問題文
A team asks whether the model stops an attacker who holds valid credentials for an account. What is stated?
選択肢
- The model prevents all credential-based attacks, which is why multi-factor authentication becomes optional once the architecture is in place.
- An attacker with valid credentials, or a malicious insider, may still access resources the account has been granted, though the architecture should prevent access outside its normal purview.
- Attackers with valid credentials are stopped at the enforcement point because the posture of the device is evaluated independently of the credential presented.
- Valid credentials are insufficient by themselves because device authentication always blocks the request, so credential theft is fully mitigated.