400-007 · Question #285
A network security team observes phishing attacks on a user machine from a remote location. The organization has a policy of saving confidential data on two different systems using different types…
The correct answer is C. Ensure trustworthiness of devices. In a Zero Trust security model, after verifying user identity, the next sequential step is to ensure the trustworthiness and compliance posture of the devices those users are operating.
Question
A network security team observes phishing attacks on a user machine from a remote location. The organization has a policy of saving confidential data on two different systems using different types of authentication. What is the next step to control such events after the security team verifies all users in Zero Trust modeling?
Exhibit
Options
- AAssess real-time security health of devices
- BEnforce risk-based and adaptive access policies
- CEnsure trustworthiness of devices
- DApply a context-based network access control policy for users
How the community answered
(21 responses)- A14% (3)
- B10% (2)
- C43% (9)
- D33% (7)
Why each option
In a Zero Trust security model, after verifying user identity, the next sequential step is to ensure the trustworthiness and compliance posture of the devices those users are operating.
Assessing real-time security health is an ongoing monitoring activity that occurs after device trustworthiness has already been established, not immediately after user verification.
Enforcing risk-based and adaptive access policies is a policy enforcement step that follows both user and device verification in the Zero Trust sequence.
Zero Trust follows a structured sequence - first verify users, then verify devices, then enforce policy. After user verification is complete, confirming device trustworthiness involves checking endpoint compliance, patch level, and security posture before allowing access. This step is critical in a phishing scenario because a compromised device may persist as a threat even after the user is verified.
Applying context-based network access control is a downstream enforcement action that depends on completed user and device verification, making it a later step in the process.
Concept tested: Zero Trust sequential verification - user then device trust
Source: https://www.cisco.com/c/en/us/products/security/zero-trust.html
Topics
Community Discussion
No community discussion yet for this question.
