CompTIA Security+ (SY0-701)Security ArchitectureHard
A large enterprise is redesigning its network security model after several breaches resulted from attackers moving freely once inside the perimeter. The new design requires continuous verification of every user and device, strict least-privilege access to individual resources, and no implicit trust based on network location. Which architecture is the enterprise implementing?
- ASoftware-defined WAN
- BZero trust architecture
- CSite-to-site VPN mesh
- DScreened subnet
Show answer & explanationAnswer & explanation
Correct answer: B. Zero trust architecture
Zero trust architecture eliminates implicit trust based on network location, requiring continuous authentication, authorization, and least-privilege access to each resource regardless of whether the user is inside or outside the traditional perimeter.
Why the other options are wrong
- A. SD-WAN optimizes and manages WAN connectivity paths, not identity-based access control.
- C. A VPN mesh secures connections between sites but does not enforce continuous per-resource verification.
- D. A screened subnet segments public-facing servers but still relies on perimeter-based trust internally.
Zero Trust Architecture
A security model that assumes no implicit trust for any user or device, requiring continuous verification and least-privilege access to individual resources regardless of network location.
- Core principle: 'never trust, always verify'
- Relies on strong identity, device posture, and microsegmentation
- Eliminates the traditional trusted internal network concept
Memory trick: Trust nobody, verify everybody, every time.