CompTIA Network+ (N10-009)Networking ConceptsHard
An organization is redesigning its network security model based on the principle that no user or device should be automatically trusted, regardless of whether they are inside or outside the corporate network perimeter. Which security concept is being implemented?
- APerimeter-based security
- BNetwork segmentation
- CDefense in depth
- DZero trust
Show answer & explanationAnswer & explanation
Correct answer: D. Zero trust
Zero trust is a security framework built on the principle of 'never trust, always verify,' requiring continuous authentication and authorization for every user and device regardless of network location, rather than assuming trust based on being inside the network perimeter.
Why the other options are wrong
- A. Perimeter-based security is the opposite model, trusting devices once inside the network boundary.
- B. Network segmentation divides a network into zones but is only one possible tool within a zero trust strategy.
- C. Defense in depth layers multiple security controls but doesn't inherently eliminate implicit trust based on location.
Zero Trust Architecture
A security model in which no user, device, or system is trusted by default, even inside the network perimeter, requiring continuous verification for every access request based on identity, device health, and context.
- Core principle: 'never trust, always verify'
- Relies on least privilege access and micro-segmentation
- Continuously authenticates and authorizes rather than trusting a single login
Memory trick: Trust no one, verify everyone, every time