Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium
A company is implementing a Zero Trust architecture for its internal network. The security team needs to ensure that every connection attempt, regardless of its origin (internal or external), is authenticated and authorized before access is granted to any resource. Which core principle of Zero Trust is being emphasized in this implementation?
- AVerify Explicitly
- BLeast Privilege Access
- CMicro-segmentation
- DAssume Breach
Show answer & explanationAnswer & explanation
Correct answer: A. Verify Explicitly
The 'Verify Explicitly' principle of Zero Trust mandates that all access requests, regardless of source, must be authenticated and authorized based on all available data points, including user identity, device posture, location, and service being accessed, before access is granted. This directly matches the requirement for every connection attempt to be authenticated and authorized.
Why the other options are wrong
- B. Least Privilege Access is a separate principle focusing on granting minimum necessary permissions, which is a consequence of verification, not the verification itself.
- C. Micro-segmentation is an architectural technique to isolate workloads, which helps enforce Zero Trust, but isn't the core principle of 'never trust, always verify'.
- D. Assume Breach is a principle that anticipates security failures, but doesn't directly describe the action of authenticating every connection.
Zero Trust - Verify Explicitly
A core principle of Zero Trust that demands all access requests are authenticated and authorized based on all available data points before granting access.
- No implicit trust for any user or device
- Authentication and authorization are continuous
- Contextual factors are considered (identity, device, location)
Memory trick: Never trust, always verify every step.