Cisco CCNP Security Core (SCOR) 350-701Network SecurityHard
A large enterprise is adopting a Zero Trust security model. They are implementing a solution that continuously monitors device posture, user behavior, and application access requests, even for internal traffic. Which principle of Zero Trust is primarily being addressed by this continuous monitoring?
- ASegment Access
- BLeast Privilege
- CAssume Breach
- DVerify Explicitly
Show answer & explanationAnswer & explanation
Correct answer: D. Verify Explicitly
Continuous monitoring of device posture, user behavior, and application access is central to 'Verify Explicitly' in Zero Trust, as it means every access request is authenticated and authorized based on all available context, not just once at the perimeter.
Why the other options are wrong
- A. Segment Access involves breaking down the network into smaller, isolated zones, which enhances security but doesn't directly describe the continuous verification aspect of the monitoring.
- B. Least Privilege ensures users and devices only have access to what they absolutely need, which is a result of verification, but not the primary principle addressed by continuous monitoring.
- C. Assume Breach is the mindset that an attacker may already be inside, leading to a focus on containment and detection, but 'continuous monitoring' itself is the active verification process.
Zero Trust - Verify Explicitly
The 'Verify Explicitly' principle of Zero Trust dictates that all access requests must be authenticated and authorized based on all available data points, including user identity, device posture, location, and application context, rather than trusting by default.
- Authenticates and authorizes every access attempt.
- Considers multiple attributes for decision-making.
- Requires continuous monitoring and re-evaluation of trust.
Memory trick: Verify Explicitly: 'V' for 'Validate' everything, every time.