Zero Trust Architecture & Microsegmentation Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Zero Trust Architecture & Microsegmentation flashcards as text
What is the foundational principle of Zero Trust Architecture (ZTA)?
Answer: Never trust, always verify every user and device
Zero Trust Architecture operates on the principle of 'never trust, always verify,' meaning no user, device, or network segment is trusted by default regardless of its location.
In microsegmentation, what is the primary purpose of dividing the network into smaller zones?
Answer: To limit lateral movement of attackers within the network
Microsegmentation limits lateral movement by containing potential breaches within small segments, preventing attackers from freely traversing the network after an initial compromise.
Which of the following best describes the role of ACLs in a Zero Trust environment?
Answer: ACLs enforce granular access controls between microsegments at the workload level
In Zero Trust, ACLs enforce granular, workload-level access controls between microsegments, ensuring only explicitly authorized traffic flows between defined zones.
What is the concept of 'implicit trust' that Zero Trust Architecture seeks to eliminate?
Answer: The assumption that users inside the network perimeter are trustworthy
Traditional security models implicitly trust users and devices inside the network perimeter; Zero Trust eliminates this assumption by requiring verification for every access request.
In a Zero Trust model, what does continuous validation mean?
Answer: Re-authenticating and re-authorizing users and devices throughout their session
Continuous validation means that trust is not granted once at login but is repeatedly verified throughout a session based on behavior, device posture, and contextual signals.
Which technology is most commonly used to implement microsegmentation in modern data centers?
Answer: Software-defined networking (SDN) and virtual firewalls
Software-defined networking and virtual firewalls enable dynamic, policy-driven microsegmentation that can be applied at the individual workload level without physical hardware changes.
What is the 'least privilege access' principle as applied in Zero Trust Architecture?
Answer: Users and systems receive only the minimum access required for their specific tasks
Least privilege access ensures that users and systems can only access resources necessary for their specific role or task, reducing the attack surface and limiting damage from compromised accounts.