CompTIA Security+ (SY0-701)Security OperationsMedium
A company is redesigning its network architecture with a focus on zero trust principles. Instead of granting blanket access to users once they are on the corporate network, the new design requires that all access requests, regardless of source (internal or external), are continuously evaluated and verified before granting access to resources. Which zero trust principle is being primarily emphasized here?
- AMicrosegmentation
- BVerify explicitly
- CAssume breach
- DLeast privilege
Show answer & explanationAnswer & explanation
Correct answer: B. Verify explicitly
The 'Verify explicitly' principle of Zero Trust mandates that all access requests are authenticated and authorized based on all available data points, including user identity, location, device health, and service/data sensitivity, and this verification is continuous, not just a one-time event upon network entry.
Why the other options are wrong
- A. Microsegmentation divides networks into small, isolated zones to limit lateral movement, which is a *control* used in Zero Trust, but not the *principle* of continuous access verification.
- C. Assume breach is a core tenet of Zero Trust, but the scenario specifically describes the *method* of continuous evaluation for access, which is 'Verify explicitly'.
- D. Least privilege ensures users only have the minimum access needed, but the scenario focuses on the *process of verification* for that access, not the scope of access itself.
Zero Trust Principle: Verify Explicitly
A core principle of Zero Trust that requires all access requests to be authenticated and authorized based on all available data points (user, device, location, service, data sensitivity) and continuously re-evaluated.
- Never trust, always verify.
- Access is not granted implicitly.
- Verification is continuous, not a one-time event.
Memory trick: VERIFY, LEAST, ASSUME: Verify everything, give least privilege, assume breach.