An enterprise logistics organization is re-architecting its cloud-native platform to comply with NIST SP 800-207 Zero Trust Architecture (ZTA) principles. Which of the following architectural practices must be implemented to establish core Zero Trust controls across the environment? (Select TWO.)
- Enforce explicit authentication and authorization for every access request, utilizing dynamic context such as identity, device state, and location regardless of network position.Cevap
- BGrant automatic trust to internal inter-service traffic once packets cross the edge virtual private network (VPN) gateway.
- Implement microsegmentation and end-to-end session encryption between workload components to minimize the blast radius of potential compromises.Cevap
- DTreat initial successful multi-factor authentication as sufficient to grant continuous access permissions for the full duration of a active session.
Cevap
The core architectural practices required are explicitly verifying every access request using dynamic risk context, and implementing microsegmentation with end-to-end encryption between workload components to contain lateral movement.
Zero Trust Architecture requires explicit verification of every access request using dynamic contextual signals (identity, device posture, location) regardless of network origin, combined with granular microsegmentation and encryption between internal services to assume breach and limit lateral movement.
Adım Adım Çözüm
Anahtar Kavram
Zero Trust Architecture Principles
Tahmini Süre:1m 30s