nerdexam
Cisco

400-007 · Question #251

A network attacker exploits application flaws to compromise critical systems in the organization with these objectives: - Obtain sensitive data and export the data out of the network - Compromise…

The correct answer is A. Enforce policies and microsegmentation. In Zero Trust networking, after application discovery is complete the immediate next step is to enforce policies and microsegmentation to restrict lateral movement and limit the blast radius of any compromise.

Designing Security

Question

A network attacker exploits application flaws to compromise critical systems in the organization with these objectives:

  • Obtain sensitive data and export the data out of the network
  • Compromise developer and administrator credentials to potentially

gain access What is the next step after application discovery is completed in Zero Trust networking?

Options

  • AEnforce policies and microsegmentation
  • BEstablish visibility and behavior modeling
  • CEnsure trustworthiness of systems
  • DAssess real-time security health

How the community answered

(40 responses)
  • A
    80% (32)
  • B
    10% (4)
  • C
    3% (1)
  • D
    8% (3)

Why each option

In Zero Trust networking, after application discovery is complete the immediate next step is to enforce policies and microsegmentation to restrict lateral movement and limit the blast radius of any compromise.

AEnforce policies and microsegmentationCorrect

Once applications and transaction flows are discovered, Zero Trust architecture requires enforcing least-privilege access policies combined with microsegmentation, creating granular network segments that prevent attackers from moving laterally between systems and from exfiltrating data even after an initial foothold is established.

BEstablish visibility and behavior modeling

Visibility and behavior modeling is performed during the earlier discovery and mapping phases, not as the step that immediately follows completed application discovery.

CEnsure trustworthiness of systems

Ensuring trustworthiness of systems is a continuous validation principle woven throughout Zero Trust, not a discrete sequential step triggered by completing discovery.

DAssess real-time security health

Assessing real-time security health is an ongoing monitoring activity that spans all phases of Zero Trust and is not a specific next step that follows application discovery.

Concept tested: Zero Trust network workflow steps after application discovery

Source: https://www.cisco.com/c/en/us/products/security/zero-trust-network-access/index.html

Topics

#Zero Trust#microsegmentation#application discovery#security policy

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice