CompTIA CySA+ (CS0-003)Security OperationsEasy
A company is redesigning its network architecture around the principle of 'never trust, always verify,' requiring continuous authentication and authorization for every resource request regardless of the user's network location. Which architectural model is being implemented?
- APerimeter-based defense
- BBastion host model
- CFlat network architecture
- DZero trust architecture
Show answer & explanationAnswer & explanation
Correct answer: D. Zero trust architecture
Zero trust architecture assumes no implicit trust based on network location; every access request is continuously verified using identity, device posture, and least-privilege policies. This directly matches the 'never trust, always verify' phrase in the stem.
Why the other options are wrong
- A. Perimeter-based defense trusts anything inside the network boundary once past the firewall.
- B. A bastion host is a hardened jump box, a single control, not a full architectural model.
- C. A flat network has no segmentation and increases lateral movement risk, the opposite of zero trust.
Zero Trust Architecture
A security model that eliminates implicit trust and requires continuous verification of identity and context for every access request, regardless of network location.
- Core tenet: 'never trust, always verify'
- Relies on micro-segmentation and least privilege
- Uses continuous authentication, not one-time perimeter login
Memory trick: Zero Trust = 'trust no one, check everyone, every time.'