A high-precision robotics enterprise is implementing Zero Trust Architecture (ZTA) controls for remote field engineers accessing edge industrial control systems. An engineer successfully authenticates and establishes an active session to deploy firmware. Ten minutes into the session, real-time endpoint telemetry alerts the system that the engineer's workstation has disabled its local host firewall and initiated an unverified concurrent wireless network connection, severely degrading its dynamic security posture score. Which of the following actions should the Policy Decision Point (PDP) execute to maintain Zero Trust tenets?
- Signal the Policy Enforcement Point (PEP) to immediately revoke or restrict access to the active session based on continuous, real-time evaluation of the endpoint's degraded trust score.Cevap
- BAllow the active session to persist until the session token naturally expires, relying on the successful initial authentication to guarantee access legitimacy.
- CRedirect the workstation's network traffic to an internal encrypted VPN tunnel under the assumption that internal segment routing mitigates endpoint vulnerability risks.
- DModify the user's role-based access control (RBAC) profile in the directory service to permanently revoke all identity authentication privileges.
Cevap
Signal the Policy Enforcement Point (PEP) to immediately revoke or restrict access to the active session based on continuous, real-time evaluation of the endpoint's degraded trust score.
Under Zero Trust Architecture (ZTA) principles (such as NIST SP 800-207), access is continuously re-evaluated based on real-time threat intelligence and endpoint security posture telemetry. When an endpoint's posture degrades mid-session (such as disabling a host firewall or establishing an untrusted connection), the Policy Decision Point (PDP) must dynamically re-evaluate trust and command the Policy Enforcement Point (PEP) to restrict or terminate the active access session.
Adım Adım Çözüm
Anahtar Kavram
Continuous Verification and Dynamic Context-Based Policy Enforcement in Zero Trust Architecture
Tahmini Süre:2m 0s