Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium
A network security team is implementing a Zero Trust architecture. They are evaluating existing security controls and trying to determine which principle best aligns with the 'never trust, always verify' philosophy. Which statement accurately reflects a core principle of Zero Trust?
- AAll access requests, regardless of source or location, must be authenticated and authorized.
- BSecurity should primarily focus on strengthening the network perimeter to keep threats out.
- CUsers are granted broad access to resources by default, with restrictions applied only when anomalies are detected.
- DOnce a device or user is inside the network perimeter, it is implicitly trusted.
Show answer & explanationAnswer & explanation
Correct answer: A. All access requests, regardless of source or location, must be authenticated and authorized.
The 'never trust, always verify' principle of Zero Trust mandates that all access attempts, from any location or source, must be subjected to authentication, authorization, and continuous validation, eliminating implicit trust based on network location.
Why the other options are wrong
- B. Zero Trust de-emphasizes the perimeter, focusing on protecting individual resources.
- C. This describes a traditional perimeter-based model, not Zero Trust's principle of least privilege.
- D. This contradicts Zero Trust by promoting implicit trust within the perimeter.
Zero Trust Principle: Never Trust, Always Verify
The foundational tenet of Zero Trust, requiring all users, devices, and applications to be authenticated, authorized, and continuously validated before being granted access to resources, regardless of their location.
- Eliminates implicit trust based on network location.
- Applies to internal and external access.
- Requires continuous monitoring and re-evaluation.
Memory trick: Zero Trust: No more trust falls; everyone gets checked every time.