Soru

Zorluk: OrtaZero Trust Architecture Principles

A renewable energy utility operates remote maintenance workstations connected to solar farm Supervisory Control and Data Acquisition (SCADA) controllers. Under the existing access model, once a field technician completes initial multi-factor authentication (MFA) at the start of their shift, the active network connection is granted persistent trust across all internal SCADA subnets. The organization wants to refactor this workflow to align with core Zero Trust Architecture principles. Which of the following implementation strategies best satisfies this requirement?

  1. A
    Establishing a hardened IPSec VPN tunnel that automatically trusts all internal network traffic routed to SCADA controllers once established.
  2. B
    Upgrading the initial user login process to include hardware token multi-factor authentication without altering ongoing session permission evaluations.
  3. Continuously evaluating user risk metrics and endpoint compliance signals before granting access to each subsequent SCADA resource.Cevap
  4. D
    Deploying detective security audit logs on SCADA endpoints to record technician actions post-shift for historical compliance verification.

Cevap

Continuously evaluating user risk metrics and endpoint compliance signals before granting access to each subsequent SCADA resource represents the correct implementation of Zero Trust principles.
Zero Trust Architecture eliminates implicit trust tied to network location or past authentication. By continuously evaluating contextual risk factors—such as user activity, endpoint security posture, and resource sensitivity—before granting access to specific assets, the system maintains strict explicit verification at all times.

Adım Adım Çözüm

1
Analyze the existing architecture weakness described in the scenario.
The current model relies on persistent, implicit trust across network subnets after an initial shift authentication.
Zero Trust Architecture explicitly forbids granting implicit trust based solely on initial authentication or network location.
2
Evaluate the architectural controls against Zero Trust core tenets.
Dynamic assessment of device posture, context, and user risk scores for every individual resource request removes implicit trust and enforces explicit verification continuously.
Zero Trust requires continuous authorization evaluations rather than one-time perimeter access.

Anahtar Kavram

Continuous explicit verification and elimination of implicit trust in Zero Trust Architecture
Bu soruyu puanla