Soru

Zorluk: ZorZero Trust Architecture Principles

A logistics enterprise is migrating its fleet tracking telemetry infrastructure to a Zero Trust Architecture (ZTA). The security team is defining architecture baseline policies for API communication between edge gateway devices and core analytical microservices. Which of the following technical requirements directly align with core Zero Trust Architecture principles? (Select TWO).

  1. Continuously re-evaluate device security posture and request behavior for every API transaction, regardless of network location.Cevap
  2. B
    Grant persistent implicit trust to telemetry devices once initial mutual TLS authentication is successfully established inside the private network boundary.
  3. Enforce microsegmentation and dynamic access controls so edge devices are restricted to the minimal resources necessary for their specific function.Cevap
  4. D
    Treat strong cryptographic authentication mechanisms as automatically granting permission to access all microservices across the telemetry plane.

Cevap

The correct requirements are to continuously re-evaluate device security posture and request behavior for every API transaction regardless of network location, and to enforce microsegmentation and dynamic access controls so edge devices are restricted to the minimal resources necessary for their specific function.
Zero Trust Architecture (ZTA) eliminates implicit network perimeter trust by mandating continuous explicit verification of every transaction (evaluating security posture, location, and behavior) and applying least privilege through microsegmentation to isolate workloads and minimize blast radius.

Adım Adım Çözüm

1
Analyze core tenets of Zero Trust Architecture (ZTA).
ZTA operates under an assumed breach mindset, requiring continuous explicit verification and strict least privilege.
Traditional perimeter-based implicit trust models must be abandoned in favor of dynamic context evaluation.
2
Evaluate requirement for continuous context validation.
Every API request must be continuously authenticated and authorized based on dynamic context metrics.
Re-evaluating posture and request behavior prevents compromised endpoints from abusing persistent session trust.
3
Evaluate requirement for microsegmentation and least privilege access.
Access must be restricted granularly to only the exact microservice endpoints required for the gateway's role.
Microsegmentation prevents lateral movement across microservices if an edge device is compromised.

Anahtar Kavram

Zero Trust Architecture Principles: Continuous Explicit Verification and Microsegmentation Least Privilege
Bu soruyu puanla