Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium

A security architect is designing a network for a critical infrastructure organization. Due to the high-stakes nature of potential attacks, they aim to implement security measures that assume a breach is inevitable and focus on minimizing the impact and preventing lateral movement once an attacker gains initial access. Which security principle is being applied here?

  1. ASecurity by Design
  2. BTrust but Verify
  3. CZero Trust
  4. DThreat Modeling
Show answer & explanation

Correct answer: C. Zero Trust

The Zero Trust model operates on the principle of 'never trust, always verify,' assuming that no user or device, whether inside or outside the network perimeter, should be trusted by default. It focuses on strict access controls and micro-segmentation to prevent lateral movement after a breach.

Why the other options are wrong

  • A. Security by Design is a broader concept of integrating security throughout design, but not specifically the 'assume breach' philosophy.
  • B. Trust but Verify implies some initial trust, which contradicts the 'assume breach' mindset.
  • D. Threat Modeling identifies potential threats but is a process, not a security principle for network architecture.

Zero Trust

A security model where no user or device, whether inside or outside the network perimeter, is trusted by default, and every access request is verified before granting access.

  • Based on the principle 'never trust, always verify'.
  • Focuses on strict access controls and micro-segmentation.
  • Assumes breaches are inevitable and aims to minimize their impact.

Memory trick: Don't trust anyone, verify everything, especially inside the walls.

More Cybersecurity Fundamentals questions