Remote staff authenticate with MFA, yet unmanaged personal laptops freely reach the tax-system VPN. What gap should the access design close?
Select an answer to reveal the explanation.
Short Explanation
Knowing it is Alice is not the same as knowing it is Alice's city-managed laptop. Add device auth or posture—certs, MDM compliance—so random home PCs do not waltz into the tax VPN.
Full Explanation
Authentication strategy should address devices as well as people when sensitive resources demand trusted endpoints. Device certificates, MDM compliance, or NAC/posture checks prevent sole reliance on user MFA from unmanaged machines. Longer passwords, CAPTCHAs, or publishing VPN secrets do not establish device trust.