Every modern identity system answers these three questions in this order.
Prove the identity. Password, token, fingerprint. See the Auth Factors exploration.
Decide which resources and actions the authenticated identity may use. Independent from authentication.
Record the activity. Audit trails, session logs, command histories. Sometimes called "auditing" on the exam.
Which protocols support which letters, and what's special about each one.
The most-tested framework on the CCST. Originally five functions; CSF 2.0 (2024) added GOVERN as a sixth. Click any card for detail.
These show up in every framework and every audit question.
"Never trust, always verify."
The classic model trusted everything inside the firewall: get past the perimeter, roam freely. Zero Trust assumes the network is already breached and verifies every request based on identity and context, not network location. Pairs with least privilege and microsegmentation.