Study. uk . com
  1. Home
  2. All questions
  3. Question 193

CISSP study material · question 193 of 500

A vendor claims its product delivers zero trust because it removes the perimeter firewall. Why does NIST SP 800-207 reject definitions framed this way?

  1. It defines zero trust by seven tenets that should be present, not by what has been removed, and accepts not all will be realised purely.
  2. It defines zero trust solely as micro-segmentation of the internal network.
  3. It treats zero trust as a product category rather than an architecture.
  4. It requires the perimeter firewall to remain in place alongside the new controls.
Show the answer

Answer: A. It defines zero trust by seven tenets that should be present, not by what has been removed, and accepts not all will be realised purely.

SP 800-207 deliberately defines zero trust by basic tenets rather than by exclusion, and acknowledges that not every tenet will be fully implemented in its purest form.

Source: NIST SP 800-207 (NIST) — SP 800-207 > 2.1 Tenets of Zero Trust

Challenge yourself on this topic → Study as cards