4801
Zero-trust request ZT-001 in an authorized home-lab assessment evaluates a finance analyst requesting payroll API: managed device=yes, MFA=no, risk score=15. Policy requires an approved technical role, managed device, MFA, and risk below 60. What is the correct decision?
View answer choices
- Always allow because the request originates internally.
- Route around the policy through the default gateway.
- Always allow read-write access after one successful login.
- Deny or step up verification because the policy conditions are not all satisfied.