Which of the following is a key principle of the zero trust security model?
The zero trust model enforces authentication and authorisation at every access request, regardless of network location, by requiring continuous verification of identity, device health, and session context before granting resource access. This satisfies the stem’s requirement for a foundational principle, as it directly opposes the traditional perimeter-based trust model. In Microsoft Entra ID, conditional access policies implement this by evaluating real-time signals for each request.
Why this answer
Zero trust is built on the principle 'never trust, always verify' — no user, device, or network segment is implicitly trusted based on location. Every access request must be authenticated, authorized, and continuously validated regardless of whether it originates inside or outside the traditional perimeter. This is the foundational tenet articulated in NIST SP 800-207.
Exam trap
CAS-005 often tests the confusion between 'trust but verify' (a legacy phrase implying baseline trust) and 'never trust, always verify' (the actual zero trust mantra), since both sound security-conscious but only one reflects the model.
How to eliminate wrong answers
Option A is wrong because trusting all internal traffic is the exact opposite of zero trust — it reflects the legacy castle-and-moat perimeter model that zero trust was designed to replace. Option B is wrong because 'verify once, trust forever' describes a one-time authentication model; zero trust requires continuous verification of session context, device posture, and behavior. Option C is wrong because 'trust but verify' is a Cold War-era phrase implying implicit trust with spot checks, whereas zero trust starts from a position of no trust and requires explicit verification for every request.