Question 1 of 30
In a corporate environment implementing a Zero Trust Architecture (ZTA), a security analyst is tasked with evaluating the access control policies for a newly deployed application that handles sensitive customer data. The application is hosted in a cloud environment and is accessed by employees from various locations, including remote workers and third-party vendors. The analyst must ensure that the access control mechanisms are robust and adhere to the principles of least privilege and continuous verification. Which of the following strategies would best align with the Zero Trust model to secure access to this application?
Implementing identity and access management (IAM) solutions that enforce multifactor authentication (MFA) and role-based access control (RBAC) for all users, regardless of their location or device.
Allowing unrestricted access to the application for all internal employees while requiring external vendors to authenticate using a single sign-on (SSO) solution.
Utilizing a traditional perimeter-based security model that relies on firewalls to restrict access to the application based on IP addresses.
Granting access to the application based solely on the user's job title and department, without additional verification measures.

Preparing for CISCO 350-701 Implementing and Operating Cisco Security Core Technologies (SCOR)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free