PSE-STRATA · Question #185
Within the Five-Step Methodology of Zero Trust, in which step would application access and user access be defined?
The correct answer is E. Step 2: Map the Protect Surface Transaction Flows. *Step 2 is correct because mapping transaction flows is precisely the process of documenting who (users) and what (applications) needs to access the protect surface, and how that access flows. This mapping exercise produces the foundational inventory of user access and…
Question
Within the Five-Step Methodology of Zero Trust, in which step would application access and user access be defined?
Options
- AStep 3: Architect a Zero Trust Network
- BStep 5. Monitor and Maintain the Network
- CStep 4: Create the Zero Trust Policy
- DStep 1: Define the Protect Surface
- EStep 2: Map the Protect Surface Transaction Flows
How the community answered
(30 responses)- A7% (2)
- B3% (1)
- C17% (5)
- D3% (1)
- E70% (21)
Explanation
Step 2 is correct because mapping transaction flows is precisely the process of documenting who (users) and what (applications) needs to access the protect surface, and how that access flows. This mapping exercise produces the foundational inventory of user access and application access patterns that all subsequent steps depend on - you cannot architect a network or write a policy without first knowing what access relationships exist.
- Step 1 (D) is wrong because it focuses on identifying what you're protecting (data, assets, services), not who or what accesses it.
- Step 3 (A) is wrong because architecture decisions come after flows are mapped; you design the network to enforce the access you've already documented.
- Step 4 (C) is wrong because policies are written to enforce access rules, not to define that access exists - policy creation relies on the Step 2 map.
- Step 5 (B) is wrong because monitoring is an ongoing operational activity, not a definitional one.
Memory tip: Think of the five steps as a funnel - what to protect (Step 1) → who/how accesses it (Step 2) → build the network around it (Step 3) → write rules for it (Step 4) → watch it (Step 5). Users and applications are part of the "who/how" flow mapping in Step 2.
Community Discussion
No community discussion yet for this question.