🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An enterprise is deploying several hundred Windows 11 laptops, each equipped with TPM 2.0. The network team wants to ensure that only company-owned laptops can obtain access to the wired 802.1X LAN, even if an attacker learns a valid employee username and password. The solution must require little or no user interaction after initial enrollment. Which device authentication method BEST meets these goals?

  • Enable MAC address filtering on access switches and allow only the NIC addresses of corporate laptops.

  • Implement PEAP authentication that requires users to enter their Active Directory credentials when connecting to the wired network.

  • Use EAP-TLS with machine certificates whose private keys are stored in each laptop's TPM, validated by the RADIUS server during 802.1X authentication.

  • Assign every switch port to a restricted guest VLAN unless the first connected MAC address remains unchanged for the session.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot