CompTIA Network+ (N10-009)Network SecurityMedium

A CISO mandates that no user or device, whether inside or outside the corporate network, should be automatically trusted, and that every access request must be authenticated, authorized, and continuously validated regardless of location. Which security model is being described?

  1. AZero Trust architecture
  2. BDefense in depth
  3. CScreened subnet
  4. DNetwork Access Control
Show answer & explanation

Correct answer: A. Zero Trust architecture

Zero Trust operates on the principle of 'never trust, always verify,' requiring continuous authentication, least-privilege access, and micro-segmentation regardless of whether the request originates inside or outside the traditional network perimeter. NAC is one tool that can support Zero Trust but is not the overall model.

Why the other options are wrong

  • B. Defense in depth layers multiple security controls but doesn't specifically eliminate implicit trust zones.
  • C. A screened subnet is a perimeter architecture, not an identity-centric trust model.
  • D. NAC checks device posture at connection time but is only one component that could support Zero Trust.

Zero Trust Architecture

A security model that assumes no implicit trust for any user or device, requiring continuous verification and least-privilege access for every request.

  • Core principle: 'never trust, always verify'
  • Uses micro-segmentation to limit lateral movement
  • Applies equally to internal and external network locations

Memory trick: Zero Trust: everyone's a stranger until they prove otherwise, every single time.

More Network Security questions