CAS-004 Security Architecture Practice Question
Which of the following is a key principle of the zero trust security model?
⚠ Common exam trap
CAS-005 often tests the confusion between 'trust but verify' (a legacy phrase implying baseline trust) and 'never trust, always verify' (the actual zero trust mantra), since both sound security-conscious but only one reflects the model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Never trust, always verify
Zero trust is built on the principle 'never trust, always verify' — no user, device, or network segment is implicitly trusted based on location. Every access request must be authenticated, authorized, and continuously validated regardless of whether it originates inside or outside the traditional perimeter. This is the foundational tenet articulated in NIST SP 800-207.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trust all internal traffic
Why it's wrong here
Zero trust explicitly rejects implicit trust based on network location, so trusting all internal traffic contradicts its core premise that no actor or packet is trusted by default. It is tempting because perimeter firewalls historically treated the internal LAN as safe, which is the assumption zero trust was designed to eliminate.
- ✗
Verify once, trust forever
Why it's wrong here
Zero trust requires continuous re-evaluation of every session, so a single authentication event granting permanent trust fails the model's per-request verification requirement. It is tempting because traditional single sign-on issues long-lived session tokens, which is exactly the standing access zero trust seeks to remove.
- ✗
Trust but verify
Why it's wrong here
"Trust but verify" still grants trust first and checks afterwards, whereas zero trust grants no access until identity and device posture are verified. It is tempting because it sounds security-conscious and suits insider-risk programmes where known users receive baseline trust before monitoring begins.
- ✓
Never trust, always verify
Why this is correct
The zero trust model enforces authentication and authorisation at every access request, regardless of network location, by requiring continuous verification of identity, device health, and session context before granting resource access. This satisfies the stem’s requirement for a foundational principle, as it directly opposes the traditional perimeter-based trust model. In Microsoft Entra ID, conditional access policies implement this by evaluating real-time signals for each request.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.