Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityEasy

A company is implementing a Zero Trust architecture for its internal network. Which core principle of Zero Trust mandates that all network traffic, regardless of its source or destination within the network, must be authenticated and authorized before access is granted?

  1. AMicrosegmentation
  2. BNever Trust, Always Verify
  3. CLeast Privilege Access
  4. DDevice Posture Assessment
Show answer & explanation

Correct answer: B. Never Trust, Always Verify

The 'Never Trust, Always Verify' principle is the foundational tenet of Zero Trust, stating that no user, device, or application should be implicitly trusted, even if it's inside the network perimeter. All access requests must be authenticated and authorized.

Why the other options are wrong

  • A. Microsegmentation is a technique used to implement Zero Trust, but it's not the core principle of 'never trust'.
  • C. Least Privilege Access is a principle that limits user/device permissions to only what is necessary, but it's a consequence of 'never trust', not the principle itself.
  • D. Device Posture Assessment is a component used to verify the trustworthiness of a device, but it's a mechanism, not the overarching principle.

Zero Trust Principle: Never Trust, Always Verify

The foundational principle of Zero Trust security, stating that no user, device, or application is implicitly trusted, regardless of its location (inside or outside the network). All access attempts must be explicitly authenticated and authorized.

  • Eliminates the concept of a trusted internal network.
  • Requires continuous verification for every access request.
  • Forms the basis for all other Zero Trust components.

Memory trick: In Zero Trust, Trust is a Four-Letter Word!

More Security questions