Courseiva
easyMultiple Select

CISSP Practice Question: Which TWO of the following are principles of the…

Which TWO of the following are principles of the zero trust security model? (Select TWO.)

⚠ Common exam trap

Watch out — candidates often confuse 'trust but verify' (a legacy perimeter model) with zero trust, or assume that zero trust still allows some inherent trust for authenticated users, when in fact it requires verification for every single access request regardless of prior authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Never trust, always verify

Option B, "Never trust, always verify," is a core zero trust principle: every access request must be explicitly authenticated and authorized based on identity, device posture, and context, regardless of where it originates. Option D, "Assume all networks are hostile," is also correct because zero trust treats both internal and external networks as untrusted, eliminating the implicit trust traditionally granted to traffic inside a corporate perimeter. In contrast, option A ("Trust but verify") reflects the older perimeter-based model where internal entities are trusted by default, which zero trust explicitly rejects. Option C is wrong because zero trust assumes no user is inherently trustworthy; trust must be continuously evaluated. Option E is wrong because zero trust moves away from relying on perimeter defenses like firewalls alone, instead enforcing microsegmentation and per-request policy checks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Trust but verify

    Why it's wrong here

    This principle, often associated with traditional security models, suggests an initial level of trust is granted, followed by verification. Zero Trust fundamentally rejects this by assuming no entity, device, or network is trustworthy by default, requiring continuous validation for every access request. It represents a reactive approach to security rather than the proactive distrust inherent in Zero Trust.

  • ✓

    Never trust, always verify

    Why this is correct

    This is a foundational tenet of Zero Trust, mandating that no user, device, application, or network segment is inherently trustworthy, regardless of its location or prior authentication. Every access request must be explicitly and continuously authenticated, authorized, and validated based on all available contextual data. This continuous verification ensures that trust is never implicitly granted but earned and re-evaluated for each transaction.

  • ✗

    Users are inherently trustworthy

    Why it's wrong here

    The assumption that users are inherently trustworthy directly contradicts the core philosophy of Zero Trust, which operates on the principle of 'never trust, always verify.' Zero Trust mandates that all users, whether internal or external, must have their identity and authorization continuously validated before being granted access to resources. This approach mitigates risks associated with compromised credentials, insider threats, and human error by eliminating implicit trust.

  • ✓

    Assume all networks are hostile

    Why this is correct

    This Zero Trust principle dictates that all network environments, including internal corporate networks, should be treated as potentially compromised or untrusted. It rejects the traditional notion of a secure internal perimeter and drives the implementation of micro-segmentation and granular access controls. By assuming hostility, organizations are compelled to implement robust security measures, such as strong authentication and encryption, for all data in transit, regardless of its network location.

  • ✗

    Perimeter defenses are sufficient

    Why it's wrong here

    Relying solely on perimeter defenses is a characteristic of legacy security models and is fundamentally incompatible with Zero Trust architecture. Zero Trust acknowledges that sophisticated threats can bypass traditional firewalls and intrusion detection systems, making the internal network vulnerable. Instead, it advocates for protecting individual resources and data directly, moving security enforcement closer to the assets rather than solely at the network edge.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.