Zero Trust Architecture & Microsegmentation Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Zero Trust Architecture & Microsegmentation flashcards as text
What is the function of a Policy Decision Point (PDP) in Zero Trust Architecture?
Answer: It evaluates access requests against policies and grants or denies access
The Policy Decision Point (PDP) evaluates access requests by comparing them against defined policies, determining whether to grant or deny access before the Policy Enforcement Point acts on that decision.
How does microsegmentation differ from traditional VLAN-based network segmentation?
Answer: Microsegmentation provides workload-level granularity, while VLANs segment at the subnet level
Microsegmentation enforces policies at the individual workload or application level, providing far more granular control than VLANs, which segment traffic at the broader network or subnet level.
In Zero Trust Architecture, what is 'East-West' traffic?
Answer: Traffic moving laterally between servers and services within a data center or cloud
East-West traffic refers to lateral traffic moving between internal servers, services, and workloads within a data center or cloud environment, as opposed to North-South traffic entering or leaving the perimeter.
Which NIST publication provides the primary framework for implementing Zero Trust Architecture?
Answer: NIST SP 800-207
NIST Special Publication 800-207 is the definitive guide for Zero Trust Architecture, defining its core components, tenets, logical components, and deployment models.
What is a Software-Defined Perimeter (SDP) in the context of Zero Trust?
Answer: A dynamic, identity-centric access control model that hides infrastructure from unauthorized users
A Software-Defined Perimeter creates a dynamic perimeter based on user identity and device posture, making infrastructure invisible to unauthorized users until after authentication and authorization succeed.
What is a primary challenge when adopting Zero Trust Architecture in legacy enterprise environments?
Answer: Legacy systems often lack the APIs and identity integration needed for continuous verification
Legacy systems frequently lack modern APIs, identity federation capabilities, or logging functionality needed to support the continuous verification and policy enforcement that Zero Trust requires.
Which of the following is a key component of the Zero Trust 'Five Pillars' model developed by the U.S. Department of Defense (DoD)?
Answer: Identity, Devices, Networks, Applications & Workloads, and Data
The DoD Zero Trust Reference Architecture identifies five pillars: Identity, Devices, Networks, Applications & Workloads, and Data, each requiring continuous verification and least-privilege enforcement.