Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityHard

A company is implementing a Zero Trust security model. They are evaluating existing security controls to align with the 'Never Trust, Always Verify' principle. Which of the following best represents an implementation of this principle?

  1. AUsing static access control lists (ACLs) to segment network subnets.
  2. BDeploying a single, strong firewall at the network perimeter.
  3. CAllowing all internal network traffic to pass without inspection.
  4. DAuthenticating and authorizing every user and device for every access request, regardless of location.
Show answer & explanation

Correct answer: D. Authenticating and authorizing every user and device for every access request, regardless of location.

The 'Never Trust, Always Verify' principle of Zero Trust mandates that no user, device, or application should be inherently trusted, regardless of whether it is inside or outside the network perimeter. Therefore, every access request must be explicitly authenticated and authorized based on context, continuous monitoring, and granular policies.

Why the other options are wrong

  • A. Static ACLs provide basic segmentation but lack the dynamic, granular, and continuous verification required by a Zero Trust model.
  • B. A single perimeter firewall is a traditional perimeter-based security model, which Zero Trust aims to move beyond, as it trusts internal entities.
  • C. Allowing all internal traffic without inspection contradicts the 'Never Trust' aspect of Zero Trust, as it assumes inherent trust.

Zero Trust Principle: Never Trust, Always Verify

The core tenet of Zero Trust security, stating that no user, device, or application should be inherently trusted, regardless of its location or previous authentication. All access requests must be continuously authenticated, authorized, and validated.

  • Eliminates implicit trust.
  • Requires continuous verification of identity and context.
  • Applies to all resources, internal and external.

Memory trick: Zero Trust: No one gets a free pass.

More Security questions