Soru

Zorluk: OrtaZero Trust Architecture Principles

A biotechnology enterprise is updating its network security posture to protect cloud-hosted genomic research databases accessed by remote scientists. The organization intends to implement Zero Trust Architecture (ZTA) principles to replace legacy perimeter defenses. Which of the following requirements must be implemented to align with core Zero Trust tenets? (Select TWO.)

  1. Explicitly verify user identity, device security posture, and transaction context for every resource request, regardless of origin network location.Cevap
  2. B
    Establish implicit trust for internal network traffic once a user successfully authenticates at the edge Virtual Private Network gateway.
  3. Enforce microsegmentation and dynamic access policies that restrict permissions strictly to the specific resources needed for the current task.Cevap
  4. D
    Automatically grant full database permissions upon successful authentication, delegating access authorization to client-side scripts.

Cevap

The organization must explicitly verify user identity, device health, and context for every request regardless of location, and enforce microsegmentation with dynamic least-privilege access controls.
Zero Trust Architecture relies on the fundamental principles of explicit verification and least privilege through microsegmentation. The requirement to explicitly verify every access request evaluates user identity, device health, and context dynamically before granting entry. Concurrently, microsegmentation restricts network connectivity to micro-perimeters around specific workloads, containing potential lateral movement.

Adım Adım Çözüm

1
Evaluate the core tenets of Zero Trust Architecture regarding network trust boundaries.
Zero Trust assumes the internal network is untrusted and requires explicit verification for every request, rejecting implicit perimeter-based trust models.
Assuming internal network traffic is safe allows compromised accounts or devices to move laterally across resources.
2
Analyze access control granularities required under Zero Trust design principles.
Implementing microsegmentation minimizes attack surfaces by creating isolated logical segments enforced by granular access policies.
Least privilege and microsegmentation ensure users and devices receive only the specific access required for their immediate role.

Anahtar Kavram

Zero Trust Architecture Principles
Tahmini Süre:1m 30s
Bu soruyu puanla