Cisco CCNP Security Core (SCOR) 350-701Endpoint Security and Secure Network AccessMedium

A company is implementing a Zero Trust security model. As part of this, the security team needs to ensure that even after a user or device gains initial access, their access privileges are continuously evaluated and adapted based on changes in context, such as location, time of day, or device posture. Which Zero Trust principle does this requirement primarily address?

  1. AVerify Explicitly
  2. BNever Trust, Always Verify
  3. CAssume Breach
  4. DLeast Privilege Access
Show answer & explanation

Correct answer: A. Verify Explicitly

The 'Verify Explicitly' principle in Zero Trust dictates that all access attempts, regardless of origin, must be explicitly and continuously verified based on all available data points, including user identity, device posture, location, and application sensitivity. This includes re-evaluating access after initial granting.

Why the other options are wrong

  • B. While 'Never Trust, Always Verify' is the overarching motto of Zero Trust, 'Verify Explicitly' describes the specific continuous evaluation aspect.
  • C. 'Assume Breach' is a Zero Trust principle that focuses on designing defenses with the expectation that breaches will occur, not specifically on continuous access evaluation.
  • D. 'Least Privilege Access' dictates granting only the minimum necessary permissions, but doesn't explicitly cover the continuous re-evaluation of those privileges based on dynamic context.

Zero Trust: Verify Explicitly

The 'Verify Explicitly' Zero Trust principle requires all access requests to be authenticated and authorized based on all available data points, continuously and dynamically.

  • No implicit trust granted to any user or device.
  • Access decisions are dynamic and context-aware.
  • Continuously re-evaluates access based on changing conditions (location, posture, etc.).
  • Applies to all resources, regardless of network location.

Memory trick: Zero Trust says 'Explicitly Verify Everything, Always'.

More Endpoint Security and Secure Network Access questions