Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsEasy

A cybersecurity analyst is investigating a persistent threat actor who consistently uses social engineering tactics to gain initial access to corporate networks. Which of the following security models primarily focuses on preventing unauthorized access at every stage of an interaction, rather than relying solely on perimeter defenses?

  1. AZero Trust Model
  2. BCastle-and-Moat Model
  3. CDefense-in-Depth Model
  4. DShared Responsibility Model
Show answer & explanation

Correct answer: A. Zero Trust Model

The Zero Trust Model operates on the principle of 'never trust, always verify,' requiring strict identity verification for every user and device attempting to access resources, regardless of their location.

Why the other options are wrong

  • B. The Castle-and-Moat model focuses on strong perimeter defenses, which Zero Trust aims to move beyond.
  • C. Defense-in-Depth uses multiple layers of security, but Zero Trust specifically redefines the trust boundary.
  • D. The Shared Responsibility Model defines security obligations between cloud providers and customers, not an architectural approach to access control.

Zero Trust Model

A security concept centered on the belief that organizations should not automatically trust anything inside or outside its perimeters and instead must verify anything and everything trying to connect to its systems before granting access.

  • Never trust, always verify.
  • Requires strict identity verification for every user and device.
  • Assumes breach and minimizes the attack surface.

Memory trick: Zero trust means verifying everyone, not just keeping them out.

More Cybersecurity Fundamentals questions