A. Virtual firewalls.
B. Verifying identity and context through a secure identity provider.
C. SSL/TLS inspection.
D. Data Loss Prevention (out-of-band and inline).
A. Issue a log that can be interpreted in a modern SOC.
B. State a conditional allow or a conditional block.
C. Designate an initiator as always trustworthy or always untrustworthy.
D. Track network bandwidth utilization across destination application categories.
A. True
B. False
A. An assessment of all things related to the current connection, previous context, and considered on an ongoing basis for future requests, thus allowing for unique and dynamic changes in the consideration of risk.
B. An ongoing process to verify publicly known bad actor IP addresses.
C. Universal control across the entire enterprise. Once assessed, risk applies to all traffic from that enterprise.
D. A non-recurring process to determine how to treat requests from a specific initiator for the next 30 days.
A. Should never be trusted.
B. 100% trusted, as cloud providers make sure content is safe before it is uploaded.
C. Considered risky until inspected, either through inline SSL/TLS controls or through assessing the files"at rest" using an out-of-band assessment.
D. Partially trusted depending on whether you maintain a proper audit log for access.
A. Independent of any network for control or trust.
B. Highly dependent on the network type, including whether that network is IPv4 or IPv6.
C. Based purely on a network appliance, constrained by how much CPU may be available.
D. Hairpinned through service chaining by an SD-WAN appliance.
A. Logging violations in a public database.
B. Re-categorization of an initiator, and their organization, so that subsequent access requests are limited, deceived, or stopped.
C. Deploying best-in-class security appliances.
D. Permanent quarantining of devices in a particular VLAN.