Topic 02 Practice Test 2 covers Fundamental Security Concepts for CompTIA Security+ SY0-701 and maps to objective 1.2: Summarize fundamental security concepts. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
Which Zero Trust component establishes or terminates the communication path after receiving the policy decision?
- Policy administrator
- Authorization
- Availability
- Accounting
Correct Answer: A
Correct Answer
Answer A is correct because Policy administrator means the Zero Trust component that establishes or terminates the communication path after receiving the policy decision. The deciding point is functional fit: this option covers the stated need, while Accounting addresses the recording and tracking of security-relevant actions for auditing and accountability.
Incorrect Answers
Answer B is incorrect because Authorization refers to the process of determining what an authenticated identity is allowed to do. The concept is valid, but it does not match this stem. The required function is the Zero Trust component that establishes or terminates the communication path after receiving the policy decision, which maps to Policy administrator.
Answer C is incorrect because Availability refers to the security objective of keeping systems and information accessible to authorized users when needed. The key mismatch is functional: Policy administrator addresses the Zero Trust component that establishes or terminates the communication path after receiving the policy decision, the need stated by the question.
Answer D is incorrect because Accounting refers to the recording and tracking of security-relevant actions for auditing and accountability. The question is not asking for this function. It is testing the Zero Trust component that establishes or terminates the communication path after receiving the policy decision, so Policy administrator is the stronger fit.
Question 2
To enforce the access decision at the boundary between a subject and a resource, which security approach should be selected?
- Accounting
- Zero Trust
- Bollard
- Policy enforcement point
Correct Answer: D
Correct Answer
Answer D is correct because Policy enforcement point means the component that actually allows, blocks, or terminates traffic according to policy decisions. That is the function the question is testing. Bollard would instead be used for a sturdy physical barrier positioned to prevent vehicles from reaching protected areas.
Incorrect Answers
Answer A is incorrect because Accounting refers to the recording and tracking of security-relevant actions for auditing and accountability. That concept can be valid in another scenario, but this question is testing the component that actually allows, blocks, or terminates traffic according to policy decisions; Policy enforcement point therefore fits the requirement more directly.
Answer B is incorrect because Zero Trust refers to a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access. That concept can be valid in another scenario, but this question is testing the component that actually allows, blocks, or terminates traffic according to policy decisions; Policy enforcement point therefore fits the requirement more directly.
Answer C is incorrect because Bollard refers to a sturdy physical barrier positioned to prevent vehicles from reaching protected areas. This could be appropriate elsewhere, but the required function is the component that actually allows, blocks, or terminates traffic according to policy decisions; that makes Policy enforcement point the precise choice.
Question 3
To identify missing controls, capabilities, or compliance requirements, which security approach should be selected?
- Access badge
- Gap analysis
- Availability
- Confidentiality
Correct Answer: B
Correct Answer
Answer B is correct because Gap analysis means a comparison of the current security state with a required or desired target state. This is the precise fit for the scenario. Access badge serves the different purpose of a physical or electronic credential used to identify and permit authorized personnel into a facility.
Incorrect Answers
Answer A is incorrect because Access badge refers to a physical or electronic credential used to identify and permit authorized personnel into a facility. The scenario instead requires a comparison of the current security state with a required or desired target state, which is why Gap analysis is the better answer; this option serves the different function defined above.
Answer C is incorrect because Availability refers to the security objective of keeping systems and information accessible to authorized users when needed. The scenario instead requires a comparison of the current security state with a required or desired target state, which is why Gap analysis is the better answer; this option serves the different function defined above.
Answer D is incorrect because Confidentiality refers to the security objective of preventing unauthorized disclosure of information. The key mismatch is functional: Gap analysis addresses a comparison of the current security state with a required or desired target state, the need stated by the question.
Question 4
To observe attacker behavior across multiple realistic decoy assets, which security approach should be selected?
- Policy administrator
- Honeynet
- Confidentiality
- Integrity
Correct Answer: B
Correct Answer
Answer B is correct because Honeynet means a network of decoy systems designed to provide a broader deception environment. That is the function the question is testing. Policy administrator would instead be used for the Zero Trust component that establishes or terminates the communication path after receiving the policy decision.
Incorrect Answers
Answer A is incorrect because Policy administrator refers to the Zero Trust component that establishes or terminates the communication path after receiving the policy decision. The question is not asking for this function. It is testing a network of decoy systems designed to provide a broader deception environment, so Honeynet is the stronger fit.
Answer C is incorrect because Confidentiality refers to the security objective of preventing unauthorized disclosure of information. The scenario instead requires a network of decoy systems designed to provide a broader deception environment, which is why Honeynet is the better answer; this option serves the different function defined above.
Answer D is incorrect because Integrity refers to the security objective of preventing unauthorized or undetected modification of data and systems. The concept is valid, but it does not match this stem. The required function is a network of decoy systems designed to provide a broader deception environment, which maps to Honeynet.
Question 5
The control set for a zero-trust and foundational-security design review must address both component that actually allows, blocks, or terminates traffic according to policy decisions and physical or electronic credential used to identify and permit authorized personnel into a facility. Which TWO choices map directly to those needs? Choose TWO.
- Authentication
- Gap analysis
- Policy enforcement point
- Access badge
- Honeytoken
Correct Answers: C, D
Correct Answers
Answer C is correct because Policy enforcement point means the component that actually allows, blocks, or terminates traffic according to policy decisions. One required function is exactly what this option provides. Gap analysis may be useful elsewhere, but it is used for a comparison of the current security state with a required or desired target state. This question specifically tests the combined requirements represented by Policy enforcement point and Access badge.
Answer D is correct because Access badge means a physical or electronic credential used to identify and permit authorized personnel into a facility. It belongs in the fixed-count answer set because it covers one of the stated requirements. Honeytoken instead serves a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Authentication means the process of verifying the identity of a user, device, or other entity. The fixed-count answer set is Policy enforcement point, Access badge; this option does not fill one of those named functions.
Answer B is incorrect because Gap analysis means a comparison of the current security state with a required or desired target state. Every answer slot must map to a stated requirement. The correct set is Policy enforcement point, Access badge, so this option cannot replace one of those selections.
Answer E is incorrect because Honeytoken means a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched. Every answer slot must map to a stated requirement. The correct set is Policy enforcement point, Access badge, so this option cannot replace one of those selections.
Question 6
To translate an access decision into actions that create or remove a session, which security approach should be selected?
- Policy engine
- Honeynet
- Policy administrator
- Honeypot
Correct Answer: C
Correct Answer
Answer C is correct because Policy administrator means the Zero Trust component that establishes or terminates the communication path after receiving the policy decision. The deciding point is functional fit: this option covers the stated need, while Honeynet addresses a network of decoy systems designed to provide a broader deception environment.
Incorrect Answers
Answer A is incorrect because Policy engine refers to the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed. The concept is valid, but it does not match this stem. The required function is the Zero Trust component that establishes or terminates the communication path after receiving the policy decision, which maps to Policy administrator.
Answer B is incorrect because Honeynet refers to a network of decoy systems designed to provide a broader deception environment. The scenario instead requires the Zero Trust component that establishes or terminates the communication path after receiving the policy decision, which is why Policy administrator is the better answer; this option serves the different function defined above.
Answer D is incorrect because Honeypot refers to a decoy system or service intended to attract and observe malicious activity. The scenario instead requires the Zero Trust component that establishes or terminates the communication path after receiving the policy decision, which is why Policy administrator is the better answer; this option serves the different function defined above.
Question 7
Two requirements remain open in a zero-trust and foundational-security design review: assurance that a party cannot credibly deny having performed a specific action or sent a specific message; process of verifying the identity of a user, device, or other entity. Which TWO options close those specific gaps? Choose TWO.
- Availability
- Integrity
- Authentication
- Non-repudiation
- Policy administrator
Correct Answers: C, D
Correct Answers
Answer C is correct because Authentication means the process of verifying the identity of a user, device, or other entity. This selection maps directly to one of the named needs. Availability addresses the security objective of keeping systems and information accessible to authorized users when needed, so it does not satisfy the same slot.
Answer D is correct because Non-repudiation means assurance that a party cannot credibly deny having performed a specific action or sent a specific message. The fixed-count item needs this function in the answer set. Integrity covers the security objective of preventing unauthorized or undetected modification of data and systems, a different requirement.
Incorrect Answers
Answer A is incorrect because Availability means the security objective of keeping systems and information accessible to authorized users when needed. The question requires exactly 2 selections: Authentication, Non-repudiation. This option falls outside that required set. For example, Authentication is required for the process of verifying the identity of a user, device, or other entity.
Answer B is incorrect because Integrity means the security objective of preventing unauthorized or undetected modification of data and systems. The scenario calls for Authentication, Non-repudiation. Selecting this option would leave one of those required functions uncovered. For example, Authentication is required for the process of verifying the identity of a user, device, or other entity.
Answer E is incorrect because Policy administrator means the Zero Trust component that establishes or terminates the communication path after receiving the policy decision. The fixed-count answer set is Authentication, Non-repudiation; this option does not fill one of those named functions.
Question 8
Which term describes assurance that a party cannot credibly deny having performed a specific action or sent a specific message?
- Confidentiality
- Non-repudiation
- Authorization
- Policy administrator
Correct Answer: B
Correct Answer
Answer B is correct because Non-repudiation means assurance that a party cannot credibly deny having performed a specific action or sent a specific message. This matches the requirement as written. Authorization can be valid in another context, but it is used for the process of determining what an authenticated identity is allowed to do.
Incorrect Answers
Answer A is incorrect because Confidentiality refers to the security objective of preventing unauthorized disclosure of information. The concept is valid, but it does not match this stem. The required function is assurance that a party cannot credibly deny having performed a specific action or sent a specific message, which maps to Non-repudiation.
Answer C is incorrect because Authorization refers to the process of determining what an authenticated identity is allowed to do. The key mismatch is functional: Non-repudiation addresses assurance that a party cannot credibly deny having performed a specific action or sent a specific message, the need stated by the question. This question specifically tests the requirement represented by Non-repudiation.
Answer D is incorrect because Policy administrator refers to the Zero Trust component that establishes or terminates the communication path after receiving the policy decision. That concept can be valid in another scenario, but this question is testing assurance that a party cannot credibly deny having performed a specific action or sent a specific message; Non-repudiation therefore fits the requirement more directly.
Question 9
What is the process of verifying the identity of a user, device, or other entity?
- Authentication
- Non-repudiation
- Accounting
- Policy administrator
Correct Answer: A
Correct Answer
Answer A is correct because Authentication means the process of verifying the identity of a user, device, or other entity. That is the function the question is testing. Non-repudiation would instead be used for assurance that a party cannot credibly deny having performed a specific action or sent a specific message.
Incorrect Answers
Answer B is incorrect because Non-repudiation refers to assurance that a party cannot credibly deny having performed a specific action or sent a specific message. This could be appropriate elsewhere, but the required function is the process of verifying the identity of a user, device, or other entity; that makes Authentication the precise choice.
Answer C is incorrect because Accounting refers to the recording and tracking of security-relevant actions for auditing and accountability. The question is not asking for this function. It is testing the process of verifying the identity of a user, device, or other entity, so Authentication is the stronger fit.
Answer D is incorrect because Policy administrator refers to the Zero Trust component that establishes or terminates the communication path after receiving the policy decision. The question is not asking for this function. It is testing the process of verifying the identity of a user, device, or other entity, so Authentication is the stronger fit.
Question 10
Which Zero Trust decision component evaluates policy and contextual signals to determine whether access should be allowed?
- Authorization
- Access badge
- Policy engine
- Policy enforcement point
Correct Answer: C
Correct Answer
Answer C is correct because Policy engine means the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed. The deciding point is functional fit: this option covers the stated need, while Authorization addresses the process of determining what an authenticated identity is allowed to do.
Incorrect Answers
Answer A is incorrect because Authorization refers to the process of determining what an authenticated identity is allowed to do. That concept can be valid in another scenario, but this question is testing the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed; Policy engine therefore fits the requirement more directly.
Answer B is incorrect because Access badge refers to a physical or electronic credential used to identify and permit authorized personnel into a facility. The scenario instead requires the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed, which is why Policy engine is the better answer; this option serves the different function defined above.
Answer D is incorrect because Policy enforcement point refers to the component that actually allows, blocks, or terminates traffic according to policy decisions. The scenario instead requires the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed, which is why Policy engine is the better answer; this option serves the different function defined above.
Question 11
To limit access through explicit verification and least-privilege decisions, which security approach should be selected?
- Zero Trust
- Non-repudiation
- Honeytoken
- Policy engine
Correct Answer: A
Correct Answer
Answer A is correct because Zero Trust means a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access. This is the precise fit for the scenario. Honeytoken serves the different purpose of a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched.
Incorrect Answers
Answer B is incorrect because Non-repudiation refers to assurance that a party cannot credibly deny having performed a specific action or sent a specific message. The key mismatch is functional: Zero Trust addresses a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access, the need stated by the question.
Answer C is incorrect because Honeytoken refers to a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched. The concept is valid, but it does not match this stem. The required function is a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access, which maps to Zero Trust.
Answer D is incorrect because Policy engine refers to the Zero Trust decision component that evaluates policy and contextual signals to determine whether access should be allowed. The concept is valid, but it does not match this stem. The required function is a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access, which maps to Zero Trust.
Question 12
Reviewers working through a zero-trust and foundational-security design review identify three separate needs: recording and tracking of security-relevant actions for auditing and accountability; security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access; network of decoy systems designed to provide a broader deception environment. Which THREE choices map to those needs? Choose THREE.
- Gap analysis
- Access control vestibule
- Zero Trust
- Honeytoken
- Accounting
- Honeynet
Correct Answers: C, E, F
Correct Answers
Answer C is correct because Zero Trust means a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access. This selection maps directly to one of the named needs. Gap analysis addresses a comparison of the current security state with a required or desired target state, so it does not satisfy the same slot.
Answer E is correct because Accounting means the recording and tracking of security-relevant actions for auditing and accountability. It belongs in the fixed-count answer set because it covers one of the stated requirements. Gap analysis instead serves a comparison of the current security state with a required or desired target state and cannot replace this function.
Answer F is correct because Honeynet means a network of decoy systems designed to provide a broader deception environment. It belongs in the fixed-count answer set because it covers one of the stated requirements. Gap analysis instead serves a comparison of the current security state with a required or desired target state and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Gap analysis means a comparison of the current security state with a required or desired target state. The fixed-count answer set is Honeynet, Zero Trust, Accounting; this option does not fill one of those named functions.
Answer B is incorrect because Access control vestibule means a physical entry design that uses two controlled doors so only one is open at a time. The question requires exactly 3 selections: Honeynet, Zero Trust, Accounting. This option falls outside that required set.
Answer D is incorrect because Honeytoken means a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched. The fixed-count answer set is Honeynet, Zero Trust, Accounting; this option does not fill one of those named functions.
Question 13
During a zero-trust and foundational-security design review, the team has two independent requirements: (1) component that actually allows, blocks, or terminates traffic according to policy decisions; and (2) fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched. Which TWO choices best satisfy those requirements? Choose TWO.
- Bollard
- Non-repudiation
- Policy enforcement point
- Honeytoken
- Authorization
Correct Answers: C, D
Correct Answers
Answer C is correct because Policy enforcement point means the component that actually allows, blocks, or terminates traffic according to policy decisions. The fixed-count item needs this function in the answer set. Bollard covers a sturdy physical barrier positioned to prevent vehicles from reaching protected areas, a different requirement.
Answer D is correct because Honeytoken means a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched. One required function is exactly what this option provides. Non-repudiation may be useful elsewhere, but it is used for assurance that a party cannot credibly deny having performed a specific action or sent a specific message.
Incorrect Answers
Answer A is incorrect because Bollard means a sturdy physical barrier positioned to prevent vehicles from reaching protected areas. The question requires exactly 2 selections: Honeytoken, Policy enforcement point. This option falls outside that required set. For example, Honeytoken is required for a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched.
Answer B is incorrect because Non-repudiation means assurance that a party cannot credibly deny having performed a specific action or sent a specific message. The required choices are Honeytoken, Policy enforcement point. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer E is incorrect because Authorization means the process of determining what an authenticated identity is allowed to do. The required choices are Honeytoken, Policy enforcement point. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 14
To maintain reliable access despite failures, attacks, or capacity problems, which security approach should be selected?
- Availability
- Honeytoken
- Integrity
- Gap analysis
Correct Answer: A
Correct Answer
Answer A is correct because Availability means the security objective of keeping systems and information accessible to authorized users when needed. That makes it the best answer here; Honeytoken addresses a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched, not the function requested in the stem.
Incorrect Answers
Answer B is incorrect because Honeytoken refers to a fake credential, record, API key, or other data element that has no legitimate use and can reveal unauthorized access when touched. The question is not asking for this function. It is testing the security objective of keeping systems and information accessible to authorized users when needed, so Availability is the stronger fit.
Answer C is incorrect because Integrity refers to the security objective of preventing unauthorized or undetected modification of data and systems. The scenario instead requires the security objective of keeping systems and information accessible to authorized users when needed, which is why Availability is the better answer; this option serves the different function defined above.
Answer D is incorrect because Gap analysis refers to a comparison of the current security state with a required or desired target state. The concept is valid, but it does not match this stem. The required function is the security objective of keeping systems and information accessible to authorized users when needed, which maps to Availability.
Question 15
A review during a zero-trust and foundational-security design review identifies two gaps. One requires process of determining what an authenticated identity is allowed to do. The other requires comparison of the current security state with a required or desired target state. Which TWO options should be included in the remediation plan? Choose TWO.
- Honeypot
- Authentication
- Authorization
- Gap analysis
- Policy administrator
Correct Answers: C, D
Correct Answers
Answer C is correct because Authorization means the process of determining what an authenticated identity is allowed to do. This selection maps directly to one of the named needs. Honeypot addresses a decoy system or service intended to attract and observe malicious activity, so it does not satisfy the same slot.
Answer D is correct because Gap analysis means a comparison of the current security state with a required or desired target state. One required function is exactly what this option provides. Policy administrator may be useful elsewhere, but it is used for the Zero Trust component that establishes or terminates the communication path after receiving the policy decision.
Incorrect Answers
Answer A is incorrect because Honeypot means a decoy system or service intended to attract and observe malicious activity. Every answer slot must map to a stated requirement. The correct set is Authorization, Gap analysis, so this option cannot replace one of those selections.
Answer B is incorrect because Authentication means the process of verifying the identity of a user, device, or other entity. The fixed-count answer set is Authorization, Gap analysis; this option does not fill one of those named functions. For example, Authorization is required for the process of determining what an authenticated identity is allowed to do.
Answer E is incorrect because Policy administrator means the Zero Trust component that establishes or terminates the communication path after receiving the policy decision. The question requires exactly 2 selections: Authorization, Gap analysis. This option falls outside that required set.
Question 16
What is a sturdy physical barrier positioned to prevent vehicles from reaching protected areas?
- Honeynet
- Bollard
- Zero Trust
- Accounting
Correct Answer: B
Correct Answer
Answer B is correct because Bollard means a sturdy physical barrier positioned to prevent vehicles from reaching protected areas. That makes it the best answer here; Accounting addresses the recording and tracking of security-relevant actions for auditing and accountability, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Honeynet refers to a network of decoy systems designed to provide a broader deception environment. This could be appropriate elsewhere, but the required function is a sturdy physical barrier positioned to prevent vehicles from reaching protected areas; that makes Bollard the precise choice.
Answer C is incorrect because Zero Trust refers to a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access. The question is not asking for this function. It is testing a sturdy physical barrier positioned to prevent vehicles from reaching protected areas, so Bollard is the stronger fit.
Answer D is incorrect because Accounting refers to the recording and tracking of security-relevant actions for auditing and accountability. This could be appropriate elsewhere, but the required function is a sturdy physical barrier positioned to prevent vehicles from reaching protected areas; that makes Bollard the precise choice.
Question 17
What is a comparison of the current security state with a required or desired target state?
- Zero Trust
- Confidentiality
- Integrity
- Gap analysis
Correct Answer: D
Correct Answer
Answer D is correct because Gap analysis means a comparison of the current security state with a required or desired target state. That makes it the best answer here; Zero Trust addresses a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Zero Trust refers to a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access. The question is not asking for this function. It is testing a comparison of the current security state with a required or desired target state, so Gap analysis is the stronger fit.
Answer B is incorrect because Confidentiality refers to the security objective of preventing unauthorized disclosure of information. The question is not asking for this function. It is testing a comparison of the current security state with a required or desired target state, so Gap analysis is the stronger fit.
Answer C is incorrect because Integrity refers to the security objective of preventing unauthorized or undetected modification of data and systems. The key mismatch is functional: Gap analysis addresses a comparison of the current security state with a required or desired target state, the need stated by the question.
Question 18
To confirm who or what is requesting access, which security approach should be selected?
- Confidentiality
- Honeynet
- Policy enforcement point
- Authentication
Correct Answer: D
Correct Answer
Answer D is correct because Authentication means the process of verifying the identity of a user, device, or other entity. That is the function the question is testing. Policy enforcement point would instead be used for the component that actually allows, blocks, or terminates traffic according to policy decisions.
Incorrect Answers
Answer A is incorrect because Confidentiality refers to the security objective of preventing unauthorized disclosure of information. That concept can be valid in another scenario, but this question is testing the process of verifying the identity of a user, device, or other entity; Authentication therefore fits the requirement more directly.
Answer B is incorrect because Honeynet refers to a network of decoy systems designed to provide a broader deception environment. The scenario instead requires the process of verifying the identity of a user, device, or other entity, which is why Authentication is the better answer; this option serves the different function defined above.
Answer C is incorrect because Policy enforcement point refers to the component that actually allows, blocks, or terminates traffic according to policy decisions. This could be appropriate elsewhere, but the required function is the process of verifying the identity of a user, device, or other entity; that makes Authentication the precise choice.
Question 19
During a zero-trust and foundational-security design review, the team has two independent requirements: (1) assurance that a party cannot credibly deny having performed a specific action or sent a specific message; and (2) security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access. Which TWO choices best satisfy those requirements? Choose TWO.
- Policy administrator
- Authorization
- Non-repudiation
- Zero Trust
- Bollard
Correct Answers: C, D
Correct Answers
Answer C is correct because Non-repudiation means assurance that a party cannot credibly deny having performed a specific action or sent a specific message. This selection maps directly to one of the named needs. Authorization addresses the process of determining what an authenticated identity is allowed to do, so it does not satisfy the same slot.
Answer D is correct because Zero Trust means a security approach that avoids implicit trust and continuously evaluates identity, device, context, and policy before allowing access. This option satisfies a specific requirement in the stem; Authorization serves the process of determining what an authenticated identity is allowed to do and therefore is not interchangeable with it.
Incorrect Answers
Answer A is incorrect because Policy administrator means the Zero Trust component that establishes or terminates the communication path after receiving the policy decision. The required choices are Non-repudiation, Zero Trust. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer B is incorrect because Authorization means the process of determining what an authenticated identity is allowed to do. Every answer slot must map to a stated requirement. The correct set is Non-repudiation, Zero Trust, so this option cannot replace one of those selections.
Answer E is incorrect because Bollard means a sturdy physical barrier positioned to prevent vehicles from reaching protected areas. The required choices are Non-repudiation, Zero Trust. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 20
To reduce tailgating and tightly control entry into a restricted area, which security approach should be selected?
- Authentication
- Bollard
- Access control vestibule
- Confidentiality
Correct Answer: C
Correct Answer
Answer C is correct because Access control vestibule means a physical entry design that uses two controlled doors so only one is open at a time. That is the function the question is testing. Confidentiality would instead be used for the security objective of preventing unauthorized disclosure of information.
Incorrect Answers
Answer A is incorrect because Authentication refers to the process of verifying the identity of a user, device, or other entity. This could be appropriate elsewhere, but the required function is a physical entry design that uses two controlled doors so only one is open at a time; that makes Access control vestibule the precise choice.
Answer B is incorrect because Bollard refers to a sturdy physical barrier positioned to prevent vehicles from reaching protected areas. The question is not asking for this function. It is testing a physical entry design that uses two controlled doors so only one is open at a time, so Access control vestibule is the stronger fit.
Answer D is incorrect because Confidentiality refers to the security objective of preventing unauthorized disclosure of information. That concept can be valid in another scenario, but this question is testing a physical entry design that uses two controlled doors so only one is open at a time; Access control vestibule therefore fits the requirement more directly.