Cybersecurity-Practitioner Cybersecurity Fundamentals Practice Question
A security operations team is implementing zero trust network access (ZTNA) principles across the enterprise. According to foundational Zero Trust architecture guidelines, which THREE tenets must be enforced? (Choose three)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify explicitly by authenticating and authorizing based on all available data points
Zero Trust mandates verifying explicitly, using least privilege access, and assuming breach, regardless of whether traffic originates inside or outside the traditional network perimeter.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify explicitly by authenticating and authorizing based on all available data points
Why this is correct
Explicit verification requires validating identity, location, device health, and service context for every access request.
- ✗
Trust users and devices automatically once they successfully authenticate at the network perimeter
Why it's wrong here
Zero Trust rejects implicit trust based on network location or perimeter authentication.
- ✓
Assume breach and continuously monitor all sessions for anomalous behavior
Why this is correct
Assuming breach requires continuous monitoring and verification of all internal and external traffic.
- ✓
Limit user access with Just-In-Time and Just-Enough-Access (JIT/JEA) principles
Why this is correct
Enforcing least privilege via JIT/JEA ensures users only have the exact access needed for the required duration.
- ✗
Grant broad internal network access to trusted partners and contractors to streamline operations
Why it's wrong here
Granting broad access violates least privilege and undermines Zero Trust principles.
About these practice questions
Courseiva writes every Cybersecurity-Practitioner question from scratch — 206 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This Cybersecurity-Practitioner practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Practitioner exam.