Posts

Showing posts with the label SY0-701

Threat Scope Reduction Explained: Zero Trust for the Security+ Exam

Zero Trust is usually summed up as "never trust, always verify." The phrase is accurate and almost useless — it describes an attitude without describing a mechanism. Threat scope reduction is one of the actual mechanisms, and it is a named term in the CompTIA Security+ SY0-701 objectives. The idea fits in one sentence. Threat scope reduction means limiting what any single user, device, or account can reach, so that a compromise stays small. Notice what that is not promising. It does not prevent the breach. It contains it. Traditional perimeter security assumed that anything inside the network was trustworthy, which meant an attacker who phished one set of credentials inherited everything that account could touch. Threat scope reduction removes the assumption by making sure no single account is worth very much on its own. Where It Sits in the Zero Trust Model Security+ divides the Zero Trust architecture into a control plane and a data plane . Threat scope reducti...