CompTIA SecurityX (CAS-005) flashcards
156 free flashcards. Tap a card to flip it.
DNS Tunneling
Flip cardDNS tunneling is a data exfiltration or command-and-control technique that encodes data within DNS queries and responses to bypass firewalls and security controls.
- Uses UDP port 53, often overlooked by network defenses.
- Data is encapsulated within subdomains of DNS queries or TXT/NULL records.
- Can be used for C2 communication or data exfiltration.
Memory trick: Hidden Data Exits Covertly.
ImagePolicyWebhook
Flip cardA Kubernetes admission controller that allows external HTTP callbacks (webhooks) to validate or mutate admission requests for container images, enabling custom image policy enforcement.
- Kubernetes admission controller
- Uses external webhooks
- Enforces image-related policies
- Can restrict images to trusted registries
Memory trick: ImagePolicyWebhook: The gatekeeper for trusted container images.
Data Diode (Unidirectional Gateway)
Flip cardA hardware device that permits data flow in only one physical direction, ensuring absolute isolation and preventing any return path or back-channel communication.
- Physically enforced one-way data flow
- Provides absolute isolation
- Prevents data exfiltration
- Common in ICS/OT and high-security networks
Memory trick: Data Diode: One-way street for critical data.
Single Point of Failure (SPOF) Elimination
Flip cardAn architectural principle focused on identifying and mitigating any single component or logical path whose failure would cause the entire system or service to become unavailable.
- Achieved through redundancy, clustering, and failover.
- Crucial for high availability and business continuity.
- Applies to hardware, software, network paths, and data.
Memory trick: SPOF Elimination: 'Stop Points Of Failure' to keep systems running.
EDR for Lateral Movement
Flip cardEndpoint Detection and Response (EDR) solutions collect and analyze endpoint data (process execution, network connections, file system changes) to detect, investigate, and respond to threats like lateral movement and LOLBin abuse.
- Provides granular endpoint visibility.
- Detects anomalous process behavior.
- Tracks network connections originating from endpoints.
- Essential for post-compromise detection.
Memory trick: To find the thief, you need to look at the footprints they left.
Resilient Architecture
Flip cardA resilient architecture is designed to withstand and recover from various failures, attacks, or unexpected conditions, maintaining its core functionality and operations even when components are compromised or unavailable.
- Focuses on continuous operation despite disruptions.
- Achieved through redundancy, fault tolerance, isolation, graceful degradation.
- Adapts to changing conditions and recovers quickly.
- Critical for high-availability and critical infrastructure systems.
Memory trick: A strong building can bend but not break.
End-to-End Data Encryption
Flip cardThe practice of encrypting data at its origin and decrypting it only at its final destination, ensuring it remains protected throughout its entire lifecycle, including in transit and at rest.
- Protects data confidentiality from source to destination.
- Crucial for sensitive data, especially during cloud migrations.
- Combines encryption for data in transit (e.g., TLS) and at rest (e.g., disk encryption).
Memory trick: Moving sensitive data is like shipping valuables; you need a 'locked, armored truck' and a 'secure vault' at the destination.
Binary Reverse Engineering (Malware)
Flip cardThe process of deconstructing executable software (binaries) to understand its inner workings, algorithms, and logic, without access to the source code. It's essential for analyzing complex malware, especially when obfuscation is present, to develop countermeasures or identify vulnerabilities.
- Analyzes compiled code (binary).
- Reveals algorithms and logic (e.g., decryption).
- Bypasses obfuscation techniques.
- Requires specialized tools and skills (disassemblers, debuggers).
Memory trick: To Break the Ransomware's Code, Reverse Engineering is the Mode.
Static Application Security Testing (SAST)
Flip cardStatic Application Security Testing (SAST) is a white-box testing method that analyzes an application's source code, bytecode, or binary code without actually executing the application, to identify security vulnerabilities and coding errors.
- Performed early in the SDLC ('shift-left').
- Identifies vulnerabilities in custom code.
- Does not require a running application.
Memory trick: SAST is like a 'spell check' for security, catching errors before you even print.
Linux Process Forensics (/proc)
Flip cardThe `/proc` filesystem in Linux is a virtual filesystem that provides an interface to kernel data structures, allowing forensic investigators to examine running processes, their memory maps, open files, and other runtime information.
- Each process has a directory `/proc/<PID>/`.
- Contains `exe` (executable path), `cwd` (current working directory), `maps` (memory maps).
- Crucial for analyzing live system state and memory dumps.
Memory trick: Linux processes leave clues in /proc, even when deleted.
Geographic Redundancy
Flip cardThe practice of having duplicate critical systems and data in geographically separate locations to ensure continuous operation and data availability in the event of a regional disaster.
- Protects against large-scale outages (e.g., natural disasters).
- Often involves active/active or active/passive deployments across regions.
- Requires robust data replication strategies (synchronous for zero data loss).
Memory trick: Geographic Redundancy: 'Global Resilience' protects your data from any single point of failure.
Living Off The Land (LotL)
Flip cardAn attack technique where adversaries use legitimate, pre-installed tools and features already present on a compromised system (e.g., PowerShell, WMI, PsExec) to carry out malicious activities, making detection difficult.
- Uses legitimate system binaries and scripts.
- Avoids introducing new malware.
- Difficult to detect with signature-based methods.
Memory trick: Hunting for threats requires looking beyond the obvious.
Sidecar Proxy (Service Mesh)
Flip cardA lightweight proxy deployed alongside each application container (microservice) in a Kubernetes pod. It intercepts all network traffic to and from the microservice, offloading network and security functions from the application logic.
- Enables transparent mutual TLS (mTLS) between services.
- Enforces traffic policies and authorization.
- Removes security and network concerns from application code.
Memory trick: Sidecar Secures Inter-Service Connections.
HMAC
Flip cardHMAC (Hash-based Message Authentication Code) is a specific type of Message Authentication Code (MAC) involving a cryptographic hash function and a secret cryptographic key. It is used to simultaneously verify both the data integrity and the authenticity of a message.
- Provides both data integrity and authenticity.
- Uses a shared secret key.
- More efficient than digital signatures for integrity/authenticity.
- Does NOT provide confidentiality (encryption).
Memory trick: HMAC Keeps ICS Messages Honest and Authentic
Tokenization for PCI DSS SAD
Flip cardTokenization is a data security technique where sensitive data (like credit card numbers or Sensitive Authentication Data - SAD) is replaced with a unique, non-sensitive identifier called a token. For PCI DSS, this ensures SAD is never stored by the merchant after authorization, as only the token is retained.
- Replaces sensitive data with a non-sensitive token.
- Original data stored in a secure token vault (or discarded for SAD).
- Crucial for PCI DSS compliance, especially for SAD.
- Reduces the scope of PCI DSS for systems handling tokens.
Memory trick: Don't keep the real card details, just a fake ID.
MITRE ATT&CK Persistence
Flip cardThe MITRE ATT&CK 'Persistence' tactic describes techniques adversaries use to maintain their foothold in a system across reboots, changes in credentials, or other interruptions.
- Ensures continued access to a compromised system.
- Often involves modifying system startup mechanisms, creating new user accounts, or injecting code.
- Crucial for long-term operations by an attacker.
Memory trick: Initial Execution Persists to Evade Credentials.
Quantitative Risk Assessment
Flip cardAn objective, data-driven approach to risk assessment that assigns monetary values to assets, threats, vulnerabilities, and the potential losses from security incidents.
- Uses formulas like ALE = SLE x ARO to calculate financial risk.
- Provides a clear financial justification for security investments.
- Requires detailed data on asset values, incident frequency, and recovery costs.
Memory trick: Quantity counts the cash, quality describes the feel.
NIST Cybersecurity Framework (CSF)
Flip cardA voluntary framework for organizations to manage and reduce cybersecurity risk.
- Composed of five core functions: Identify, Protect, Detect, Respond, Recover.
- Designed to be flexible and adaptable to various sectors and organizational types.
- Enables communication of cybersecurity risk across an organization.
Memory trick: NIST for critical, flexible, and clear.
Data Localization (Data Residency)
Flip cardThe requirement that certain data must be stored and processed within the geographical borders of a specific country or region, often due to legal or regulatory mandates.
- Ensures compliance with national data protection laws.
- Impacts cloud deployment strategies and data transfer mechanisms.
- Requires careful planning for global applications and services.
Memory trick: Data security principles are like 'rules for data travelers', some can go anywhere, some must stay home.
Digital Signatures
Flip cardA cryptographic technique used to verify the authenticity and integrity of digital messages or documents, providing assurance of the sender's identity (non-repudiation) and proof that the data has not been altered in transit.
- Uses asymmetric cryptography (private key to sign, public key to verify).
- Provides data integrity and non-repudiation.
- Often involves hashing the message before signing.
Memory trick: Digital Signatures: 'Sign, Verify, Never Deny' your transactions.
Managed Service Accounts (MSAs/gMSAs)
Flip cardManaged Service Accounts (MSAs) and group Managed Service Accounts (gMSAs) are special types of domain accounts in Active Directory designed to provide automatic password management, simplified SPN management, and delegation of management to other administrators, for services and scheduled tasks.
- Automate password rotation for service accounts.
- Provide principle of least privilege for services.
- Eliminate need for manual password updates for services.
- gMSAs allow multiple servers to share the same service account.
Memory trick: MSAs Make Services Minimal Privilege
AI Fairness
Flip cardThe principle that AI systems should produce equitable outcomes and not discriminate against specific groups or perpetuate societal biases.
- Involves identifying and mitigating algorithmic bias.
- Crucial for ethical and trustworthy AI systems.
- Ensures AI benefits all users equally.
Memory trick: Fairness ensures AI plays nice with everyone.
Hardware-Enforced Separation (MILS)
Flip cardA system architecture that uses hardware mechanisms to create provably isolated partitions, ensuring distinct security domains cannot interfere with each other.
- Highest level of isolation.
- Used for classified or safety-critical systems.
- Prevents side-channel attacks and hypervisor escapes.
Memory trick: For ultimate isolation, hardware is the hardest wall.
OAuth 2.0 / OpenID Connect (OIDC)
Flip cardOAuth 2.0 is an authorization framework allowing third-party applications to obtain limited access to an HTTP service. OpenID Connect (OIDC) is an identity layer built on top of OAuth 2.0, enabling clients to verify the identity of the end-user.
- OAuth provides authorization, OIDC provides authentication.
- Token-based (access tokens, ID tokens).
- Widely used for federated identity and SSO in cloud/mobile.
Memory trick: OIDC Offers Identity for Distributed Clouds.
Cloud Security Posture Management (CSPM)
Flip cardA security solution that continuously monitors cloud environments for misconfigurations, compliance violations, and security risks, providing remediation guidance and enforcing security policies.
- Automates identification of security misconfigurations across cloud resources.
- Ensures continuous compliance with industry standards and regulations.
- Provides centralized visibility and reporting for multi-cloud environments.
Memory trick: Securing multiple clouds needs a 'central auditor' to ensure everyone follows the rules.
Client-Side Encryption
Flip cardThe process of encrypting data on the user's or application's device before it is transmitted to a cloud service or stored in a database, ensuring that the cloud provider never has access to unencrypted sensitive data.
- User/application controls the encryption keys.
- Protects data even if the cloud provider is compromised.
- Can make search and indexing more complex.
Memory trick: Cloud data needs two shields: one for travel, one for rest.
Security Service Edge (SSE)
Flip cardSecurity Service Edge (SSE) is a cloud-centric security model that converges security services including Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Zero Trust Network Access (ZTNA), and Firewall-as-a-Service (FWaaS) into a unified, cloud-delivered platform.
- Delivers security as a cloud service.
- Provides consistent policy enforcement for users, devices, and applications.
- Component of SASE (Secure Access Service Edge).
Memory trick: Think of SSE as your universal security 'control tower' for all your digital air traffic, no matter where it flies.
Secrets Management
Flip cardThe tools and methods used to manage digital authentication credentials (secrets) for applications, services, and users, ensuring their secure storage, access, and lifecycle.
- Secure storage for credentials, API keys, tokens.
- Dynamic delivery to applications.
- Centralized control, auditing, and rotation.
Memory trick: Secrets in the Vault, never in the code.
AES (Advanced Encryption Standard)
Flip cardA symmetric block cipher adopted as an encryption standard by the U.S. government, widely used globally for its strength and efficiency.
- Symmetric encryption algorithm.
- Supports 128, 192, and 256-bit key sizes.
- Efficient in hardware and software, suitable for IoT.
Memory trick: Small devices need efficient AES, not big RSA.
Cryptographic Signing & Verification
Flip cardThe process of using digital signatures to ensure the authenticity and integrity of data or software artifacts, where a private key signs and a public key verifies.
- Guarantees that data has not been altered since it was signed.
- Verifies the identity of the signer (authenticity).
- Essential for securing software supply chains and ensuring trusted components.
Memory trick: Securing the supply chain is like putting a 'tamper-proof seal' on every package and checking it at every stop.
SOAR Platform
Flip cardA SOAR (Security Orchestration, Automation, and Response) platform is a software solution that helps organizations collect threat-related data, automate security tasks, and orchestrate incident response workflows.
- Automates repetitive security tasks and incident response.
- Integrates with various security tools and threat intelligence feeds.
- Uses playbooks to standardize and accelerate response actions.
- Improves incident handling efficiency and reduces response times.
Memory trick: SOAR Orchestrates Rapid Cloud Response
DevSecOps
Flip cardAn approach that integrates security practices into every phase of the software development lifecycle (SDLC), from design to deployment and operations, ensuring security is a shared responsibility across development, operations, and security teams.
- Integrates security throughout SDLC.
- Automates security testing.
- Fosters a 'shift-left' security mindset.
Memory trick: Shift Left, Automate, Integrate, Monitor.
PASTA Framework (Threat Modeling)
Flip cardA 7-step risk-centric methodology for threat modeling that integrates business objectives with technical requirements.
- Stands for Process for Attack Simulation and Threat Analysis.
- Risk-centric approach.
- Moves from business context to technical attacks.
Memory trick: PASTA: Start broad, then get specific about threats and attacks.
Server Hardening
Flip cardThe process of securing a server by reducing its attack surface and mitigating vulnerabilities through configuration changes, software removal, and security controls.
- Minimize attack surface.
- Apply least privilege.
- Regularly patch and update.
Memory trick: Less is more for server security.
IPsec (Internet Protocol Security)
Flip cardA suite of protocols for securing Internet Protocol (IP) communications by authenticating and encrypting each IP packet of a communication session.
- Operates at the network layer (Layer 3 of OSI model).
- Provides confidentiality, integrity, and authenticity.
- Commonly used to create VPNs and secure router-to-router communication.
Memory trick: IPsec ensures my network packets are always 'IP-Safe' and sound.
Attribute-Based Access Control (ABAC)
Flip cardA dynamic access control model that grants or denies access based on a combination of attributes associated with the user, resource, action, and environment.
- Provides fine-grained access control.
- Highly flexible and scalable for complex environments.
- Access decisions are evaluated at the time of the request.
Memory trick: Attributes Bring Access Control.
Practical Byzantine Fault Tolerance (PBFT)
Flip cardA consensus algorithm for distributed systems that can tolerate Byzantine faults (malicious or arbitrary failures) among a known, finite set of participants, ensuring agreement and transaction finality.
- Suitable for permissioned blockchain networks.
- Provides immediate transaction finality.
- Can tolerate up to (n-1)/3 faulty nodes, where n is total nodes.
Memory trick: PBFT Provides Blockchain Finality and Trust.
Mandatory Access Control (MAC)
Flip cardMandatory Access Control (MAC) is an access control model where the operating system or security kernel enforces access decisions based on security labels assigned to subjects (users, processes) and objects (files, data).
- Access decisions are not at the discretion of the owner.
- Based on sensitivity labels (e.g., top secret, confidential).
- Used in highly secure environments (military, government, healthcare).
- Strongest form of access control for strict enforcement.
Memory trick: MAC is like a 'military clearance' system for your data—no exceptions, no discretion.
Zero Trust Policy Decision Point (PDP)
Flip cardIn a Zero Trust architecture, the Policy Decision Point (PDP) is the logical component responsible for making the final decision to grant or deny access to a resource based on existing access policies and contextual information.
- Evaluates access requests against policies.
- Makes the 'grant' or 'deny' decision.
- Communicates its decision to the Policy Enforcement Point (PEP).
Memory trick: The PDP is the 'Judge' of the Zero Trust court, deciding who gets in.
Global Baseline with Local Override (GBwLO)
Flip cardA compliance strategy that sets a global minimum standard for policies and controls, allowing for specific local adjustments.
- Ensures global consistency while accommodating local requirements.
- Prevents unnecessary over-compliance in some regions.
- Requires clear documentation and justification for local overrides.
Memory trick: Global Base, Local Grace.
WebAuthn
Flip cardWebAuthn is a web standard published by the W3C and FIDO Alliance, defining an API that allows web-based applications to integrate with strong authenticators for passwordless or multi-factor authentication.
- Component of FIDO2, enabling passwordless authentication in browsers.
- Uses public-key cryptography (asymmetric keys).
- Authenticators can be hardware tokens, biometrics, or platform-integrated.
- Provides phishing resistance and prevents username enumeration via password guessing.
Memory trick: WebAuthn's Cryptographic Challenge Stops User Enumeration
Defense-in-Depth
Flip cardA security strategy that employs multiple layers of security controls to protect assets, so if one control fails, others are still in place.
- Layered security approach.
- Reduces reliance on a single security control.
- Applies to physical, technical, and administrative controls.
Memory trick: Layers of defense, like an onion, protect the core.
Hardcoded Credentials Risk
Flip cardThe security risk associated with embedding sensitive authentication information (like API keys, passwords, or tokens) directly into application source code or configuration files. This practice makes credentials easily discoverable, difficult to rotate, and highly vulnerable if the code repository or compiled application is compromised.
- Credentials exposed in source code.
- Anyone with code access can retrieve them.
- Difficult to manage and rotate.
- Common source of data breaches.
Memory trick: Hardcoded Credentials are a Hard NO for Security.
Identity Broker
Flip cardA service that acts as an intermediary, translating identity information and authentication protocols between different identity providers and service providers.
- Enables Single Sign-On (SSO) across heterogeneous identity systems.
- Supports various protocols like SAML, OAuth, OIDC, LDAP.
- Simplifies identity management in hybrid and multi-cloud environments.
Memory trick: Hybrid identity needs a 'translator' to make different 'languages' of authentication understand each other.
C2 Channel Detection
Flip cardThe process of identifying covert communication pathways established by attackers to control compromised systems within a target network, often involving beaconing or unusual network traffic.
- Focuses on identifying outbound communication.
- Looks for unusual patterns (e.g., beaconing, non-standard protocols).
- Often uses DNS, HTTP/S, or custom protocols.
- Critical for detecting active compromises.
Memory trick: Listen for the hidden whispers trying to call home.
HSM and KMS for Key Management
Flip cardA Hardware Security Module (HSM) is a physical computing device that safeguards and manages digital keys, performing cryptographic functions. A Key Management System (KMS) is a comprehensive system for managing the full lifecycle of cryptographic keys, often integrating with HSMs for secure key storage.
- HSMs provide tamper-resistant hardware for key generation and storage.
- KMS manages key lifecycle (creation, rotation, revocation).
- Separates key management from data storage for enhanced security.
- Crucial for compliance in highly regulated industries (e.g., healthcare, finance).
Memory trick: The master key lives in a vault, managed by a trusted system.
PASTA (Process for Attack Simulation and Threat Analysis)
Flip cardA risk-centric threat modeling framework that guides organizations through a seven-stage process to identify, enumerate, and score threats, and then analyze potential attacks to determine appropriate countermeasures.
- Integrates threat modeling into the software development lifecycle.
- Focuses on attacker centric perspective and risk analysis.
- Provides a structured, repeatable process for threat identification and mitigation.
Memory trick: PASTA: A full-course meal for security analysis.
Identity Provider (IdP)
Flip cardA system entity that creates, maintains, and manages identity information for principals (users) and provides authentication services to other service providers (SPs) within a federated identity management system.
- Authenticates users within its domain.
- Issues security assertions (e.g., SAML assertions, OIDC tokens).
- Enables Single Sign-On (SSO) across multiple services.
Memory trick: IdP Identifies Principals for Partners.
Business Impact Analysis (BIA)
Flip cardA systematic process to determine and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, accident or emergency.
- Identifies critical business functions.
- Determines potential financial and operational impacts.
- Establishes recovery time objectives (RTO) and recovery point objectives (RPO).
Memory trick: To bounce back strong, first know what hits hardest.
STRIDE (Threat Modeling)
Flip cardA mnemonic used in threat modeling to categorize and identify threats: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. It helps in systematically analyzing potential security weaknesses.
- Categorizes threats into six types.
- Used during the threat modeling process.
- Helps ensure comprehensive threat analysis.
Memory trick: D-I-D-A: Diagram, Identify, Determine, Analyze.
BIA Impact Analysis
Flip cardThe phase of a Business Impact Analysis (BIA) that identifies and quantifies the consequences of business disruptions.
- Considers financial and non-financial impacts.
- Includes direct and indirect losses.
- Helps prioritize recovery efforts based on severity of impact.
Memory trick: Impact tells you 'how bad', RTO/RPO 'how fast'.
SOAR Connectors
Flip cardModules or APIs within a Security Orchestration, Automation, and Response (SOAR) platform that enable communication, data exchange, and action execution with other security tools and systems.
- Facilitate data enrichment.
- Enable automated response actions.
- Integrate with SIEM, EDR, TI feeds, firewalls, etc.
- Crucial for SOAR functionality.
Memory trick: The robot needs its arms and hands to reach out and do its work.
Digital Signature
Flip cardA mathematical scheme for verifying the authenticity and integrity of digital messages or documents, providing non-repudiation.
- Uses asymmetric cryptography (private key to sign, public key to verify).
- Ensures data integrity (detects tampering).
- Provides non-repudiation (proves sender's identity and intent).
Memory trick: Signatures prove who and what, for integrity and non-repudiation.
Infrastructure as Code (IaC) Security Scanning
Flip cardThe process of analyzing Infrastructure as Code (IaC) definition files (e.g., Terraform, CloudFormation, Kubernetes YAML) for security misconfigurations, policy violations, and vulnerabilities before deployment.
- Integrates into CI/CD pipelines.
- Identifies security issues early ('shift left').
- Ensures compliance with security policies for infrastructure.
Memory trick: IaC Scanning Secures Infrastructure Early.
Annualized Loss Expectancy (ALE)
Flip cardThe expected monetary loss for a given risk over a one-year period.
- ALE = SLE * ARO.
- SLE = Single Loss Expectancy (total cost of a single event).
- ARO = Annualized Rate of Occurrence (probability of event per year).
Memory trick: ALE is your yearly cost, SLE times ARO.
Post-Quantum Cryptography (PQC)
Flip cardCryptographic algorithms that are believed to be secure against cryptanalytic attacks by both classical and quantum computers. PQC aims to replace current public-key cryptography standards vulnerable to quantum algorithms.
- Resistant to Shor's and Grover's algorithms.
- Focuses on public-key algorithms (key exchange, digital signatures).
- Standardization efforts are ongoing (e.g., NIST PQC competition).
Memory trick: PQC Protects Quantum-Proof Confidentiality.
Trusted Platform Module (TPM)
Flip cardA secure cryptoprocessor that stores cryptographic keys and offers security services such as platform integrity verification and hardware-based encryption key generation/storage.
- Hardware-based security
- Stores cryptographic keys securely
- Protects against software attacks
- Verifies platform integrity
Memory trick: TPM: Trust in hardware for key protection.
MITRE ATT&CK T1053.005
Flip cardScheduled Task/Job - Adversaries can abuse the Windows Task Scheduler or Linux cron jobs to execute programs, commands, or scripts on a a periodic basis to achieve persistence or perform other malicious activities.
- Used for persistence and execution.
- Leverages legitimate system utilities.
- Can be configured to run at specific times or intervals.
- Detection involves monitoring scheduled tasks and their associated scripts/commands.
Memory trick: The ghost keeps coming back at the same time every day.
Unified Security Management (USM)
Flip cardA comprehensive approach to security that integrates multiple security functions, tools, and processes into a single platform for centralized management and visibility across diverse IT environments.
- Provides a single pane of glass for security operations.
- Enables consistent policy enforcement across hybrid environments.
- Integrates with various security tools and platforms.
- Improves visibility and simplifies compliance reporting.
Memory trick: To keep two houses in order, you need one master key.
Zero Trust Architecture (ZTA)
Flip cardA security model based on the principle of 'never trust, always verify,' where no user, device, or application is granted implicit trust, and all access requests are continuously authenticated, authorized, and validated based on context.
- Assumes no implicit trust, even inside the network.
- Requires continuous verification of identity and context.
- Focuses on securing access to resources, not network location.
Memory trick: Zero Trust: 'No Trust, Just Verify' for every access.