Courseiva
hardMultiple Choice

Zero Trust Architecture — Micro-Segmentation, Least Privilege, Continuous Monitoring

A company is migrating to a zero trust architecture. Which of the following is a key principle of zero trust?

⚠ Common exam trap

Candidates often confuse 'trust but verify' (Option D) with zero trust, but zero trust explicitly eliminates the initial trust assumption, requiring verification before any access is granted, not after.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assume breach and verify every request

Zero trust architecture is built on the principle of 'never trust, always verify,' which explicitly requires that every access request—regardless of origin—be authenticated, authorized, and continuously validated. Option B ('Assume breach and verify every request') captures this core tenet, as it mandates that no implicit trust is granted based on network location or device status, and every request must be treated as potentially malicious until proven otherwise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allow all traffic within the corporate network

    Why it's wrong here

    Zero trust removes implicit trust from the network perimeter, requiring every request to be authenticated and authorised; permitting all internal traffic reinstates the flat-network model zero trust eliminates. It tempts as a legacy convenience for trusted subnets, but that is precisely the assumption being retired.

  • ✓

    Assume breach and verify every request

    Why this is correct

    Zero trust removes implicit trust based on network location, so every access request must be authenticated and authorised regardless of origin. Assuming breach means designing as though attackers are already inside, which drives continuous verification of identity, device health and context before granting access to resources.

  • ✗

    Trust devices based on their IP address

    Why it's wrong here

    IP addresses are spoofable and workload identities move, so zero trust authenticates device identity and posture rather than network location. It tempts because static IP allow-lists are simple to configure, but that is perimeter-based trust, which zero trust explicitly replaces with identity-based verification.

  • ✗

    Trust but verify for all internal traffic

    Why it's wrong here

    Zero trust never grants standing trust to internal traffic; each session and request is continuously verified regardless of origin. It tempts because 'trust but verify' describes older defence-in-depth postures, yet zero trust's mechanism is explicit per-request policy evaluation, not network-location-based trust.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CAS-005

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which THREE of the following are key components of a zero-trust security architecture? (Select THREE).

hard
  • A.VPN concentrator
  • ✓ B.Micro-segmentation
  • C.Implicit trust for internal network traffic
  • ✓ D.Least privilege access control
  • ✓ E.Continuous monitoring of user and device behavior

Why B: Micro-segmentation (B) is a core zero-trust component because it divides the network into granular zones and enforces policy between workloads, preventing lateral movement even after a breach. Least privilege access control (D) is essential since zero trust grants only the minimum permissions needed for a specific task, typically enforced through just-in-time and just-enough-access policies rather than broad standing rights. Continuous monitoring of user and device behavior (E) is required because zero trust never assumes trust permanently; it continuously validates identity, device posture, and context through telemetry and analytics to make real-time access decisions. By contrast, a VPN concentrator (A) reflects the traditional perimeter model of granting broad network access once authenticated, which contradicts zero-trust principles. Implicit trust for internal network traffic (C) is the exact opposite of zero trust, which assumes no implicit trust based on network location and verifies every request explicitly.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.