Courseiva
SOC OperationshardMultiple SelectObjective-mapped

Cybersecurity-Practitioner SOC Operations Practice Question

An enterprise is implementing a Zero Trust Architecture across its cloud and on-premises environments using Palo Alto Networks Prisma Access and Next-Generation Firewalls. Which THREE of the following principles are core tenets of a Zero Trust Architecture? (Choose three)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assume breach and verify explicitly at every access request

Zero Trust tenets include continuous verification, least privilege access, assuming breach, and treating all networks as untrusted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Rely primarily on perimeter firewalls to secure internal east-west traffic

    Why it's wrong here

    Zero Trust requires internal segmentation and inspection, not reliance solely on perimeter firewalls.

  • Assume breach and verify explicitly at every access request

    Why this is correct

    Assuming breach and performing explicit verification of every access request is a fundamental Zero Trust tenet.

  • Use comprehensive telemetry and analytics to monitor and validate device posture continuously

    Why this is correct

    Continuous monitoring and telemetry evaluation of device health and posture are essential in Zero Trust.

  • Trust internal subnets implicitly once a user authenticates at the corporate perimeter

    Why it's wrong here

    Zero Trust rejects implicit trust based on network location or perimeter placement.

  • Enforce least privilege access with just-in-time and just-enough access controls

    Why this is correct

    Least privilege access combined with JIT/JEA is a core pillar of Zero Trust authorization.

About these practice questions

This Cybersecurity-Practitioner question is part of Courseiva's 206-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This Cybersecurity-Practitioner practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Cybersecurity-Practitioner exam.