Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium

A hospital network needs to implement robust security measures to protect patient health information (PHI) and critical medical devices. They are concerned about both external attacks and insider threats. Which security architecture philosophy emphasizes continuous verification and assumes that no user, device, or application should be trusted by default, regardless of its location?

  1. ALeast Privilege
  2. BPerimeter Security
  3. CDefense in Depth
  4. DZero Trust
Show answer & explanation

Correct answer: D. Zero Trust

Zero Trust is a security model that dictates that no user or device, whether inside or outside the network, should be trusted by default. All access requests must be verified, authorized, and continuously monitored, aligning with the hospital's need to protect against both external and insider threats.

Why the other options are wrong

  • A. Least Privilege grants users only the minimum access necessary, which is a component of Zero Trust, but not the overarching architecture philosophy described.
  • B. Perimeter Security focuses on securing the network boundary, which is insufficient for insider threats or modern distributed environments.
  • C. Defense in Depth uses multiple layers of security controls, but doesn't inherently assume zero trust by default.

Zero Trust

A security model based on the principle of 'never trust, always verify.' It dictates that no user, device, or application should be trusted by default, regardless of whether it is inside or outside the network perimeter, and all access attempts must be authenticated and authorized.

  • Never trust, always verify.
  • Micro-segmentation is a key component.
  • Applies to all users, devices, and applications.

Memory trick: Zero Trust: Trust NO ONE, Verify EVERYTHING.

More Cybersecurity Fundamentals questions