A security architect is designing a system for a highly distributed global manufacturing company. The company wants to enforce security policies based on user attributes, device posture, and environmental factors, rather than just network location or static roles. The goal is to dynamically grant or deny access to resources, even for internal users. Which concept is being described?
- AZero Trust Architecture (ZTA)
- BDemilitarized Zone (DMZ)
- CPerimeter Security
- DVirtual Private Network (VPN)
Show answer & explanationAnswer & explanation
Correct answer: A. Zero Trust Architecture (ZTA)
Zero Trust Architecture (ZTA) operates on the principle of 'never trust, always verify.' It enforces strict access controls based on multiple contextual factors like user identity, device health, location, and application sensitivity, irrespective of whether the user is inside or outside the traditional network perimeter. This dynamic, attribute-based approach aligns perfectly with the scenario's requirements.
Why the other options are wrong
- B. A DMZ isolates publicly accessible services but does not provide dynamic, attribute-based access control for internal users.
- C. Perimeter security focuses on protecting the network edge, which is insufficient for internal threats or dynamic access based on attributes.
- D. A VPN provides secure remote access but doesn't inherently enforce dynamic, attribute-based policies for all internal resource access.
Zero Trust Architecture (ZTA)
A security model based on the principle that no user or device, whether inside or outside the network, should be implicitly trusted. All access requests are continuously verified based on identity, device posture, and other contextual factors.
- Never trust, always verify.
- Enforces granular access based on multiple attributes.
- Eliminates the concept of a trusted internal network.
Memory trick: Zero Trust means verifying everyone, every time, no matter where they are.