Why does re-checking NAC posture during a session cost you, and what does never re-checking hand an intruder?
answer
- a pass is a timestamp, not a state
- the session outlives the check
- re-auth timer versus agent reassessment
- mass re-check equals mass quarantine
- nobody owns the interval
basics
~20 sA health check run at admission proves only that the device satisfied policy at that instant. Re-checking costs mid-session churn and support load; never re-checking leaves an authorization granted months ago standing over a device an intruder took last week.
solid answer
~50 sThe check is evaluated when the session is authorized, and that authorization then persists — through the working day, through sleep and resume in many designs, until a re-authentication timer fires or the link drops. So a compliant verdict is a timestamp, not a property: it says a check passed then. Re-evaluation exists — a re-auth interval, or an agent-driven reassessment that makes the policy server push a change-of-authorization — but every re-evaluation can move a working user into quarantine mid-task, and a policy change that raises the bar fails thousands of sessions at once, arriving at the service desk as a network outage. That is why nobody wants to own the interval. The cost of not owning it is that a device compromised after admission keeps its full production authorization, and the control never re-examines the one device that changed.
go deeper
Know that the health check happens when the device joins and that the resulting access lasts for the session. Be able to say that passing once is not the same as being healthy now.
Explain both re-evaluation paths — a re-authentication timer and agent-driven reassessment with a change-of-authorization — and what each costs in policy-server load and mid-session disruption.
Demonstrate that you would stage a stricter health policy in audit-only mode, size quarantine and the remediation path for the failure wave, and name who owns the interval.
Be ready to argue what the estate is really buying: a joining-time gate, not a continuous assurance, and where the money should go if continuous assurance is what the business was promised.
## Where the check sits in the session Admission is a single event. The device authenticates, a health evaluation runs, and the policy server returns an authorization — a segment, a filter, or both — which the switch installs on the port for the life of the session. Everything after that is the session, not the check. The session ends when the link drops, when a re-authentication timer expires, or when the policy server tears it down. Unless something re-runs the evaluation, the verdict from admission is still the verdict at hour nine. ## What a passing verdict actually asserts This is the direction-of-claim error the topic exists to correct. A pass asserts: *at the moment of admission, the signals the policy asked for came back satisfying it.* It does not assert that the device is healthy now, that it stayed healthy, or that the same person is using it. A senior candidate who says 'NAC guarantees only compliant devices are on the network' has stated something the mechanism cannot support, and the gap is time. ## The two ways to re-evaluate, and what each costs **Periodic re-authentication.** The switch re-runs authentication on an interval; the policy server re-decides and re-installs authorization. Cheap to configure, blunt in effect: it re-checks every device on the same clock whether anything changed or not, and it produces a load spike on the policy server proportional to the estate divided by the interval. Set it short and the server sizing becomes the constraint; set it long and it is decorative. **Reassessment driven by the health agent.** The agent re-evaluates on its own schedule or on a state change and reports; the policy server responds with a change-of-authorization that swaps the session's authorization in place. Much more targeted, and it can move a device to quarantine without ending the session. But it depends on an agent you control, which on a partner-owned or contractor laptop you frequently do not, and a device whose agent has stopped reporting looks exactly like a device that is fine. ## Why the interval is politically hard Every re-evaluation that returns a failure is somebody being moved into a restricted segment while they are working. On an estate where quarantine is well built, that is an inconvenience. On an estate where quarantine barely reaches the update service, it is an outage for that user. Now consider a policy change — a new minimum agent version, a new required update — applied to a fleet on reassessment: hundreds or thousands of sessions fail within minutes and land in a segment sized for a handful. The correct handling is to stage the policy in an audit-only mode first, measure how many devices *would* fail, fix the fleet, and only then enforce; and to make the reassessment interval a decision with a named owner rather than a default nobody has looked at since deployment. ## What the gap hands an adversary Two distinct gifts. First, persistence: an intruder who takes a device that passed months ago inherits its production authorization, and nothing in the admission control will ever look at that device again while the session lives. The control's guarantee was always about the moment of joining, and the adversary operates entirely after it. Second, a shaped opportunity: an adversary who understands that reassessment is off knows the health signal is a one-time toll, not a continuous condition, so degrading the device after admission — stopping the agent, disabling updates — carries no network consequence at all. ## How to answer it well Say what the check proves, say that the session outlives it, name the two re-evaluation mechanisms, and then price them honestly: server load and mid-session quarantine on one side, an unbounded stale authorization on the other. The interview is not looking for 're-check every five minutes'; it is looking for someone who knows that choosing the interval means choosing who gets quarantined mid-call, and who has an answer for who signs that decision.
- What is the difference between a re-authentication timer and a posture reassessment?The timer re-runs authentication on the switch's schedule and re-installs whatever authorization the policy server now returns — blunt, estate-wide, and load-proportional to the interval. Reassessment is the health agent re-evaluating and reporting, with the policy server pushing a change-of-authorization for that one session. The first needs no agent; the second is targeted but only exists where you control the endpoint software.
- Why can raising the health policy be an outage rather than a tightening?Because it is applied to live sessions at reassessment. A new minimum agent or update version can fail thousands of devices within minutes, all of which land in a segment sized for a trickle and reach a remediation path sized for the same. Stage the policy in audit-only mode first, count how many devices would fail, fix the fleet, and enforce afterwards.
- A device has not produced a health failure in three months. What does that tell you?On its own, nothing about the device's health. It is equally consistent with a fleet that is genuinely current, with reassessment being disabled or set to an interval longer than any session, or with an agent that stopped reporting and whose silence is read as success. Confirm which by checking that failures are being produced somewhere, not by trusting the absence.
saying these in an interview costs you the question
- Treats a compliant verdict as a continuing property of the device
- Assumes the check runs continuously because an agent is installed
- Proposes a very short re-check interval with no thought to who gets quarantined mid-call
- Says NAC guarantees only healthy devices are ever on the network
- Rolls out a stricter health policy straight to enforcement with no audit-only stage
- Reads a silent agent as a passing device