Section 2 - Lesson 15 Flashcards

Zero Trust (16 cards)

1
Q

What is Zero Trust slogan?

A

“Trust nothing and verify everything”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What two planes do we need to zero trust implementation?

A

Control Plane, Data Plane

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Control Plane

A

Policies and procedures. The overwatching framework and set of components responsible for defining, managing and enforcing policies related to user and system access within an organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Data Plane

A

Ensures policies and procedures are properly executed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are elements of control plane?

A

Adaptive identity, Threat scope reduction, Policy-driven access control, Secured zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Adapted Identity

A

Rely on real-time validation, that takes int account user’s behavior, device, location and more

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Threat scope reduction

A

Reduce user access to only what they need to do their work tasks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Policy-driven access control

A

Developing, managing and enforcing user access policies based on their roles and responsibilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Secured zones

A

Isolated environments within network that store sensitive data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Policy Engine in Control Plane

A

Checks the access request against predefined policies. “Is this request allowed by rules?”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Policy Administrator in Control Plane

A

Establish and manage access policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What Control Plane consist of?

A

Policy Engine and Policy Administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What Data Plane consist of?

A

Subject/System and Policy Enforcement Point

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Subject/System in Data Plane

A

Individual or Entity attempting to gain access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Policy Enforcement Point in Data Plane

A

Allow or restrict access. Acts as gatekeeper to the sensitive areas of system or network. This is were decision about access or denial is made.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Zero Trus?

A

Cybersecurity approach that assumes no user or system is trusted by default and requires continuous verification for access to organizational resources