- Home
- All questions
- Question 195
CISSP study material · question 195 of 500
A single sign-on deployment issues a token at login that admits the user to every application in the estate for eight hours. Which two zero trust expectations does this arrangement fail? Choose two.
Show the answer
Answer: B. Authorisation to one resource should not automatically extend to a different resource.
D. Access should be granted on a per-session basis with trust evaluated before each grant.
Zero trust evaluates trust before each session and states that authentication and authorisation to one resource does not automatically grant access to another.
Source: NIST SP 800-207 (NIST) — SP 800-207 > 2.1 Tenets of Zero Trust, tenet 3