nerdexam
Cisco

400-007 · Question #285

A network security team observes phishing attacks on a user machine from a remote location. The organization has a policy of saving confidential data on two different systems using different types…

The correct answer is C. Ensure trustworthiness of devices. In a Zero Trust security model, after verifying user identity, the next sequential step is to ensure the trustworthiness and compliance posture of the devices those users are operating.

Designing Security

Question

A network security team observes phishing attacks on a user machine from a remote location. The organization has a policy of saving confidential data on two different systems using different types of authentication. What is the next step to control such events after the security team verifies all users in Zero Trust modeling?

Exhibit

400-007 question #285 exhibit

Options

  • AAssess real-time security health of devices
  • BEnforce risk-based and adaptive access policies
  • CEnsure trustworthiness of devices
  • DApply a context-based network access control policy for users

How the community answered

(21 responses)
  • A
    14% (3)
  • B
    10% (2)
  • C
    43% (9)
  • D
    33% (7)

Why each option

In a Zero Trust security model, after verifying user identity, the next sequential step is to ensure the trustworthiness and compliance posture of the devices those users are operating.

AAssess real-time security health of devices

Assessing real-time security health is an ongoing monitoring activity that occurs after device trustworthiness has already been established, not immediately after user verification.

BEnforce risk-based and adaptive access policies

Enforcing risk-based and adaptive access policies is a policy enforcement step that follows both user and device verification in the Zero Trust sequence.

CEnsure trustworthiness of devicesCorrect

Zero Trust follows a structured sequence - first verify users, then verify devices, then enforce policy. After user verification is complete, confirming device trustworthiness involves checking endpoint compliance, patch level, and security posture before allowing access. This step is critical in a phishing scenario because a compromised device may persist as a threat even after the user is verified.

DApply a context-based network access control policy for users

Applying context-based network access control is a downstream enforcement action that depends on completed user and device verification, making it a later step in the process.

Concept tested: Zero Trust sequential verification - user then device trust

Source: https://www.cisco.com/c/en/us/products/security/zero-trust.html

Topics

#Zero Trust#device trustworthiness#adaptive access#phishing mitigation

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice