Courseiva
Security Architecture →easyMultiple Choice

CAS-004 Security Architecture Practice Question

Which of the following is a key principle of the zero trust security model?

⚠ Common exam trap

CAS-005 often tests the confusion between 'trust but verify' (a legacy phrase implying baseline trust) and 'never trust, always verify' (the actual zero trust mantra), since both sound security-conscious but only one reflects the model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Never trust, always verify

Zero trust is built on the principle 'never trust, always verify' — no user, device, or network segment is implicitly trusted based on location. Every access request must be authenticated, authorized, and continuously validated regardless of whether it originates inside or outside the traditional perimeter. This is the foundational tenet articulated in NIST SP 800-207.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Trust all internal traffic

    Why it's wrong here

    Zero trust explicitly rejects implicit trust based on network location, so trusting all internal traffic contradicts its core premise that no actor or packet is trusted by default. It is tempting because perimeter firewalls historically treated the internal LAN as safe, which is the assumption zero trust was designed to eliminate.

  • ✗

    Verify once, trust forever

    Why it's wrong here

    Zero trust requires continuous re-evaluation of every session, so a single authentication event granting permanent trust fails the model's per-request verification requirement. It is tempting because traditional single sign-on issues long-lived session tokens, which is exactly the standing access zero trust seeks to remove.

  • ✗

    Trust but verify

    Why it's wrong here

    "Trust but verify" still grants trust first and checks afterwards, whereas zero trust grants no access until identity and device posture are verified. It is tempting because it sounds security-conscious and suits insider-risk programmes where known users receive baseline trust before monitoring begins.

  • ✓

    Never trust, always verify

    Why this is correct

    The zero trust model enforces authentication and authorisation at every access request, regardless of network location, by requiring continuous verification of identity, device health, and session context before granting resource access. This satisfies the stem’s requirement for a foundational principle, as it directly opposes the traditional perimeter-based trust model. In Microsoft Entra ID, conditional access policies implement this by evaluating real-time signals for each request.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.