Study. uk . com
  1. Home
  2. All questions
  3. Question 32

CISSP study material · question 32 of 500

A manufacturer is rebuilding remote access around a zero trust architecture. Engineers argue that company-issued laptops sitting on the plant's internal LAN should reach the production historian directly, since both the hardware and the segment are corporate property. The security architect rejects this. Which statement reflects the model the architect is applying?

  1. The subject is authenticated at the perimeter, and any device on the internal LAN is trusted for the duration of that session.
  2. The subject and the device are authenticated as separate steps, and both conclude before the session to the resource opens.
  3. The device is authenticated once at network admission, and later resource sessions rely on that earlier admission decision.
  4. The device inherits trust from the corporate segment, so only the subject is authenticated before the resource session opens.
Show the answer

Answer: B. The subject and the device are authenticated as separate steps, and both conclude before the session to the resource opens.

Zero trust authenticates subject and asset separately before any resource session; corporate ownership and presence on the internal LAN confer no implicit trust.

Source: NIST SP 800-207 (NIST) — SP 800-207 > Abstract

Challenge yourself on this topic → Study as cards