CompTIA SecurityX (CAS-005)Security ArchitectureMedium
A security architect is designing a system for a highly distributed global manufacturing company that has thousands of devices, users, and applications spread across multiple continents. The company wants to enforce a security model where no user, device, or application is inherently trusted, and access is granted only after continuous verification based on context. Which architectural model best describes this approach?
- AContent Delivery Network (CDN)
- BPerimeter-based security
- CDemilitarized Zone (DMZ)
- DZero Trust Architecture (ZTA)
Show answer & explanationAnswer & explanation
Correct answer: D. Zero Trust Architecture (ZTA)
Zero Trust Architecture (ZTA) is a security model that operates on the principle of 'never trust, always verify,' requiring continuous authentication and authorization for every access request, regardless of whether the entity is inside or outside the traditional network perimeter. This fits the distributed, untrusted environment described.
Why the other options are wrong
- A. A CDN is for content delivery and caching, not a security architecture.
- B. Perimeter-based security assumes trust within the network, which is contrary to the 'never trust' principle.
- C. A DMZ is a network segment for exposing public-facing services, not a comprehensive security model for all users, devices, and applications.
Zero Trust Architecture (ZTA)
A security model based on the principle of 'never trust, always verify,' where no user, device, or application is granted implicit trust, and all access requests are continuously authenticated, authorized, and validated based on context.
- Assumes no implicit trust, even inside the network.
- Requires continuous verification of identity and context.
- Focuses on securing access to resources, not network location.
Memory trick: Zero Trust: 'No Trust, Just Verify' for every access.