Courseiva
Network Defense ManagementhardMultiple SelectObjective-mapped

CND Network Defense Management Practice Question

A security architect is designing a Zero Trust Architecture (ZTA) framework in accordance with NIST SP 800-207. Which THREE core tenets must be incorporated into the network defense strategy? (Choose three)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assume breach: minimize blast radius by micro-segmenting resources and assuming the network is hostile.

NIST SP 800-207 Zero Trust tenets include continuous verification of trust, least privilege access enforcement, and dynamic policy evaluation based on all available telemetry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assume breach: minimize blast radius by micro-segmenting resources and assuming the network is hostile.

    Why this is correct

    Assuming breach ensures that internal network compromise does not mean total infrastructure access.

  • Implicitly trust all devices connected to the internal corporate LAN backbone

    Why it's wrong here

    Zero Trust explicitly rejects the concept of an implicit trusted internal network zone.

  • Always verify explicitly: authentication and authorization are validated continuously before every access request.

    Why this is correct

    Continuous verification is a foundational tenet of Zero Trust.

  • Rely solely on perimeter firewall packet filtering for all internal security enforcement

    Why it's wrong here

    ZTA moves away from perimeter-only trust models toward device- and identity-centric controls.

  • Use least privilege access: restrict user and device access with Just-In-Time (JIT) and Just-Enough-Access (JEA).

    Why this is correct

    Least privilege limits potential damage from compromised credentials.

About these practice questions

This CND question is part of Courseiva's 323-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.