Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessEasy
A company is implementing a zero-trust security model. As part of this, every network access attempt, whether from internal or external users, must be continuously verified and authorized based on real-time context. Which principle of zero trust emphasizes that access decisions are not static but are re-evaluated throughout the user's session?
- AAssume Breach
- BMicro-segmentation
- CContinuous Verification
- DLeast Privilege Access
Show answer & explanationAnswer & explanation
Correct answer: C. Continuous Verification
Continuous verification is a core principle of zero trust, dictating that once access is granted, it is not permanently trusted but is continually re-evaluated based on changes in context, user behavior, or device posture.
Why the other options are wrong
- A. Assume breach is a mindset that acknowledges compromises will happen, but it's not the principle of ongoing access re-evaluation.
- B. Micro-segmentation is a technique to isolate network resources, not a principle of continuous re-evaluation.
- D. Least privilege access grants only the minimum necessary permissions, but doesn't specifically refer to continuous re-evaluation.
Zero Trust Principle: Continuous Verification
The zero-trust principle that requires continuous monitoring and re-evaluation of user and device trustworthiness throughout the duration of a session, rather than granting static access.
- Trust is never implicit; it is always earned and continuously validated.
- Contextual factors (location, device posture, behavior) are continually assessed.
- Access can be revoked or adjusted dynamically if conditions change.
Memory trick: Never trust, always verify, and verify continuously.