Soru

Zorluk: OrtaZero Trust Architecture Principles

A maritime shipping container logistics terminal is modernizing its operational technology (OT) network and port management systems. The security architecture team is adopting Zero Trust Architecture (ZTA) principles to prevent unauthorized access between automated gantry crane control systems, IoT tracking sensors, and cloud management consoles. Which of the following architectural requirements represent core tenets of Zero Trust Architecture that must be implemented in this design? (Select TWO.)

  1. Treat all network traffic as inherently untrusted regardless of whether the source originates from inside or outside the physical enterprise perimeter.Cevap
  2. Dynamically evaluate and continuously verify trust factors and security posture throughout the entirety of an active session.Cevap
  3. C
    Grant full implicit trust to internal subnets once traffic passes initial perimeter firewall and site-to-site VPN authentication.
  4. D
    Eliminate distinct resource authorization checks whenever mutual TLS (mTLS) authentication successfully verifies device identities.

Cevap

The core tenets of Zero Trust Architecture include assuming no implicit trust based on network location (treating all traffic as untrusted regardless of origin) and continuously re-evaluating trust and posture dynamically throughout active sessions.
Zero Trust Architecture relies on the tenets of 'never trust, always verify' and 'assume breach'. Traffic originating from internal subnets must be treated with the same scrutiny as external traffic. Furthermore, access decisions are dynamic and subjected to continuous verification during active sessions rather than relying on a single login event.

Adım Adım Çözüm

1
Analyze core principles of Zero Trust Architecture (NIST SP 800-207)
Identified that Zero Trust mandates explicit verification, assumed breach, least privilege access, and continuous monitoring regardless of network location.
Traditional perimeter-based security models fail when internal networks are assumed to be safe.
2
Evaluate the requirement for perimeter-independent trust management
Selecting the requirement to treat all traffic as untrusted regardless of origin aligns directly with the 'assume breach' and 'explicit verification' tenets.
Location within an enterprise network does not guarantee security or non-malicious behavior.
3
Evaluate continuous authentication vs. static initial checks
Selecting continuous dynamic posture evaluation ensures sessions are reassessed continuously as contextual risk attributes change.
Initial authentication checks cannot detect mid-session compromises or device posture degradation.

Anahtar Kavram

Zero Trust Architecture Principles
Bu soruyu puanla