What Should Security Teams Do Before Guest Devices Access Corporate Resources?
An administrator has configured a quarantine subnet for all guest devices that connect to the network. Which of the following would be best for the security team to perform before allowing access to corporate resources?
Community Votes
80% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests whether you can distinguish endpoint identification (fingerprinting) from endpoint posture verification (compliance attestation), with the trap being to pick fingerprinting because it sounds like a pre-access security check.
In a quarantine subnet for guest devices, compliance attestation is the control that verifies a device meets corporate security policy before it can reach protected resources. This page explains why B beats device fingerprinting, penetration testing, and application vulnerability testing for pre-access guest admission.
The most common wrong answer is A, device fingerprinting, because it identifies the device type and OS but does not confirm patching, antivirus, or firewall compliance required for corporate access.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Compliance attestation is the best action because the quarantine subnet is a pre-access holding area, and the security team must verify that each guest device satisfies the organization's minimum security requirements before it can reach corporate resources. This is a network access control posture check: it can validate up-to-date OS patches, active antivirus, host firewall configuration, and other endpoint policy settings. The question asks what to perform before allowing access, and attestation directly gates that access on a compliance decision. Guest devices that fail attestation can remain quarantined or be remediated rather than being trusted by default.Why the Other Options Are Wrong
Device fingerprinting identifies characteristics such as device type, operating system, or browser version, but it does not prove that the endpoint is patched or running required security controls. A penetration test assesses the security of systems and networks under controlled conditions; it is not a per-device admission check for guest endpoints. An application vulnerability test scans applications for weaknesses and similarly does not verify the security posture of a guest laptop or phone before corporate access. None of those options provides the policy-compliance decision that compliance attestation provides.Community Comment Notes
ProudFather describes compliance attestation as verifying antivirus, firewall, and similar policy checks before guest access, which matches the quarantine-subnet scenario. 9149f41 adds that "Guest devices have to meet the minimum requirement for the company," including OS patches and configured firewalls. jbmac calls compliance attestation the best step before allowing corporate access, reinforcing the majority view. mohammad88 argues for device fingerprinting, but fingerprinting alone only identifies a device; it does not confirm that the device meets corporate security policy.Official Reference
Exam Strategy
When a question places devices in a quarantine subnet and asks what to do before corporate access, look for the option that checks endpoint posture against policy rather than merely identifying the device. On SY0-701, compliance attestation is the NAC-style answer for conditional guest admission.
Frequently Asked Questions
Why is device fingerprinting not enough before guest devices access corporate resources?
Fingerprinting identifies the device type, OS, or browser, but it does not verify that patches, antivirus, or firewall settings meet corporate policy. Compliance attestation performs that policy check before access is granted.
Does compliance attestation apply to guest devices in a quarantine subnet?
Yes. A quarantine subnet is a pre-access holding area, so the security team should attest that each guest device satisfies minimum security requirements before allowing it to reach corporate resources.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →