A company implements a security model where no user or device is automatically trusted, even if they are inside the corporate network. Every access request must be authenticated, authorized, and encrypted before granting access, regardless of the request origin. This model is known as:
Zero Trust is the security model that fundamentally assumes no user, device, or application should be automatically trusted, regardless of its location inside or outside the network perimeter. It mandates explicit verification for every access request, ensuring identity and device health are validated before granting access. This model strictly enforces least privilege access and operates under an 'assume breach' mentality, continuously monitoring and re-validating trust throughout a session.
Why this answer
Zero Trust is a security model that explicitly assumes no implicit trust based on network location. Every access request must be authenticated, authorized, and encrypted, regardless of whether it originates from inside or outside the corporate network. This aligns with the core Zero Trust principle of 'never trust, always verify'.
Exam trap
The trap here is that candidates often confuse Zero Trust with Defense in depth, assuming that multiple layers of security automatically remove implicit trust, but Zero Trust specifically targets the assumption of trust based on network location.
Why the other options are wrong
Defense in depth is a layered security strategy using multiple controls, but it does not inherently reject automatic trust for internal users or devices. The question specifically describes the core principle of Zero Trust: never trust, always verify.
Perimeter security relies on a trusted internal network and a defended boundary, but the question explicitly states that no user or device is automatically trusted even inside the network, which contradicts the perimeter model.
Least privilege is a principle that restricts users to only the permissions necessary for their tasks, but it does not address the core concept of never trusting any request by default, regardless of origin, which is the defining characteristic of Zero Trust.
When would these options actually be correct?
A question asking: 'Which security model uses multiple layers of controls (e.g., firewalls, antivirus, IDS) to protect assets?' would make Defense in depth the correct answer, as it emphasizes layered defenses rather than trust verification.
A question that asks: 'A company uses firewalls, IDS/IPS, and VPNs to protect its network boundary from external threats. Which security model does this describe?' Then perimeter security would be correct.
A question that asks: 'Which security principle ensures that users and processes are granted only the minimum access rights needed to perform their job functions?' would have Least privilege as the correct answer.
Why candidates pick the wrong answer
Candidates may confuse the layered approach of defense in depth with the 'never trust' concept, assuming multiple layers inherently distrust internal traffic, when in fact traditional defense in depth often trusts the internal network.
Candidates may confuse perimeter security with Zero Trust because both involve security controls, but they fail to recognize that Zero Trust eliminates implicit trust, whereas perimeter security trusts internal traffic by default.
Candidates may confuse least privilege with Zero Trust because both involve limiting access, but they focus on different aspects: least privilege is about permission levels, while Zero Trust is about continuous verification of every request.