Scenario: As a ZTA security administrator, you aim to enforce the principle of least privilege for private cloud network access. Which ZTA policy entity is mainly responsible for crafting and maintaining these policies?
-
A
Gateway enforcing access policies
-
B
Policy enforcement point (PEP)
-
C
Policy administrator (PA)
-
D
Policy decision point (PDP)
Reveal answer details
Close answer details
Correct answerC
ExplanationA policy administrator (PA) is a ZTA policy entity that is responsible for crafting and maintaining the policies that govern the access to resources in a ZT environment 1. A PA defines the rules and conditions that specify who, what, when, where, and how an entity can access a resource, based on the principle of least privilege 2. A PA also updates and reviews the policies periodically to ensure they are aligned with the changing business and security requirements 3. References: Zero Trust Architecture | NIST Zero Trust Architecture: Policy Engine and Policy Administrator Zero Trust Architecture: Policy Administration
ZTA reduces management overhead by applying a consistent access model throughout the environment for all assets. What can be said about ZTA models in terms of access decisions?
-
A
The traffic of the access workflow must contain all the parameters for the policy decision points.
-
B
The traffic of the access workflow must contain all the parameters for the policy enforcement points.
-
C
Each access request is handled just-in-time by the policy decision points.
-
D
Access revocation data will be passed from the policy decision points to the policy enforcement points.
Reveal answer details
Close answer details
Correct answerC
ExplanationZTA models in terms of access decisions are based on the principle of "never trust, always verify", which means that each access request is handled just-in-time by the policy decision points. The policy decision points are the components in a ZTA that evaluate the policies and the contextual data collected from various sources, such as the user identity, the device posture, the network location, the resource attributes, and the environmental factors, and then generate an access decision. The access decision is communicated to the policy enforcement points, which enforce the decision on the resource. This way, ZTA models apply a consistent access model throughout the environment for all assets, regardless of their location, type, or ownership. References: Certificate of Competence in Zero Trust (CCZT) prepkit, page 14, section 2.2.2 What Is Zero Trust Architecture (ZTA)? - F5, section "Policy Engine" Zero trust security model - Wikipedia, section "What Is Zero Trust Architecture?" Zero Trust Maturity Model | CISA, section "Zero trust security model"
In a continual improvement model, who maintains the ZT policies?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationIn a continual improvement model, policy administrators are the ones who maintain the ZT policies. Policy administrators are ZTA policy entities that are responsible for crafting and maintaining the policies that govern the access to resources in a ZT environment 1. Policy administrators define the rules and conditions that specify who, what, when, where, and how an entity can access a resource, based on the principle of least privilege 2. Policy administrators also update and review the policies periodically to ensure they are aligned with the changing business and security requirements 3. References: Zero Trust Architecture | NIST Zero Trust Architecture: Policy Engine and Policy Administrator Zero Trust Architecture: Policy Administration
Network architects should consider__________before selecting an SDP model. Select the best answer.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationDifferent SDP deployment models have different advantages and disadvantages depending on the organization's use case, such as the type of resources to be protected, the location of the clients and servers, the network topology, the scalability, the performance, and the security requirements. Network architects should consider their use case before selecting an SDP model that best suits their needs and goals. References: Certificate of Competence in Zero Trust (CCZT) prepkit, page 21, section 3.1.2 6 SDP Deployment Models to Achieve Zero Trust | CSA, section "Deployment Models Explained" Software-Defined Perimeter (SDP) and Zero Trust | CSA, page 7, section 3.1 Why SDP Matters in Zero Trust | SonicWall, section "SDP Deployment Models"
When kicking off ZT planning, what is the first step for an organization in defining priorities?
-
A
-
B
-
C
-
D
Identifying the data and assets
Reveal answer details
Close answer details
Correct answerA
ExplanationThe first step for an organization in defining priorities for ZT planning is to determine the current state of its network, security, and business environment. This involves conducting a comprehensive assessment of the existing IT infrastructure, systems, applications, data, and assets, as well as the threats, risks, and vulnerabilities that affect them. The current state analysis also involves identifying the gaps, challenges, and opportunities for improvement in the current security posture, as well as the business goals, objectives, and requirements for ZT implementation 12. By determining the current state, the organization can establish a baseline for measuring the progress and impact of ZT, as well as prioritize the most critical and urgent areas for ZT adoption. References: Planning for a Zero Trust Architecture: A Planning Guide for Federal Administrators | CSRC Publications NIST Zero Trust Architecture Explained: A Step-by-Step Approach - Comparitech
SDP incorporates single-packet authorization (SPA). After successful authentication and authorization, what does the client usually do next? Select the best answer.
-
A
Generates an SPA packet and sends it to the initiating host.
-
B
Generates an SPA packet and sends it to the controller.
-
C
Generates an SPA packet and sends it to the accepting host.
-
D
Generates an SPA packet and sends it to the gateway.
Reveal answer details
Close answer details
Correct answerB
ExplanationAfter successful authentication and authorization, the client typically sends an SPA packet to the controller, which acts as an intermediary in authenticating the client's request before access to the accepting host is granted. References: Certificate of Competence in Zero Trust (CCZT) - Cloud Security Alliance, Zero Trust Training (ZTT) - Module 9: Risk Management
ZT project implementation requires prioritization as part of the overall ZT project planning activities. One area to consider is______Select the best answer.
-
A
prioritization based on risks
-
B
prioritization based on budget
-
C
prioritization based on management support
-
D
prioritization based on milestones
Reveal answer details
Close answer details
Correct answerA
ExplanationZT project implementation requires prioritization as part of the overall ZT project planning activities. One area to consider is prioritization based on risks, which means that the organization should identify and assess the potential threats, vulnerabilities, and impacts that could affect its assets, operations, and reputation, and prioritize the ZT initiatives that address the most critical and urgent risks. Prioritization based on risks helps to align the ZT project with the business objectives and needs, and optimize the use of resources and time. References: Zero Trust Planning - Cloud Security Alliance, section "Scope, Priority, & Business Case" The Zero Trust Journey: 4 Phases of Implementation - SEI Blog, section "Second Phase: Assess" Planning for a Zero Trust Architecture: A Planning Guide for Federal ..., section "Gap Analysis"
Which vital ZTA component enhances network security and simplifies management by creating boundaries between resources in the same network zone?
-
A
-
B
Session establishment or termination
-
C
-
D
Authentication request/validation request (AR/VR)
Reveal answer details
Close answer details
Correct answerA
ExplanationMicro-segmentation is a vital ZTA component that enhances network security and simplifies management by creating boundaries between resources in the same network zone. Micro-segmentation divides the network into smaller segments or zones based on the attributes and context of the resources, such as data sensitivity, application functionality, user roles, etc. Micro-segmentation helps to isolate and protect the resources from unauthorized access and lateral movement of attackers within the same network zone. References: Certificate of Competence in Zero Trust (CCZT) - Cloud Security Alliance, Zero Trust Training (ZTT) - Module 6: Micro-segmentation
Optimal compliance posture is mainly achieved through two key ZT features:_____ and_____
-
A
(1) Principle of least privilege (2) Verifying remote access connections
-
B
(1) Discovery (2) Mapping access controls and network assets
-
C
(1) Authentication (2) Authorization of all networked assets
-
D
(1) Never trusting (2) Reducing the attack surface
Reveal answer details
Close answer details
Correct answerD
ExplanationOptimal compliance posture is mainly achieved through two key ZT features: never trusting and reducing the attack surface. Never trusting means that no entity or resource is assumed to be trustworthy or secure by default, and that every request for access or transaction is verified and validated before granting access or allowing the transaction. Reducing the attack surface means that the exposure and vulnerability of the assets and resources are minimized by implementing granular and dynamic policies, controls, and segmentation. These two features help to ensure that the organization complies with the security standards and regulations, and that the risks of breaches and incidents are reduced. References: Certificate of Competence in Zero Trust (CCZT) - Cloud Security Alliance, Zero Trust Training (ZTT) - Module 1: Strategy and Governance
|