mediumMultiple SelectObjective-mapped
350-701 Practice Question: Implementing zero trust architecture in the cloud
A company is implementing zero trust architecture in the cloud. Which TWO principles are fundamental to zero trust? (Choose two.)
⚠ Common exam trap
Cisco often tests the misconception that zero trust still allows implicit trust for internal traffic or that traditional perimeter defenses are sufficient, leading candidates to select 'Implicit trust for internal traffic' or 'Use perimeter firewalls only' instead of recognizing that zero trust requires explicit verification for all traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assume breach
Zero trust architecture operates on the principle of 'never trust, always verify,' which includes assuming that a breach has already occurred or is inevitable. This assumption drives continuous validation of every access request, regardless of source, and enforces least-privilege access to limit lateral movement. In cloud environments, this means treating every API call, workload, and user session as potentially compromised until proven otherwise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assume breach
Why this is correct
Design systems assuming an attacker is present.
- ✗
Implicit trust for internal traffic
Why it's wrong here
Zero trust does not trust any traffic by default.
- ✗
Use static passwords
Why it's wrong here
Static passwords are not a zero trust principle; MFA is preferred.
- ✗
Use perimeter firewalls only
Why it's wrong here
Zero trust uses micro-perimeters, not just edge.
- ✓
Verify explicitly
Why this is correct
Always authenticate and authorize every request.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.