Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium
A company is adopting a 'zero-trust' security model for its cloud environment. They are implementing strict access controls for all internal and external communication. Which core tenet of zero-trust architecture directly addresses the need to continuously verify the legitimacy of every access attempt, regardless of its origin?
- AMicro-segmentation
- BAssume breach
- CLeast privilege access
- DVerify explicitly
Show answer & explanationAnswer & explanation
Correct answer: D. Verify explicitly
The 'Verify explicitly' tenet of zero trust mandates that all access requests are authenticated, authorized, and continuously validated based on all available data points, not just assumed trusted based on location.
Why the other options are wrong
- A. Micro-segmentation isolates resources but doesn't define the verification process for accessing them.
- B. Assume breach is a mindset, not a specific tenet for verifying access attempts.
- C. Least privilege access defines what an entity can do, not how it's initially verified for access.
Zero Trust Tenets
Core principles guiding the implementation of a zero-trust security model, emphasizing 'never trust, always verify'.
- Verify explicitly: Authenticate and authorize every access request.
- Use least privilege access: Grant only necessary permissions.
- Assume breach: Design with the expectation that systems will be compromised.
Memory trick: Zero Trust: No one's trusted, everyone's checked, expect the worst.