フリー問題

Certificate of Competence in Zero Trust (CCZT) のフリー問題 18 / 20 問目

問題文

A team asks whether the model stops an attacker who holds valid credentials for an account. What is stated?

選択肢

  1. The model prevents all credential-based attacks, which is why multi-factor authentication becomes optional once the architecture is in place.
  2. An attacker with valid credentials, or a malicious insider, may still access resources the account has been granted, though the architecture should prevent access outside its normal purview.
  3. Attackers with valid credentials are stopped at the enforcement point because the posture of the device is evaluated independently of the credential presented.
  4. Valid credentials are insufficient by themselves because device authentication always blocks the request, so credential theft is fully mitigated.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。