Zero Trust Flashcards

(12 cards)

1
Q

Zero Trust

A

Zero trust → security model that assumes no implicit trust and requires continuous verification for every access request.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

MFA

A

Multifactor authentication (MFA) → authentication method requiring two or more verification factors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Planes of Operation

A

Planes of operation → logical layers in zero trust architecture that separate data processing and control decisions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Data Plane

A

Data plane → handles the actual transmission of data between systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Control Plane

A

Control plane → manages access decisions, policies, and traffic control.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Adaptive Identity

A

Adaptive identity → dynamic authentication based on user behavior, context, and risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Threat Scope Reduction

A

Threat scope reduction → shrinks the potential attack surface by limiting access, isolating elements, and enforcing strict controls. Often a key part of Zero Trust architecture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Policy-Driven Access Control

A

Policy-driven access control → enforces access decisions based on predefined security policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Security Zones

A

Security zones → segmented network areas that isolate resources based on trust levels.

Examples: Public (internet), Internal (LAN), DMZ (Web Servers), etc. they all have their own rules and permissions based on needed security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

PEP

A

Policy enforcement point (PEP) → component that enforces access decisions.

The bouncer at a party

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

PDP

A

Policy decision point (PDP) → component that evaluates access requests against policies. Tells the PEP whether to allow or deny access.

The guest list at a party

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Policy Engine and Policy Administrator

A

Policy engine and policy administrator → systems that evaluate policies and manage enforcement actions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly