nerdexam
Palo_Alto_Networks

PSE-SASE · Question #14

In which step of the Five-Step Methodology of Zero Trust are application access and user access defined?

The correct answer is A. Step 4: Create the Zero Trust Policy. Step 4: Create the Zero Trust Policy is where application access and user access are formally defined, because this step translates your architecture into enforceable rules - specifying who can access what, how, and under what conditions, using frameworks like Kipling's "who…

Zero Trust Network Access (ZTNA)

Question

In which step of the Five-Step Methodology of Zero Trust are application access and user access defined?

Options

  • AStep 4: Create the Zero Trust Policy
  • BStep 3: Architect a Zero Trust Network
  • CStep 1: Define the Protect Surface
  • DStep 5: Monitor and Maintain the Network

How the community answered

(44 responses)
  • A
    89% (39)
  • B
    7% (3)
  • C
    2% (1)
  • D
    2% (1)

Explanation

Step 4: Create the Zero Trust Policy is where application access and user access are formally defined, because this step translates your architecture into enforceable rules - specifying who can access what, how, and under what conditions, using frameworks like Kipling's "who, what, when, where, why, and how."

  • Step 3 (Architect a Zero Trust Network) is wrong because that step focuses on designing the technical infrastructure (micro-segmentation, controls placement) around the protect surface - not writing access policies.
  • Step 1 (Define the Protect Surface) is wrong because it's about identifying what needs protection (data, apps, assets, services - DAAS), not who gets access to it.
  • Step 5 (Monitor and Maintain) is wrong because that's an ongoing operational phase for logging, inspecting traffic, and refining the environment over time.

Memory tip: Think of it as a sequence - you define what to protect (Step 1), map the flows (Step 2), build the architecture (Step 3), then write the rules for who gets in (Step 4), and finally watch and tune (Step 5). Access rules logically come just before you go live and start monitoring.

Topics

#Zero Trust#Five-Step Methodology#Zero Trust policy#access control

Community Discussion

No community discussion yet for this question.

Full PSE-SASE Practice