- Home
- All questions
- Question 206
CISSP study material · question 206 of 500
A gateway grants access whenever the user presents valid credentials, without examining the device the request came from. Which two zero trust points does this miss? Choose two.
Show the answer
Answer: C. Subject credentials alone are insufficient to authenticate the device to the resource.
A. The asset's security posture must be evaluated before the request is granted.
Every asset must have its posture evaluated by an enforcement point before access is granted and continually through the session; the subject's credentials do not authenticate the device.
Source: NIST SP 800-207 (NIST) — SP 800-207 > 2.2 A Zero Trust View of a Network, assumption 3