What Should Security Teams Do Before Guest Devices Access Corporate Resources?

Given a scenario, select mitigation techniques or controls to secure an enterprise environment. Given a scenario, apply security principles to secure enterprise infrastructure.
Answer Correct answer: B — Before quarantined guest devices access corporate resources, perform compliance attestation to verify patching, antivirus, and firewall compliance.

An administrator has configured a quarantine subnet for all guest devices that connect to the network. Which of the following would be best for the security team to perform before allowing access to corporate resources?

  1. Device fingerprinting
  2. Compliance attestation Correct Answer
  3. Penetration test
  4. Application vulnerability test

Community Votes

B
80%
A
20%

80% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests whether you can distinguish endpoint identification (fingerprinting) from endpoint posture verification (compliance attestation), with the trap being to pick fingerprinting because it sounds like a pre-access security check.

In a quarantine subnet for guest devices, compliance attestation is the control that verifies a device meets corporate security policy before it can reach protected resources. This page explains why B beats device fingerprinting, penetration testing, and application vulnerability testing for pre-access guest admission.

The most common wrong answer is A, device fingerprinting, because it identifies the device type and OS but does not confirm patching, antivirus, or firewall compliance required for corporate access.

Community Discussion (4 comments)

9149f41 👍 2 Selected: B
Complince Attestation: Guest devices have to meet the minimum requirement for the company. The requirement includes an up-to-date OS patch, applications that are downloaded to have a security patch, a configured firewall, a device name that meets company standards, etc.
jbmac 👍 2 Selected: B
The correct answer is: B. Compliance attestation Explanation: Compliance attestation is the best step for the security team to perform before allowing guest devices to access corporate resources. It involves ensuring that the devices meet specific security requirements or policies (e.g., having up-to-date antivirus software, applying security patches, or configuring firewalls). This is an essential part of network access control (NAC) and helps ensure that devices are compliant with the company's security standards before granting access to sensitive resources.
ProudFather 👍 4 Selected: B
Before allowing guest devices access to corporate resources, the security team should perform compliance attestation. Compliance attestation involves verifying that the guest device meets the organization's security policies and standards. This typically includes checks such as: Antivirus software: Is antivirus software installed and updated? Firewall: Is a firewall enabled and configured correctly? Operating system updates: Is the operating system up-to-date with the latest security patches? Other security controls: Does the device meet other security requirements, such as strong passwords and encryption? By performing compliance attestation, the security team can ensure that guest devices do not pose a significant security risk to the corporate network before granting them access to critical resources.
mohammad88 👍 2 Selected: A
Device fingerprinting. This means checking the type of device, its settings, and its software to make sure it’s a legitimate and safe device. It helps identify risky devices and prevent them from accessing sensitive company systems.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Compliance attestation is the best action because the quarantine subnet is a pre-access holding area, and the security team must verify that each guest device satisfies the organization's minimum security requirements before it can reach corporate resources. This is a network access control posture check: it can validate up-to-date OS patches, active antivirus, host firewall configuration, and other endpoint policy settings. The question asks what to perform before allowing access, and attestation directly gates that access on a compliance decision. Guest devices that fail attestation can remain quarantined or be remediated rather than being trusted by default.

Why the Other Options Are Wrong

Device fingerprinting identifies characteristics such as device type, operating system, or browser version, but it does not prove that the endpoint is patched or running required security controls. A penetration test assesses the security of systems and networks under controlled conditions; it is not a per-device admission check for guest endpoints. An application vulnerability test scans applications for weaknesses and similarly does not verify the security posture of a guest laptop or phone before corporate access. None of those options provides the policy-compliance decision that compliance attestation provides.

Community Comment Notes

ProudFather describes compliance attestation as verifying antivirus, firewall, and similar policy checks before guest access, which matches the quarantine-subnet scenario. 9149f41 adds that "Guest devices have to meet the minimum requirement for the company," including OS patches and configured firewalls. jbmac calls compliance attestation the best step before allowing corporate access, reinforcing the majority view. mohammad88 argues for device fingerprinting, but fingerprinting alone only identifies a device; it does not confirm that the device meets corporate security policy.

Official Reference

Exam Strategy

When a question places devices in a quarantine subnet and asks what to do before corporate access, look for the option that checks endpoint posture against policy rather than merely identifying the device. On SY0-701, compliance attestation is the NAC-style answer for conditional guest admission.

Frequently Asked Questions

Why is device fingerprinting not enough before guest devices access corporate resources?

Fingerprinting identifies the device type, OS, or browser, but it does not verify that patches, antivirus, or firewall settings meet corporate policy. Compliance attestation performs that policy check before access is granted.

Does compliance attestation apply to guest devices in a quarantine subnet?

Yes. A quarantine subnet is a pre-access holding area, so the security team should attest that each guest device satisfies minimum security requirements before allowing it to reach corporate resources.

More SY0-701 FAQ →

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide