An enterprise security team is implementing a Zero Trust Identity and Access Management (IAM) architecture. The team needs to ensure that access to cloud resources is dynamically granted or restricted based on real-time signals, such as user risk level, device health state, and geographic location, rather than relying solely on static group memberships or initial password verification. Which of the following IAM architectural mechanisms should the team implement to satisfy this requirement?
- Context-aware access policiesCevap
- BRole-Based Access Control (RBAC)
- CFederated Single Sign-On (SSO)
- DMandatory Access Control (MAC)
Cevap
Context-aware access policies
Context-aware access policies evaluate real-time signals—such as user IP location, device security posture, and behavioral risk scores—to dynamically enforce granular access controls in alignment with Zero Trust architecture principles.
Adım Adım Çözüm
Anahtar Kavram
Context-Aware Conditional Access in IAM Architecture