireless access points to limit the number of MAC addresses learned per port

  4. D

    Replace WPA2-Enterprise with WPA2-Personal so employees can connect more easily with a shared passphrase

Show answer and explanation

Correct answer: A

Explanation

The best answer is to implement network access control (NAC), because the scenario focuses on reducing risk from BYOD devices that may be unpatched or compromised while still allowing those devices to connect. NAC is a core network security concept because it enforces policy at the point of access, often integrating with authentication services, posture assessment, and network segmentation. In practice, NAC solutions can check whether a device meets minimum security requirements and then assign access based on compliance status. This aligns with common enterprise best practices of least privilege, segmentation, and conditional access. Guidance from organizations such as NIST supports controlling device access based on security posture and limiting access for unmanaged or noncompliant devices, particularly in BYOD environments.

  • A. Correct.

    Correct. Network access control (NAC) is designed to evaluate endpoint posture, such as patch level, antivirus status, or device compliance, before allowing full network access. In a BYOD environment, NAC can place noncompliant devices into a guest or remediation VLAN, or block them entirely. This directly addresses the problem of vulnerable or infected personal devices reaching sensitive internal systems.

  • B. Incorrect.

    Incorrect. Disabling SSID broadcasting provides little real security benefit because the network can still be discovered through wireless analysis tools and client probe traffic. It does not assess whether a device is patched, infected, or otherwise safe to connect. This is a common misconception that obscuring a network name meaningfully improves security.

  • C. Incorrect.

    Incorrect. Port security is primarily a switch feature used on wired networks to limit MAC addresses on a physical switchport. It is not the best control for evaluating the security health of employee-owned wireless endpoints. Even if an infrastructure component supports MAC limits, that would not verify patching, malware status, or compliance.

  • D. Incorrect.

    Incorrect. WPA2-Personal uses a shared pre-shared key, which reduces accountability and generally weakens enterprise security compared to WPA2-Enterprise with individual authentication. Moving to a shared passphrase would make access control and auditing harder and would not prevent insecure or infected BYOD devices from connecting.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam