CompTIA Security+ (SY0-501) — Question 714
A security administrator is adding a NAC requirement for all VPN users to ensure the connecting devices are compliant with company policy. Which of the following items provides the HIGHEST assurance to meet this requirement?
Answer options
- A. Implement a permanent agent.
- B. Install antivirus software.
- C. Use an agentless implementation.
- D. Implement PKI.
Correct answer: A
Explanation
Implementing a permanent agent ensures continuous compliance monitoring and enforcement on connecting devices, providing the highest assurance. In contrast, installing antivirus software is just one aspect of compliance and may not cover all policy requirements. An agentless implementation lacks the ability to enforce real-time compliance, while PKI primarily focuses on identity and encryption rather than device compliance.