Soru

Zorluk: OrtaZero Trust Architecture Principles

A fintech enterprise is redesigning its transactional API gateway and core internal services to align with Zero Trust Architecture (ZTA) principles. Under the legacy model, any service deployed within the internal management network zone was implicitly trusted to execute database queries. Which of the following access enforcement strategies best reflects the core Zero Trust principle of explicit verification for internal service communication?

  1. Requiring every service transaction to be explicitly authenticated, authorized, and encrypted using context-aware inspection regardless of network locationCevap
  2. B
    Granting database privileges automatically to any internal request originating from a recognized management VLAN subnet
  3. C
    Treating user identity authentication as sufficient confirmation for system-level data access permissions without evaluating contextual authorization policies
  4. D
    Reclassifying internal access enforcement mechanisms as post-incident detective controls to avoid latency during API execution

Cevap

Requiring every service transaction to be explicitly authenticated, authorized, and encrypted using context-aware inspection regardless of network location
Zero Trust Architecture operates on the core principle of 'never trust, always verify.' In a ZTA model, network location provides no inherent trust. Every access request—even those originating within internal subnets—must be explicitly authenticated, authorized against context-aware policy, and encrypted end-to-end.

Adım Adım Çözüm

1
Identify the core tenet of Zero Trust Architecture (ZTA) regarding network trust boundaries.
ZTA operates under the assumption that network location does not imply trust, eliminating implicit trust for internal segments.
Traditional perimeter security relies on location-based trust, whereas ZTA requires continuous validation regardless of origin.
2
Evaluate the requirement for explicit verification across internal service transactions.
Every access request must be explicitly authenticated, authorized within context, and encrypted end-to-end.
Explicit verification ensures least privilege and continuous evaluation for all data flows.

Anahtar Kavram

Explicit verification and removal of implicit network perimeter trust in Zero Trust Architecture
Tahmini Süre:1m 30s
Bu soruyu puanla