Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessEasy

A company is implementing a zero-trust security model. As part of this, every network access attempt, whether from internal or external users, must be continuously verified and authorized based on real-time context. Which principle of zero trust emphasizes that access decisions are not static but are re-evaluated throughout the user's session?

  1. AAssume Breach
  2. BMicro-segmentation
  3. CContinuous Verification
  4. DLeast Privilege Access
Show answer & explanation

Correct answer: C. Continuous Verification

Continuous verification is a core principle of zero trust, dictating that once access is granted, it is not permanently trusted but is continually re-evaluated based on changes in context, user behavior, or device posture.

Why the other options are wrong

  • A. Assume breach is a mindset that acknowledges compromises will happen, but it's not the principle of ongoing access re-evaluation.
  • B. Micro-segmentation is a technique to isolate network resources, not a principle of continuous re-evaluation.
  • D. Least privilege access grants only the minimum necessary permissions, but doesn't specifically refer to continuous re-evaluation.

Zero Trust Principle: Continuous Verification

The zero-trust principle that requires continuous monitoring and re-evaluation of user and device trustworthiness throughout the duration of a session, rather than granting static access.

  • Trust is never implicit; it is always earned and continuously validated.
  • Contextual factors (location, device posture, behavior) are continually assessed.
  • Access can be revoked or adjusted dynamically if conditions change.

Memory trick: Never trust, always verify, and verify continuously.

More Endpoint Security and Secure Network Access questions