Study. uk . com
  1. Home
  2. All questions
  3. Question 195

CISSP study material · question 195 of 500

A single sign-on deployment issues a token at login that admits the user to every application in the estate for eight hours. Which two zero trust expectations does this arrangement fail? Choose two.

  1. Authentication should rely on a password rather than a token.
  2. Authorisation to one resource should not automatically extend to a different resource.
  3. Enforcement should occur only at the network perimeter.
  4. Access should be granted on a per-session basis with trust evaluated before each grant.
Show the answer

Answer: B. Authorisation to one resource should not automatically extend to a different resource.
D. Access should be granted on a per-session basis with trust evaluated before each grant.

Zero trust evaluates trust before each session and states that authentication and authorisation to one resource does not automatically grant access to another.

Source: NIST SP 800-207 (NIST) — SP 800-207 > 2.1 Tenets of Zero Trust, tenet 3

Challenge yourself on this topic → Study as cards