Study. uk . com
  1. Home
  2. All questions
  3. Question 361

CompTIA Security+ study material · question 361 of 611

Which external inputs may a zero trust policy engine consult when scoring a request?

  1. Threat intelligence, device inventories and identity systems
  2. Only the destination resource's classification
  3. Only the user's credentials
  4. Only the network segment the request originated from
Show the answer

Answer: A. Threat intelligence, device inventories and identity systems

The engine draws on several sources so the decision reflects current state rather than a static grant.

Source: NIST SP 800-207 (NIST) — SP 800-207 § 3.1 Logical Components

Challenge yourself on this topic → Study as cards