Soru

Zorluk: OrtaZero Trust Architecture Principles

A pharmaceutical enterprise has implemented a Zero Trust Architecture (ZTA) to secure access to proprietary clinical research data. During an active database session initiated via multi-factor authentication, the remote endpoint's client security agent reports that host firewall services were unexpectedly disabled. Which of the following actions best reflects the core tenets of Zero Trust in this scenario?

  1. A
    The access control system maintains the active database connection unimpeded because initial identity authentication established session validity until token expiration.
  2. The Policy Decision Point (PDP) re-evaluates the asset's dynamic trust score using telemetry and signals the Policy Enforcement Point (PEP) to alter or terminate session permissions.Cevap
  3. C
    The network firewall relies on the established VPN tunnel to implicitly trust internal database queries from authenticated remote IP addresses.
  4. D
    The intrusion prevention system automatically reclassifies the database access control policies from preventive controls into detective audit controls.

Cevap

The Policy Decision Point (PDP) re-evaluates the asset's dynamic trust score using telemetry and signals the Policy Enforcement Point (PEP) to alter or terminate session permissions.
In Zero Trust Architecture, access decisions are dynamic and subject to continuous verification. When endpoint compliance degrades mid-session, host telemetry alerts the Policy Decision Point (PDP) to re-evaluate the risk score and instruct the Policy Enforcement Point (PEP) to modify or terminate the active session.

Adım Adım Çözüm

1
Analyze the security telemetry change reported during the session.
Disabling the host firewall degrades the device security posture and increases risk.
Zero Trust mandates continuous monitoring of endpoint health and compliance throughout active sessions.
2
Determine how the Zero Trust control plane processes posture changes.
The Policy Decision Point (PDP) recalculates the dynamic trust score based on incoming telemetry.
The PDP is responsible for making logical access decisions based on real-time contextual data.
3
Identify how the policy decision is operationalized at the network and application layer.
The Policy Enforcement Point (PEP) receives the updated instruction from the PDP and restricts or drops the connection.
The PEP executes session control functions based on direction from the PDP.

Anahtar Kavram

Continuous Verification and PDP/PEP Dynamic Authorization
Tahmini Süre:1m 30s
Bu soruyu puanla