nerdexam
Palo_Alto_Networks

PSE-SASE · Question #50

In which step of the Five-Step Methodology for implementing the Zero Trust model are the services most valuable to the company defined?

The correct answer is D. Step 1: Define the protect surface. Step 1: Define the protect surface is correct because Zero Trust begins by identifying what you're protecting - your most critical and valuable assets (data, applications, services, and systems, often called "DAAS"). You cannot build a security architecture without first…

Zero Trust Network Access (ZTNA)

Question

In which step of the Five-Step Methodology for implementing the Zero Trust model are the services most valuable to the company defined?

Options

  • AStep 2: Map the transaction flows
  • BStep 4: Create the Zero Trust policy
  • CStep 5: Monitor and maintain the network
  • DStep 1: Define the protect surface

How the community answered

(51 responses)
  • A
    2% (1)
  • B
    8% (4)
  • C
    2% (1)
  • D
    88% (45)

Explanation

Step 1: Define the protect surface is correct because Zero Trust begins by identifying what you're protecting - your most critical and valuable assets (data, applications, services, and systems, often called "DAAS"). You cannot build a security architecture without first knowing what deserves the highest protection, and the "protect surface" is intentionally narrow, focusing on the crown jewels rather than the entire attack surface.

Why the distractors are wrong:

  • Step 2 (Map transaction flows) comes after you've defined what to protect - you map how data moves to and from the protect surface, not what the surface is.
  • Step 4 (Create Zero Trust policy) is where you define who gets access and how - the rules enforced around the already-identified protect surface.
  • Step 5 (Monitor and maintain) is ongoing operational work after the architecture is live, not a definition phase.

Memory tip: Think of it as building a vault - Step 1 is deciding what goes in the vault (your most valuable services). You can't design the vault, map the routes to it, set the access rules, or monitor it until you first know what you're locking up.

Topics

#Zero Trust#Five-Step Methodology#protect surface#Step 1

Community Discussion

No community discussion yet for this question.

Full PSE-SASE Practice