- Home
- All questions
- Question 208
CISSP study material · question 208 of 500
A zero trust deployment restricts what each subject may open, but every subject can still enumerate the full catalogue of resources. Which aspect of least privilege does SP 800-207 say is missing?
Show the answer
Answer: A. Least privilege should restrict visibility as well as accessibility.
SP 800-207 applies least privilege principles to restrict both visibility and accessibility, so being unable to reach a resource is not enough if it can still be seen.
Source: NIST SP 800-207 (NIST) — SP 800-207 > 2.1 Tenets of Zero Trust, tenet 4