Soru

Zorluk: OrtaZero Trust Architecture Principles

An enterprise logistics organization is re-architecting its cloud-native platform to comply with NIST SP 800-207 Zero Trust Architecture (ZTA) principles. Which of the following architectural practices must be implemented to establish core Zero Trust controls across the environment? (Select TWO.)

  1. Enforce explicit authentication and authorization for every access request, utilizing dynamic context such as identity, device state, and location regardless of network position.Cevap
  2. B
    Grant automatic trust to internal inter-service traffic once packets cross the edge virtual private network (VPN) gateway.
  3. Implement microsegmentation and end-to-end session encryption between workload components to minimize the blast radius of potential compromises.Cevap
  4. D
    Treat initial successful multi-factor authentication as sufficient to grant continuous access permissions for the full duration of a active session.

Cevap

The core architectural practices required are explicitly verifying every access request using dynamic risk context, and implementing microsegmentation with end-to-end encryption between workload components to contain lateral movement.
Zero Trust Architecture requires explicit verification of every access request using dynamic contextual signals (identity, device posture, location) regardless of network origin, combined with granular microsegmentation and encryption between internal services to assume breach and limit lateral movement.

Adım Adım Çözüm

1
Identify fundamental Zero Trust Architecture (ZTA) tenets
ZTA relies on assuming breach, explicitly verifying all connections, enforcing least privilege, and continuously monitoring access context.
Implicit network trust based on physical location or static perimeters must be removed.
2
Map tenets to enterprise workload controls
Verifying each request dynamically (explicit verification) and segmenting internal workload flows (microsegmentation) directly enact these tenets.
These controls restrict access to authorized subjects and limit lateral movement if a workload is compromised.

Anahtar Kavram

Zero Trust Architecture Principles
Tahmini Süre:1m 30s
Bu soruyu puanla