SY0-701 General Security Concepts Practice Question
A security engineer is designing a Zero Trust architecture for a company that has a mix of on-premises and cloud resources. The engineer needs to implement controls that align with the core principles of Zero Trust. Which of the following are core principles of Zero Trust? (Choose two.)
⚠ Common exam trap
The trap here is selecting 'trust but verify' because it sounds similar, but Zero Trust actually requires 'never trust, always verify'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use least privilege access
Zero Trust is built on principles such as verify explicitly, use least privilege access, and assume breach. These ensure that no entity is trusted by default and that access is continuously evaluated. Trust but verify, perimeter reliance, and SSO are not core principles; they either contradict Zero Trust or are implementation details that may support it but are not foundational requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rely on network perimeter defenses
Why it's wrong here
Zero Trust moves away from relying solely on perimeter defenses like firewalls. It assumes that the perimeter can be breached and that internal networks are not inherently secure. Instead, Zero Trust focuses on micro-segmentation, identity-based controls, and continuous monitoring. Perimeter defense is not a core principle; it is the opposite of Zero Trust's assume-breach mindset.
- ✗
Trust but verify
Why it's wrong here
Trust but verify is a traditional security mantra that implies a baseline of trust. Zero Trust rejects this by never trusting implicitly. Instead, Zero Trust requires explicit verification for every access request. The phrase is often mistakenly associated with Zero Trust, but it contradicts the core tenet of 'never trust, always verify.' Therefore, it is not a core principle of Zero Trust.
- ✓
Use least privilege access
Why this is correct
Least privilege access is a core Zero Trust principle that limits user and device access to only what is necessary to perform their tasks. This minimizes the potential blast radius of a compromise. In Zero Trust, permissions are granted just-in-time and just-enough, and are continuously evaluated. This principle is explicitly part of the Zero Trust model as defined by NIST and other frameworks.
- ✓
Assume breach and verify explicitly
Why this is correct
Assuming breach means operating as if the network is already compromised and not granting implicit trust based on location. Verifying explicitly means every access request is authenticated and authorized based on all available data points. These are fundamental Zero Trust principles. They ensure that no user or device is trusted by default, regardless of whether they are inside or outside the corporate network.
- ✗
Implement single sign-on (SSO) for all users
Why it's wrong here
While SSO can improve user experience and centralize authentication, it is not a core principle of Zero Trust. SSO is a technology that can support Zero Trust by enabling centralized policy enforcement, but Zero Trust does not require SSO. Core principles focus on concepts like explicit verification, least privilege, and assume breach, not specific authentication mechanisms.
Go deeper
Related to this question
Learn chapter
Access Control Models (DAC, MAC, RBAC)
Key term
SSO
Single Sign-On (SSO) is an authentication process that allows a user to access multiple applications or systems with one set of login credentials.
Key term
Zero Trust
Zero Trust is a security framework that assumes no user, device, or network is automatically trusted, requiring verification for every access request regardless of its origin.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,030 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.