Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CSA Exam CCZT Topic 2 Question 29 Discussion

Actual exam question for CSA's Certificate of Competence in Zero Trust exam
Question #: 29
Topic #: 2
[All Certificate of Competence in Zero Trust Questions]

Which element of ZT focuses on the governance rules that define

the "who, what, when, how, and why" aspects of accessing target

resources?

Show Suggested Answer Hide Answer
Suggested Answer: A

Policy is the element of ZT that focuses on the governance rules that define the ''who, what, when, how, and why'' aspects of accessing target resources. Policy is the core component of a ZTA that determines the access decisions and controls for each request based on various attributes and factors, such as user identity, device posture, network location, resource sensitivity, and environmental context. Policy is also the element that enables the ZT principles of ''never trust, always verify'' and ''scrutinize explicitly'' by enforcing granular, dynamic, and data-driven rules for each access request.

Reference=

Certificate of Competence in Zero Trust (CCZT) prepkit, page 14, section 2.2.2

What Is Zero Trust Architecture (ZTA)? - F5, section ''Policy Engine''

Zero Trust Architecture Project - NIST Computer Security Resource Center, slide 9

[Zero Trust Frameworks Architecture Guide - Cisco], page 4, section ''Policy Decision Point''


Contribute your Thoughts:

Gwenn
6 days ago
I think it's A) Policy. The governance rules that define the 'who, what, when, how, and why' aspects of accessing resources are all about policy.
upvoted 0 times
...
Blossom
10 days ago
I'm not sure, but I think it could also be D) Never trust, always verify, as it emphasizes the importance of verifying access.
upvoted 0 times
...
Paola
22 days ago
I agree with Laine, because policies define the rules for accessing resources.
upvoted 0 times
...
Laine
24 days ago
I think the answer is A) Policy.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77