Soru

Zorluk: OrtaZero Trust Architecture Principles

An aerospace engineering firm hosts sensitive CAD schematics on an internal server. Previously, any workstation connected to the internal corporate LAN was implicitly trusted and allowed access to the repository after a single initial morning domain login. To align this environment with Zero Trust Architecture (ZTA) principles, which strategy should the security team implement?

  1. Enforce explicit authentication and contextual authorization for every access request to the schematics repository, regardless of the user's network location.Cevap
  2. B
    Strengthen perimeter firewalls and internal subnet access control lists so all network traffic originating within the corporate LAN remains implicitly trusted.
  3. C
    Require multi-factor authentication during the user's initial login session and grant persistent authorization to internal repository resources for the remainder of the workday.
  4. D
    Reclassify passive perimeter intrusion detection sensors into active preventive controls to automatically block unapproved internal network segments.

Cevap

Enforce explicit authentication and contextual authorization for every access request to the schematics repository, regardless of the user's network location.
Zero Trust Architecture mandates that no network, user, or device is inherently trusted based on physical location or network placement. Enforcing continuous verification through explicit authentication and contextual authorization for every request directly fulfills ZTA principles.

Adım Adım Çözüm

1
Identify the weakness in the legacy security model described in the scenario.
The current model relies on implicit trust granted to devices simply because they are connected to the internal corporate LAN.
Perimeter-focused security assumes internal traffic is trustworthy, leaving internal data vulnerable if an attacker gains access to the corporate network.
2
Apply core Zero Trust Architecture principles to address the architectural limitation.
Transition to explicit verification and continuous authorization for every request.
Zero Trust operates on the principle of 'never trust, always verify,' requiring identity, device stance, and environmental context to be continuously validated regardless of network location.

Anahtar Kavram

Zero Trust Architecture Principles - Explicit Verification and Continuous Assessment
Bu soruyu puanla