QuestionQ10

Security Engineering

A security engineer receives these findings from a recent security audit:

  • Data must be protected according to user permissions and roles.
  • User-action tracking must be implemented throughout the network.
  • Digital identities must be verified across the data-access workflow.

Which of the following should the engineer do first to address these findings?

Explanation

A Zero Trust access model continuously authenticates identities and authorizes each access request using contextual signals, while enforcing least-privilege, role- and permission-based access to data. This establishes the identity and authorization control plane needed to validate digital identities throughout the access workflow and provides the access events needed for user-action tracking.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!