CompTIA Security+ (SY0-701)Security OperationsHard
A company is redesigning its network architecture with a focus on zero trust principles. They want to ensure that access to resources is never implicitly trusted and is continuously verified, regardless of whether the user or device is inside or outside the traditional network perimeter. Which core concept of zero trust is being emphasized here?
- ALeast privilege
- BMicrosegmentation
- CMulti-factor authentication (MFA)
- DContinuous verification
Show answer & explanationAnswer & explanation
Correct answer: D. Continuous verification
Continuous verification is a core tenet of zero trust, stating that every access request, regardless of origin, must be authenticated, authorized, and continuously monitored. The scenario explicitly mentions 'never implicitly trusted' and 'continuously verified,' directly aligning with this principle.
Why the other options are wrong
- A. Least privilege is a general security principle, also part of zero trust, but doesn't fully encompass the continuous verification aspect.
- B. Microsegmentation is a zero trust implementation technique, but not the overarching concept of continuous verification itself.
- C. MFA is an authentication mechanism that supports zero trust, but it's a specific control, not the broad principle of continuous verification.
Continuous Verification (Zero Trust)
A core principle of Zero Trust that requires every access request to be authenticated, authorized, and continuously validated based on policy, context, and risk, regardless of location.
- Trust is never granted implicitly; it must be explicitly established and maintained.
- Access decisions are dynamic and adaptable.
- Applies to users, devices, applications, and data.
Memory trick: Zero Trust means 'Verify Every Access' always.