As the devices are not enrolled to the domain and do not have policies applied to them, which of the following are best practices for authentication and infrastructure security?

A cybersecurity administrator needs to allow mobile BYOD devices to access network resources.

As the devices are not enrolled to the domain and do not have policies applied to them, which of the following are best practices for authentication and infrastructure security? (Select TWO).
A . Create a new network for the mobile devices and block the communication to the internal network and servers
B . Use a captive portal for user authentication.
C . Authenticate users using OAuth for more resiliency
D . Implement SSO and allow communication to the internal network
E . Use the existing network and allow communication to the internal network and servers.
F . Use a new and updated RADIUS server to maintain the best solution

Answer: B, C

Explanation:

When allowing mobile BYOD devices to access network resources, using a captive portal for user authentication and authenticating users using OAuth are both best practices for authentication and infrastructure security. A captive portal requires users to authenticate before accessing the network and can be used to enforce policies and restrictions. OAuth allows users to authenticate using third-party providers, reducing the risk of password reuse and credential theft.

Reference: CompTIA Security+ Study Guide, pages 217-218, 225-226

Latest SY0-601 Dumps Valid Version with 396 Q&As

Latest And Valid Q&A | Instant Download | Once Fail, Full Refund

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments