Study. uk . com
  1. Home
  2. All questions
  3. Question 377

CompTIA Security+ study material · question 377 of 611

A zero trust enforcement point adds several seconds to every request. Why is this a design failure and not merely a performance issue?

  1. Because NIST forbids inline enforcement
  2. Because the policy engine cannot cache decisions
  3. Because latency invalidates the policy decision
  4. Because a design that harms availability will be routed around in practice
Show the answer

Answer: D. Because a design that harms availability will be routed around in practice

Zero trust designs must maintain availability and minimise delay, or users and teams will build paths around them.

Source: NIST SP 800-207 (NIST) — SP 800-207 § 2 Zero Trust Basics

Challenge yourself on this topic → Study as cards