CISA · Question #595
In a Zero Trust architecture, which element is MOST important for an IS auditor to evaluate to ensure that resources are accessed securely?
The correct answer is B. The alignment of access control policies with industry standards. In Zero Trust architecture (ZTA), the principle is "never trust, always verify." The most important aspect for an IS auditor to evaluate is whether access control policies are properly designed, aligned with industry standards, and consistently enforced. These policies define how
Question
In a Zero Trust architecture, which element is MOST important for an IS auditor to evaluate to ensure that resources are accessed securely?
Options
- AThe strength and frequency of perimeter firewall testing
- BThe alignment of access control policies with industry standards
- CThe frequency of user access reviews
- DThe protocols in place for remote access and data encryption
How the community answered
(33 responses)- A9% (3)
- B82% (27)
- C6% (2)
- D3% (1)
Explanation
In Zero Trust architecture (ZTA), the principle is "never trust, always verify." The most important aspect for an IS auditor to evaluate is whether access control policies are properly designed, aligned with industry standards, and consistently enforced. These policies define how identities, devices, and contexts are authenticated and authorized before gaining access. Option A: Perimeter firewalls are less relevant in Zero Trust, which minimizes reliance on network Option C: Access reviews are important but are periodic, not continuous enforcement. Option D: Secure remote protocols are necessary but part of broader access policy enforcement. Option B: Correct - policies are the foundation of Zero Trust security.
Topics
Community Discussion
No community discussion yet for this question.