Courseiva
Security Architecture →easyMultiple Choice

CAS-004 Security Architecture Practice Question

A security architect is designing a zero trust architecture for a corporate network. Which principle is fundamental to the zero trust model?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Never trust, always verify

Zero trust assumes no implicit trust; every access request must be verified regardless of origin.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Trust based on device compliance

    Why it's wrong here

    Device compliance is one signal feeding a conditional access decision, not the foundational principle. Zero trust authenticates and authorises every request explicitly, regardless of device state. Compliance-based trust fits conditional access policies within an existing identity framework, not the core zero trust tenet itself.

  • ✓

    Never trust, always verify

    Why this is correct

    Never trust, always verify requires every access request to be authenticated and authorised explicitly, regardless of network location, replacing implicit trust with continuous verification. This is the foundational tenet from which all other zero trust controls derive.

  • ✗

    Trust based on network location

    Why it's wrong here

    Zero trust explicitly rejects network location as a trust signal; being inside the corporate subnet grants nothing. Every session is verified against identity, device and context. Location-based trust describes traditional castle-and-moat perimeter design, where internal network placement alone conferred access.

  • ✗

    Trust but verify

    Why it's wrong here

    Zero trust grants no implicit trust based on prior verification; every request is authenticated and authorised continuously. "Trust but verify" belongs to perimeter models, where an entity is trusted once inside and checked afterwards. It would suit legacy defence-in-depth reviews, not a zero trust design.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.