- Home
- All questions
- Question 196
CISSP study material · question 196 of 500
An access policy is written purely as a static list of groups and applications. Which inputs does SP 800-207 expect a zero trust policy to weigh instead? Choose three.
Show the answer
Answer: D. Client identity together with the attributes assigned to that account.
C. The observable state of the requesting asset, such as patch level and installed credentials.
B. Environmental facts such as the requester's network location, the time, and reported active attacks.
Zero trust policy is dynamic, weighing client identity and attributes, requesting asset state, behavioural analytics, and environmental attributes such as location, time and active attacks.
Source: NIST SP 800-207 (NIST) — SP 800-207 > 2.1 Tenets of Zero Trust, tenet 4