Soru

Zorluk: OrtaZero Trust Architecture Principles

A smart manufacturing facility is updating its industrial control network to align with Zero Trust Architecture (ZTA) principles. Currently, field sensor nodes and automated robotic assembly controllers communicate freely within an internal operational technology (OT) network segment once inside the network perimeter. Which of the following architectural modifications best implements the core Zero Trust principle of continuous explicit verification for these device communications?

  1. Requiring every communication session between sensor nodes and assembly controllers to be dynamically authenticated and authorized based on real-time device health and contextual policy before granting access.Cevap
  2. B
    Deploying a next-generation perimeter firewall between the corporate network and the OT segment while trusting internal node-to-node network traffic.
  3. C
    Configuring sensor nodes to complete mutual TLS authentication once during system boot, granting persistent network access across all assembly controllers.
  4. D
    Installing host-based intrusion prevention system rules on legacy controllers to block operating system vulnerability exploits.

Cevap

Requiring every communication session between sensor nodes and assembly controllers to be dynamically authenticated and authorized based on real-time device health and contextual policy before granting access.
Zero Trust Architecture fundamentally operates under the principle of 'never trust, always verify.' Requiring every connection request between internal devices to be explicitly authenticated and authorized using dynamic contextual attributes ensures that network location alone never grants implicit access rights.

Adım Adım Çözüm

1
Identify current architecture security flaws
The current setup relies on implicit trust within the internal OT network perimeter.
Perimeter-based models assume internal network traffic is inherently safe once inside, leaving systems vulnerable to lateral movement.
2
Apply Zero Trust Architecture tenets
Zero Trust mandates explicit verification and continuous evaluation of every access request regardless of network placement.
Under Zero Trust, access decisions must be dynamic, continuous, and based on contextual identity and asset health metrics.
3
Select the control that enforces dynamic session evaluation
Enforcing real-time, policy-driven authentication and authorization per session fulfills the explicit verification requirement.
This eliminates implicit network location trust and forces granular, continuous validation for every transaction.

Anahtar Kavram

Zero Trust Explicit Verification and Continuous Authentication
Bu soruyu puanla