Study. uk . com
  1. Home
  2. All questions
  3. Question 355

CompTIA Security+ study material · question 355 of 611

A user's device falls out of compliance halfway through an authenticated session. Under zero trust, what should happen?

  1. The user should be prompted at their next login
  2. Nothing until the session's overall timeout
  3. The device should be removed from the inventory
  4. The authorisation decision should be re-evaluated
Show the answer

Answer: D. The authorisation decision should be re-evaluated

Zero trust policy is dynamic, so a material change in observable state should change the verdict mid-session.

Source: NIST SP 800-207 (NIST) — SP 800-207 § 2.1 Tenets

Challenge yourself on this topic → Study as cards