
2024年最新のCCZT問題集を試そう!更新されたCloud Security Alliance試験合格させます
最新のCCZT試験問題集でCloud Security Alliance試験にはトレーニングを提供しています
質問 # 37
SDP incorporates single-packet authorization (SPA). After
successful authentication and authorization, what does the client
usually do next? Select the best answer.
- A. Generates an SPA packet and sends it to the gateway.
- B. Generates an SPA packet and sends it to the initiating host.
- C. Generates an SPA packet and sends it to the controller.
- D. Generates an SPA packet and sends it to the accepting host.
正解:C
解説:
Explanation
After successful authentication and authorization, the client typically sends an SPA packet to the controller, which acts as an intermediary in authenticating the client's request before access to the accepting host is granted. References = Certificate of Competence in Zero Trust (CCZT) - Cloud Security Alliance, Zero Trust Training (ZTT) - Module 9: Risk Management
質問 # 38
During ZT planning, which of the following determines the scope of
the target state definition? Select the best answer.
- A. Risk register
- B. Risk assessment
- C. Risk appetite
- D. Service level agreements
正解:B
解説:
Explanation
Risk assessment is the process of identifying, analyzing, and evaluating the risks that an organization faces in achieving its objectives. Risk assessment helps to determine the scope of the target state definition for ZT planning, as it identifies the critical assets, threats, vulnerabilities, and impacts that need to be addressed by ZT capabilities and activities. Risk assessment also helps to prioritize and align the ZT planning with the organization's risk appetite and tolerance levels.
質問 # 39
In a ZTA, what is a key difference between a policy decision point
(PDP) and a policy enforcement point (PEP)?
- A. A PDP measures incoming signals against a set of access
determination criteria. A PEP uses incoming signals to open or close a
connection. - B. A PDP measures incoming signals in an untrusted zone. A PEP
measures incoming signals in an implicit trust zone. - C. A PDP measures incoming signals and makes dynamic risk
determinations. A PEP uses incoming signals to make static risk
determinations. - D. A PDP measures incoming control plane authentication signals. A
PEP measures incoming data plane authorization signals.
正解:A
解説:
Explanation
In a ZTA, a policy decision point (PDP) is a logical component that evaluates the incoming signals from an entity requesting access to a resource against a set of access determination criteria, such as identity, context, device, location, and behavior1. A PDP then makes a decision to grant or deny access, or to request additional information or verification, based on the policies defined by the policy administrator1. A policy enforcement point (PEP) is a logical component that uses the incoming signals from the PDP to open or close a connection between the entity and the resource1. A PEP acts as a gateway or intermediary that enforces the decision made by the PDP and prevents unauthorized or risky access2.
References =
Zero Trust Architecture | NIST
Policy Enforcement Point (PEP) - Pomerium
質問 # 40
In a ZTA, the logical combination of both the policy engine (PE) and
policy administrator (PA) is called
- A. data access policy
- B. policy decision point (PDP)
- C. role-based access
- D. policy enforcement point (PEP)
正解:B
解説:
Explanation
In a ZTA, the logical combination of both the policy engine (PE) and policy administrator (PA) is called the policy decision point (PDP). The PE is the component that evaluates the policies and the contextual data collected from various sources and generates an access decision. The PA is the component that establishes or terminates the communication between a subject and a resource based on the access decision. The PDP communicates with the policy enforcement point (PEP), which enforces the access decision on the resource.
References =
Certificate of Competence in Zero Trust (CCZT) prepkit, page 14, section 2.2.2 Zero Trust Architecture Project - NIST Computer Security Resource Center, slide 9 What Is a Zero Trust Security Framework? | Votiro, section "The Policy Engine and Policy Administrator" Zero Trust Frameworks Architecture Guide - Cisco, page 4, section "Policy Decision Point"
質問 # 41
In a ZTA, where should policies be created?
- A. Data plane
- B. Control plane
- C. Network
- D. Endpoint
正解:B
解説:
Explanation
In a ZTA, policies should be created in the control plane, which is the logical component that defines and manages the policies for accessing resources. The control plane consists of policy entities, such as policy administrators, policy engines, and policy decision points, that are responsible for crafting, maintaining, evaluating, and enforcing the policies1. Thecontrol plane interacts with the data plane, which is the logical component that handles the data transmission and processing, and the network, which is the physical or virtual component that provides the connectivity and transport for the data plane1. The endpoint is the device or system that requests or provides access to a resource1.
References =
Zero Trust Architecture | NIST
質問 # 42
To respond quickly to changes while implementing ZT Strategy, an
organization requires a mindset and culture of
- A. learning and growth.
- B. project governance.
- C. continuous risk evaluation and policy adjustment.
- D. continuous process improvement.
正解:C
解説:
Explanation
To respond quickly to changes while implementing ZT Strategy, an organization requires a mindset and culture of continuous risk evaluation and policy adjustment. This means that the organization should constantly monitor the threat landscape, assess the security posture, and update the policies and controls accordingly to maintain a high level of protection and resilience. The organization should also embrace feedback, learning, and improvement as part of the ZT journey.
References =
Certificate of Competence in Zero Trust (CCZT) prepkit, page 7, section 1.3 Cultivating a Zero Trust mindset - AWS Prescriptive Guidance, section "Continuous learning and improvement" Zero Trust architecture: a paradigm shift in cybersecurity - PwC, section "Continuous monitoring and improvement"
質問 # 43
What should be a key component of any ZT project, especially
during implementation and adjustments?
- A. Frequent technology changes
- B. Extensive task monitoring
- C. Frequent policy audits
- D. Proper risk management
正解:D
解説:
Explanation
Proper risk management should be a key component of any ZT project, especially during implementation and adjustments, because it helps to identify, analyze, evaluate, and treat the potential risks that may affect the ZT and ZTA objectives and outcomes. Proper risk management also helps to prioritize the ZT and ZTA activities and resources based on the risk level and impact, and to monitor and review the risk mitigation strategies and actions.
References = Certificate of Competence in Zero Trust (CCZT) - Cloud Security Alliance, Zero Trust Training (ZTT) - Module 9: Risk Management
質問 # 44
When planning for ZT implementation, who will determine valid
users, roles, and privileges for accessing data as part of data
governance?
- A. Asset owners
- B. Application owners
- C. IT teams
- D. Compliance officers
正解:A
質問 # 45
When planning for a ZTA, a critical product of the gap analysis
process is______
Select the best answer.
- A. supporting data for the project business case
- B. the implementation's requirements
- C. a report on impacted identity and access management (IAM)
infrastructure - D. a responsible, accountable, consulted, and informed (RACI) chart
and communication plan
正解:B
解説:
Explanation
A critical product of the gap analysis process is the implementation's requirements, which are the specifications and criteria that define the desired outcomes, capabilities, and functionalities of the ZTA. The implementation's requirements are derived from the gap analysis, which identifies the current state, the target state, and the gaps between them. The implementation's requirements help to guide the design, development, testing, and deployment of the ZTA, as well as the evaluation of its effectiveness and alignment with the business objectives and needs.
References =
Zero Trust Planning - Cloud Security Alliance, section "Scope, Priority, & Business Case" The Zero Trust Journey: 4 Phases of Implementation - SEI Blog, section "Second Phase: Assess" Planning for a Zero Trust Architecture: A Planning Guide for Federal ..., section "Gap Analysis"
質問 # 46
When kicking off ZT planning, what is the first step for an
organization in defining priorities?
- A. Identifying the data and assets
- B. Determine current state
- C. Define the scope
- D. Define a business case
正解:B
解説:
Explanation
The first step for an organization in defining priorities for ZT planning is to determine the current state of its network, security, and business environment. This involves conducting a comprehensive assessment of the existing IT infrastructure, systems, applications, data, and assets, as well as the threats, risks, and vulnerabilities that affect them. The current state analysis also involves identifying the gaps, challenges, and opportunities for improvement in the current security posture, as well as the business goals, objectives, and requirements for ZT implementation12. By determining the current state, the organization can establish a baseline for measuring the progress and impact of ZT, as well as prioritize the most critical and urgent areas for ZT adoption.
References =
Planning for a Zero Trust Architecture: A Planning Guide for Federal Administrators | CSRC Publications NIST Zero Trust Architecture Explained: A Step-by-Step Approach - Comparitech
質問 # 47
ZTA utilizes which of the following to improve the network's security posture?
- A. Network communication and micro-segmentation
- B. Encryption and compliance analytics
- C. Compliance analytics and network communication
- D. Micro-segmentation and encryption
正解:D
解説:
Explanation
Verified Answer= A. Micro-segmentation and encryptionVery Short Explanation= ZTA uses micro-segmentation to divide the network into smaller, isolated segments that can prevent unauthorized access and contain lateral movement. ZTA also uses encryption to protect data in transit and at rest from eavesdropping and tampering.References=1,2,3,4
質問 # 48
Which activity of the ZT implementation preparation phase ensures
the resiliency of the organization's operations in the event of
disruption?
- A. Visibility and analytics
- B. Compliance
- C. Business continuity and disaster recovery
- D. Change management process
正解:C
解説:
Explanation
Business continuity and disaster recovery are the activities of the ZT implementation preparation phase that ensure the resiliency of the organization's operations in the event of disruption. Business continuity refers to the process of maintaining or restoring the essential functions of the organization during and after a crisis, such as a natural disaster, a cyberattack, or a pandemic. Disaster recovery refers to the process of recovering the IT systems, data, and infrastructure that support the business continuity. ZT implementation requires planning and testing the business continuity and disaster recovery strategies and procedures, as well as aligning them with the ZT policies and controls.
References =
Zero Trust Planning - Cloud Security Alliance, section "Monitor & Measure" Zero Trust architecture: a paradigm shift in cybersecurity - PwC, section "Continuous monitoring and improvement" Zero Trust Implementation, section "Outline Zero Trust Architecture (ZTA) implementation steps"
質問 # 49
Which element of ZT focuses on the governance rules that define
the "who, what, when, how, and why" aspects of accessing target
resources?
- A. Scrutinize explicitly
- B. Never trust, always verify
- C. Data sources
- D. Policy
正解:D
解説:
Explanation
Policy is the element of ZT that focuses on the governance rules that define the "who, what, when, how, and why" aspects of accessing target resources. Policy is the core component of a ZTA that determines the access decisions and controls for each request based on various attributes and factors, such as user identity, device posture, network location, resource sensitivity, and environmental context. Policy is also the element that enables the ZT principles of "never trust, always verify" and "scrutinize explicitly" by enforcing granular, dynamic, and data-driven rules for each access request.
References =
Certificate of Competence in Zero Trust (CCZT) prepkit, page 14, section 2.2.2 What Is Zero Trust Architecture (ZTA)? - F5, section "Policy Engine" Zero Trust Architecture Project - NIST Computer Security Resource Center, slide 9
[Zero Trust Frameworks Architecture Guide - Cisco], page 4, section "Policy Decision Point"
質問 # 50
Network architects should consider__________ before selecting an SDP model.
Select the best answer.
- A. gateways
- B. their use case
- C. leadership buy-in
- D. cost
正解:B
解説:
Explanation
Different SDP deployment models have different advantages and disadvantages depending on the organization's use case, such as the type of resources to be protected, the location of the clients and servers, the network topology, the scalability, the performance, and the security requirements. Network architects should consider their use case before selecting an SDP model that best suits their needs and goals.
References =
Certificate of Competence in Zero Trust (CCZT) prepkit, page 21, section 3.1.2
6 SDP Deployment Models to Achieve Zero Trust | CSA, section "Deployment Models Explained" Software-Defined Perimeter (SDP) and Zero Trust | CSA, page 7, section 3.1 Why SDP Matters in Zero Trust | SonicWall, section "SDP Deployment Models"
質問 # 51
What is one benefit of the protect surface in a ZTA for an
organization implementing controls?
- A. Controls can be implemented at the perimeter of the network and
minimize risk. - B. Controls can be implemented at all ingress and egress points of the
network and minimize risk. - C. Controls can be moved away from the asset and minimize risk.
- D. Controls can be moved closer to the asset and minimize risk.
正解:D
解説:
Explanation
The protect surface in a ZTA is the collection of sensitive data, assets, applications, and services (DAAS) that require protection from threats1. One benefit of the protect surface in a ZTA for an organization implementing controls is that it allows the controls to be moved closer to the asset and minimize risk. This means that instead of relying on a single perimeter or boundary to protect the entire network, ZTA enables granular and dynamic controlsthat are applied at or near the DAAS components, based on the principle of least privilege2. This reduces the attack surface and the potential impact of a breach, as well as improves the visibility and agility of the security posture3.
References =
Zero Trust Architecture | NIST
Zero Trust Architecture Explained: A Step-by-Step Approach - Comparitech What is Zero Trust Architecture (ZTA)? - CrowdStrike
質問 # 52
What is the function of the rule-based security policies configured
on the policy decision point (PDP)?
- A. Define rules that control the entitlements to assets
- B. Define rules that map roles to users
- C. Define rules that specify multi-factor authentication (MFA)
requirements - D. Define rules that specify how information can flow
正解:A
解説:
Explanation
Rule-based security policies are a type of attribute-based access control (ABAC) policies that define rules that control the entitlements to assets, such as data, applications, or devices, based on the attributes of the subjects, objects, and environment. The policy decision point (PDP) is the component in a zero trust architecture (ZTA) that evaluates the rule-based security policies and generates an access decision for each request.
References =
Certificate of Competence in Zero Trust (CCZT) prepkit, page 14, section 2.2.2 A Zero Trust Policy Model | SpringerLink, section "Rule-Based Policies" Zero Trust architecture: a paradigm shift in cybersecurity - PwC, section "Security policy and control framework"
質問 # 53
Scenario: A multinational org uses ZTA to enhance security. They
collaborate with third-party service providers for remote access to
specific resources. How can ZTA policies authenticate third-party
users and devices for accessing resources?
- A. ZTA policies should prioritize securing remote users through
technologies like virtual desktop infrastructure (VDI) and corporate
cloud workstation resources to reduce the risk of lateral movement via
compromised access controls. - B. ZTA policies should primarily educate users about secure practices
and promote strong authentication for services accessed via mobile
devices to prevent data compromise. - C. ZTA policies can implement robust encryption and secure access
controls to prevent access to services from stolen devices, ensuring
that only legitimate users can access mobile services. - D. ZTA policies can be configured to authenticate third-party users
and their devices, determining the necessary access privileges for
resources while concealing all other assets to minimize the attack
surface.
正解:D
解説:
Explanation
ZTA is based on the principle of never trusting any user or device by default, regardless of their location or ownership. ZTA policies can use various methods to verify the identity and context of third-party users and devices, such as tokens, certificates, multifactor authentication, device posture assessment, etc. ZTA policies can also enforce granular and dynamic access policies that grant the minimum necessary privileges to third-party users and devices for accessing specific resources, while hiding all other assets from their view.
This reduces the attack surface and prevents unauthorized access and lateral movement within the network.
質問 # 54
What should an organization's data and asset classification be based on?
- A. Location of data
- B. History of data
- C. Sensitivity of data
- D. Recovery of data
正解:C
解説:
Explanation
Data and asset classification should be based on the sensitivity of data, which is the degree to which the data requires protection from unauthorized access, modification, or disclosure. Data sensitivity is determined by the potential impact of data loss, theft, or corruption on the organization, its customers, and its partners. Data sensitivity can also be influenced by legal, regulatory, and contractual obligations.
References =
Certificate of Competence in Zero Trust (CCZT) prepkit, page 10, section 2.1.1 Identify and protect sensitive business data with Zero Trust, section 1 Secure data with Zero Trust, section 1 SP 800-207, Zero Trust Architecture, page 9, section 3.2.1
質問 # 55
......
更新されたテストエンジン練習CCZT問題集と練習試験:https://www.passtest.jp/Cloud-Security-Alliance/CCZT-shiken.html
合格できるCloud Security Alliance CCZTのPDF問題集で最近更新された62問あります:https://drive.google.com/open?id=16UO-9iDmz03Lvhq3p4kzzt7hxBsdmH-G