CompTIA Security+ (SY0-701)Security OperationsMedium
A company is redesigning its network architecture with a focus on zero trust principles. They are implementing a system that requires users and devices to be continuously authenticated, authorized, and validated for every access request, even after initial authentication. Which core zero trust principle is being applied?
- AMicrosegmentation
- BAssume breach
- CVerify explicitly
- DLeast privilege
Show answer & explanationAnswer & explanation
Correct answer: C. Verify explicitly
The 'Verify explicitly' principle dictates that all access requests must be authenticated and authorized based on all available data points, including user identity, location, device health, and service being accessed, and this verification is continuous, not just at initial login.
Why the other options are wrong
- A. 'Microsegmentation' is an architectural technique to isolate network segments, supporting zero trust, but it's not the principle of continuous verification itself.
- B. 'Assume breach' is a foundational mindset of zero trust, but not the specific operational principle of continuous verification.
- D. 'Least privilege' ensures users only have access to resources absolutely necessary for their role, which is a component of zero trust but not the overarching principle described.
Zero Trust Principle: Verify Explicitly
A core tenet of Zero Trust that requires all access requests to be explicitly and continuously verified based on all available data points, rather than trusting implicitly.
- All users, devices, and applications are untrusted by default.
- Verification is continuous, not just at initial access.
- Considers user identity, location, device health, and data sensitivity.
Memory trick: Zero Trust says, 'Always 'Verify Explicitly' because you can't 'Trust' anyone, ever.'