問題文
A company currently gives remote staff an address on the corporate network and relies on internal controls from there. What changes if it moves to Zero Trust Network Access?
選択肢
- The applications are published on the public internet so that no tunnel is needed, and the stronger sign-in page placed in front of each one then carries the whole defense.
- The remote session keeps its position on the internal network, but the internal controls are applied twice instead of once, which is the change that limits what the session can reach and is the reason the approach is described as being based on the assumption of zero trust.
- The remote session no longer has a position on the internal network at all, so what it can reach is limited to the applications that were explicitly granted.
- The staff no longer need to authenticate, because a session that has been narrowed to one named application cannot be misused even if somebody else is using the device.