2.2 - Zero trust Flashcards

(9 cards)

1
Q

What is Zero Trust?

A

It is a security framework that requires all subjects, assets, and workflows to be authenticated, authorised and continuously validated before allowing access to applications and data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the main principles of zero trust

A

Continuous verification - always verify access

Access Limitation - Access is granted on per-session basis (has a time limit)

Limit the ‘blast radius’ - Minimise impact if internal or external resources are breached (e.g. segmentation, least privilege

Automate - Context, collection, and response are meant to be automatically collected (e.g. credentials, workloads, endpoints SIEMS, Threat intelligence

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the ZT components

A

Policy Decision Point (PDP)

Policy Engine (PE)

Policy Administrator (PA)

Policy Enforcement Point (PEP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a control plane

A

It is a system that management and coordinates access to resources, handles authentication, authorisation and policy enforcement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the data plane

A

This is where the application and service communication flows, it handles the actual data transfer and processing (moves data between software components

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the Policy Decision Point (PDP)?

A

PDP has two logical components Policy engine and policy administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the Policy Engine (PE)?

A

Policy Engine (PE) - responsible for the ultimate decision to grant access to the given subject

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the Policy Administrator (PA)?

A

Generates any session-specific authentication, authentication token, or credential used to access an enterprise resource

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the Policy Enforcement Point (PEP)?

A

Responsible for enabling monitoring, and eventually termination connections between a subject and an enterprise resource

How well did you know this?
1
Not at all
2
3
4
5
Perfectly