Soru

Zorluk: ZorZero Trust Architecture Principles

A global audit firm is implementing a Zero Trust Architecture (ZTA) for partner consultants accessing sensitive financial databases. During an active user session, real-time endpoint telemetry reports that a consultant's laptop has disabled its endpoint detection agent and initiated access from an unrecognized IP address, despite having passed initial Multi-Factor Authentication (MFA). Which of the following architectural responses best exemplifies core Zero Trust principles in this scenario?

  1. Instruct the Policy Decision Point (PDP) to dynamically re-evaluate the session trust score and signal the Policy Enforcement Point (PEP) to terminate or restrict access immediately.Cevap
  2. B
    Allow the current session to remain active until the authenticated access token expires, while logging the anomaly in the SIEM for post-incident review.
  3. C
    Prompt the consultant to re-verify their identity using MFA upon their next interactive resource request while retaining existing database permissions.
  4. D
    Apply a static firewall filtering rule at the remote access gateway subnet to block traffic from the consultant's entire IP range.

Cevap

Instruct the Policy Decision Point (PDP) to dynamically re-evaluate the session trust score and signal the Policy Enforcement Point (PEP) to terminate or restrict access immediately.
Under Zero Trust Architecture, access is never implicitly granted or maintained based solely on initial authentication. When risk signals change (such as disabled security agents or context anomalies), the Policy Decision Point (PDP) dynamically re-evaluates trust and directs the Policy Enforcement Point (PEP) to restrict or terminate access in real time.

Adım Adım Çözüm

1
Analyze the scenario metrics and threat posture change during an active session.
The device posture degraded (EDR agent disabled) and context changed unexpectedly (unrecognized IP address).
Zero Trust assumes breach and requires continuous inspection rather than static, one-time authentication.
2
Determine the required Zero Trust Architecture component interaction.
The PDP processes real-time telemetry to update the dynamic trust score, and the PEP enforces the updated policy decision by immediately restricting or terminating access.
ZTA relies on dynamic control plane decisions to enforce granular access state changes in real time.

Anahtar Kavram

Continuous Verification and Dynamic Policy Enforcement in Zero Trust Architecture
Tahmini Süre:2m 0s
Bu soruyu puanla