CAS-004 Security Architecture Practice Question
A security architect is designing a zero trust architecture for a corporate network. Which principle is fundamental to the zero trust model?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Never trust, always verify
Zero trust assumes no implicit trust; every access request must be verified regardless of origin.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trust based on device compliance
Why it's wrong here
Device compliance is one signal feeding a conditional access decision, not the foundational principle. Zero trust authenticates and authorises every request explicitly, regardless of device state. Compliance-based trust fits conditional access policies within an existing identity framework, not the core zero trust tenet itself.
- ✓
Never trust, always verify
Why this is correct
Never trust, always verify requires every access request to be authenticated and authorised explicitly, regardless of network location, replacing implicit trust with continuous verification. This is the foundational tenet from which all other zero trust controls derive.
- ✗
Trust based on network location
Why it's wrong here
Zero trust explicitly rejects network location as a trust signal; being inside the corporate subnet grants nothing. Every session is verified against identity, device and context. Location-based trust describes traditional castle-and-moat perimeter design, where internal network placement alone conferred access.
- ✗
Trust but verify
Why it's wrong here
Zero trust grants no implicit trust based on prior verification; every request is authenticated and authorised continuously. "Trust but verify" belongs to perimeter models, where an entity is trusted once inside and checked afterwards. It would suit legacy defence-in-depth reviews, not a zero trust design.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.