CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is designing a new cloud-native application that involves multiple microservices. The application needs to ensure that only authorized services can communicate with each other, and access policies should be dynamically enforced based on service identity and context, rather than static IP addresses. Which Zero Trust principle is MOST relevant to this requirement?

  1. AAssume breach.
  2. BLeast privilege access.
  3. CMicro-segmentation.
  4. DVerify explicitly.
Show answer & explanation

Correct answer: D. Verify explicitly.

The 'Verify explicitly' principle in Zero Trust dictates that all access attempts, regardless of origin, must be authenticated and authorized based on all available data points, including user identity, device health, location, and service identity. This directly supports dynamic enforcement based on service identity and context for microservice communication.

Why the other options are wrong

  • A. 'Assume breach' is a foundational mindset of Zero Trust, but 'Verify explicitly' is the operational principle for enforcing access.
  • B. 'Least privilege access' defines *what* resources a service can access, but 'Verify explicitly' determines *if* the service is allowed to attempt access in the first place based on its verified identity and context.
  • C. Micro-segmentation is a control *mechanism* for Zero Trust, but 'Verify explicitly' is the underlying principle guiding how those segments are secured and how access within them is granted.

Zero Trust - Verify Explicitly

The 'Verify explicitly' principle of Zero Trust mandates that all access requests, whether from inside or outside the network, must be explicitly authenticated and authorized based on all available data points, rather than implicit trust from network location.

  • Authentication and authorization are continuous, not one-time.
  • Considers user identity, device health, location, service identity, and data sensitivity.
  • Moves away from perimeter-based security to identity-based security.
  • Crucial for microservices where network boundaries are fluid.

Memory trick: Don't trust, always check: 'V'erify 'E'verything 'E'xplicitly.

More Security Architecture questions