Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesHard

A government agency is modernizing its IT infrastructure by adopting a zero-trust architecture. The cybersecurity architect needs to evaluate technical strategies to enforce granular access controls and continuously verify user and device trust for sensitive government data, adhering to NIST frameworks. Which strategy is most aligned with a comprehensive zero-trust implementation?

  1. AAssuming all internal network traffic is trustworthy and focusing security efforts only on external threats.
  2. BGranting all authenticated users full access to all internal resources to simplify administration.
  3. CDeploying an Identity and Access Management (IAM) solution with Multi-Factor Authentication (MFA) and a Network Access Control (NAC) system for device posture assessment, integrated with a Policy Decision Point (PDP) for dynamic access policy enforcement.
  4. DImplementing a traditional perimeter-based firewall and VPN for all network access.
Show answer & explanation

Correct answer: C. Deploying an Identity and Access Management (IAM) solution with Multi-Factor Authentication (MFA) and a Network Access Control (NAC) system for device posture assessment, integrated with a Policy Decision Point (PDP) for dynamic access policy enforcement.

This strategy fully aligns with zero-trust principles by continuously verifying identity (IAM, MFA), device posture (NAC), and dynamically enforcing granular access policies based on real-time context (PDP), which is a core tenet of NIST zero-trust guidelines.

Why the other options are wrong

  • A. Assuming internal trust is a legacy approach and directly opposes the 'never trust, always verify' principle of zero-trust.
  • B. Granting full access violates the principle of least privilege, which is fundamental to zero-trust and critical for government data security.
  • D. Perimeter-based security contradicts zero-trust by implicitly trusting internal networks once access is granted, which is not suitable for sensitive government data under NIST guidelines.

Zero Trust Architecture (ZTA)

A security model where no user, device, or application is implicitly trusted, regardless of their location. All access requests are authenticated, authorized, and continuously verified.

  • Based on the principle 'never trust, always verify'.
  • Enforces least privilege access.
  • Requires continuous monitoring and validation of trust.

Memory trick: Zero Trust: Verify Everything, Grant Least Privilege

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions