A global audit firm is implementing a Zero Trust Architecture (ZTA) for partner consultants accessing sensitive financial databases. During an active user session, real-time endpoint telemetry reports that a consultant's laptop has disabled its endpoint detection agent and initiated access from an unrecognized IP address, despite having passed initial Multi-Factor Authentication (MFA). Which of the following architectural responses best exemplifies core Zero Trust principles in this scenario?
- Instruct the Policy Decision Point (PDP) to dynamically re-evaluate the session trust score and signal the Policy Enforcement Point (PEP) to terminate or restrict access immediately.Cevap
- BAllow the current session to remain active until the authenticated access token expires, while logging the anomaly in the SIEM for post-incident review.
- CPrompt the consultant to re-verify their identity using MFA upon their next interactive resource request while retaining existing database permissions.
- DApply a static firewall filtering rule at the remote access gateway subnet to block traffic from the consultant's entire IP range.
Cevap
Instruct the Policy Decision Point (PDP) to dynamically re-evaluate the session trust score and signal the Policy Enforcement Point (PEP) to terminate or restrict access immediately.
Under Zero Trust Architecture, access is never implicitly granted or maintained based solely on initial authentication. When risk signals change (such as disabled security agents or context anomalies), the Policy Decision Point (PDP) dynamically re-evaluates trust and directs the Policy Enforcement Point (PEP) to restrict or terminate access in real time.
Adım Adım Çözüm
Anahtar Kavram
Continuous Verification and Dynamic Policy Enforcement in Zero Trust Architecture
Tahmini Süre:2m 0s