フリー問題

Splunk Certified Cybersecurity Defense Analyst のフリー問題 3 / 20 問目

問題文

A city transit agency SOC is documenting what its zero trust program does and does not address, so that the SOC does not stop monitoring for things the program leaves open. Which statements correctly describe the limits of a zero trust approach? (Select two.)

選択肢

  1. Zero trust makes data exfiltration impossible, since no request leaves the environment without an authorization decision.
  2. Removing implicit trust between internal segments limits how far an adversary can move, but it does not reduce the damage the adversary can do within the segment it already reached.
  3. Verifying every request does not stop an adversary who has taken over a legitimate account, because that adversary's requests are verified successfully.
  4. Zero trust removes the need for network traffic monitoring, since every request is authorized at the point of access and the authorization decision is a more reliable record than the traffic itself.
  5. Zero trust guarantees that credentials cannot be reused, since each request is evaluated independently of the previous one.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。