Study. uk . com
  1. Home
  2. All questions
  3. Question 23

CISSP study material · question 23 of 500

An engineer is building the access flow for a zero trust architecture. A contractor signs in with MFA from a laptop the enterprise has never seen and requests a session to an internal application. Which sequencing matches the SP 800-207 model?

  1. Authenticate the subject with MFA, allow the session, then evaluate the device posture while the session runs.
  2. Authenticate the device by certificate and let the subject inherit authorisation from the device enrolment record.
  3. Authenticate the subject at the gateway, then authorise the request inside the application once connected.
  4. Authenticate and authorise the subject and the device as separate steps, then allow the session to the resource.
Show the answer

Answer: D. Authenticate and authorise the subject and the device as separate steps, then allow the session to the resource.

Subject and device are authenticated and authorised as distinct steps completed before any session opens; posture evaluated during the session leaves an unvetted laptop already connected to the resource.

Source: NIST SP 800-207 (NIST) — SP 800-207 > Abstract

Challenge yourself on this topic → Study as cards