Study. uk . com
  1. Home
  2. All questions
  3. Question 208

CISSP study material · question 208 of 500

A zero trust deployment restricts what each subject may open, but every subject can still enumerate the full catalogue of resources. Which aspect of least privilege does SP 800-207 say is missing?

  1. Least privilege should restrict visibility as well as accessibility.
  2. Least privilege should be enforced at the data plane rather than the control plane.
  3. Least privilege requires per-resource encryption keys.
  4. Least privilege applies to devices rather than to subjects.
Show the answer

Answer: A. Least privilege should restrict visibility as well as accessibility.

SP 800-207 applies least privilege principles to restrict both visibility and accessibility, so being unable to reach a resource is not enough if it can still be seen.

Source: NIST SP 800-207 (NIST) — SP 800-207 > 2.1 Tenets of Zero Trust, tenet 4

Challenge yourself on this topic → Study as cards