Study. uk . com
  1. Home
  2. All questions
  3. Question 22

CISSP study material · question 22 of 500

A retailer is redesigning access after a breach in which an intruder who reached one internal subnet moved freely between servers. The architects want the model described in NIST SP 800-207 zero trust architecture. Which principle should drive the redesign?

  1. Grant no implicit trust from an asset's network location or ownership, and evaluate each request on its own merits.
  2. Treat every enterprise-owned and managed asset as trusted, and constrain only personally owned devices.
  3. Divide the internal estate into subnets so that the level of trust follows the subnet an asset is assigned.
  4. Treat assets inside the corporate perimeter as trusted, and inspect closely only the traffic crossing that perimeter.
Show the answer

Answer: A. Grant no implicit trust from an asset's network location or ownership, and evaluate each request on its own merits.

Zero trust withholds implicit trust from network location and asset ownership; enterprise ownership earns no free pass, so trusting managed devices simply rebuilds the perimeter assumption inside the network.

Source: NIST SP 800-207 (NIST) — SP 800-207 > Abstract

Challenge yourself on this topic → Study as cards