Courseiva
Cybersecurity FundamentalshardMultiple SelectObjective-mapped

Cybersecurity-Practitioner Cybersecurity Fundamentals Practice Question

A security operations team is implementing zero trust network access (ZTNA) principles across the enterprise. According to foundational Zero Trust architecture guidelines, which THREE tenets must be enforced? (Choose three)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify explicitly by authenticating and authorizing based on all available data points

Zero Trust mandates verifying explicitly, using least privilege access, and assuming breach, regardless of whether traffic originates inside or outside the traditional network perimeter.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Verify explicitly by authenticating and authorizing based on all available data points

    Why this is correct

    Explicit verification requires validating identity, location, device health, and service context for every access request.

  • Trust users and devices automatically once they successfully authenticate at the network perimeter

    Why it's wrong here

    Zero Trust rejects implicit trust based on network location or perimeter authentication.

  • Assume breach and continuously monitor all sessions for anomalous behavior

    Why this is correct

    Assuming breach requires continuous monitoring and verification of all internal and external traffic.

  • Limit user access with Just-In-Time and Just-Enough-Access (JIT/JEA) principles

    Why this is correct

    Enforcing least privilege via JIT/JEA ensures users only have the exact access needed for the required duration.

  • Grant broad internal network access to trusted partners and contractors to streamline operations

    Why it's wrong here

    Granting broad access violates least privilege and undermines Zero Trust principles.

About these practice questions

Courseiva writes every Cybersecurity-Practitioner question from scratch — 206 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cybersecurity-Practitioner practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Practitioner exam.