easyMultiple Select
CISSP Practice Question: Which TWO of the following are principles of the…
Which TWO of the following are principles of the zero trust security model? (Select TWO.)
⚠ Common exam trap
Watch out — candidates often confuse 'trust but verify' (a legacy perimeter model) with zero trust, or assume that zero trust still allows some inherent trust for authenticated users, when in fact it requires verification for every single access request regardless of prior authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Never trust, always verify
Option B, "Never trust, always verify," is a core zero trust principle: every access request must be explicitly authenticated and authorized based on identity, device posture, and context, regardless of where it originates. Option D, "Assume all networks are hostile," is also correct because zero trust treats both internal and external networks as untrusted, eliminating the implicit trust traditionally granted to traffic inside a corporate perimeter. In contrast, option A ("Trust but verify") reflects the older perimeter-based model where internal entities are trusted by default, which zero trust explicitly rejects. Option C is wrong because zero trust assumes no user is inherently trustworthy; trust must be continuously evaluated. Option E is wrong because zero trust moves away from relying on perimeter defenses like firewalls alone, instead enforcing microsegmentation and per-request policy checks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trust but verify
Why it's wrong here
This principle, often associated with traditional security models, suggests an initial level of trust is granted, followed by verification. Zero Trust fundamentally rejects this by assuming no entity, device, or network is trustworthy by default, requiring continuous validation for every access request. It represents a reactive approach to security rather than the proactive distrust inherent in Zero Trust.
- ✓
Never trust, always verify
Why this is correct
This is a foundational tenet of Zero Trust, mandating that no user, device, application, or network segment is inherently trustworthy, regardless of its location or prior authentication. Every access request must be explicitly and continuously authenticated, authorized, and validated based on all available contextual data. This continuous verification ensures that trust is never implicitly granted but earned and re-evaluated for each transaction.
- ✗
Users are inherently trustworthy
Why it's wrong here
The assumption that users are inherently trustworthy directly contradicts the core philosophy of Zero Trust, which operates on the principle of 'never trust, always verify.' Zero Trust mandates that all users, whether internal or external, must have their identity and authorization continuously validated before being granted access to resources. This approach mitigates risks associated with compromised credentials, insider threats, and human error by eliminating implicit trust.
- ✓
Assume all networks are hostile
Why this is correct
This Zero Trust principle dictates that all network environments, including internal corporate networks, should be treated as potentially compromised or untrusted. It rejects the traditional notion of a secure internal perimeter and drives the implementation of micro-segmentation and granular access controls. By assuming hostility, organizations are compelled to implement robust security measures, such as strong authentication and encryption, for all data in transit, regardless of its network location.
- ✗
Perimeter defenses are sufficient
Why it's wrong here
Relying solely on perimeter defenses is a characteristic of legacy security models and is fundamentally incompatible with Zero Trust architecture. Zero Trust acknowledges that sophisticated threats can bypass traditional firewalls and intrusion detection systems, making the internal network vulnerable. Instead, it advocates for protecting individual resources and data directly, moving security enforcement closer to the assets rather than solely at the network edge.
Go deeper
Related to this question
Learn chapter
Access Control Models and Mechanisms
Key term
Security model
A security model is a formal framework that defines how subjects (users, processes) can access objects (files, resources) based on rules, ensuring confidentiality, integrity, and availability.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.