700-760 · Question #10
What are two steps customers can take to evolve to a trust-centric security philosophy? (Choose two.)
The correct answer is C. Always verify and never trust everything inside and outside the perimeter. E. Only grant access to authorized users and devices. A trust-centric (Zero Trust) security philosophy is built on two foundational principles: never assume anything is safe by default, and restrict access to only those who are verified and authorized - making C and E the correct answers. C ("Always verify and never trust…
Question
What are two steps customers can take to evolve to a trust-centric security philosophy? (Choose two.)
Options
- ALimit internal access to networks.
- BRequire and install agents on mobile devices.
- CAlways verify and never trust everything inside and outside the perimeter.
- DBlock BYOD devices.
- EOnly grant access to authorized users and devices.
How the community answered
(16 responses)- C94% (15)
- D6% (1)
Explanation
A trust-centric (Zero Trust) security philosophy is built on two foundational principles: never assume anything is safe by default, and restrict access to only those who are verified and authorized - making C and E the correct answers.
C ("Always verify and never trust everything inside and outside the perimeter") captures the core Zero Trust mantra: eliminate implicit trust regardless of whether traffic originates inside or outside the corporate network. E ("Only grant access to authorized users and devices") reflects the least-privilege access model - a pillar of Zero Trust that ensures access is earned through identity verification, not assumed.
The distractors fail because they describe perimeter-based or overly restrictive tactics, not a trust-centric philosophy: A (limiting internal access) is a legacy perimeter control, not a trust philosophy shift. B (requiring agents on mobile devices) is a specific enforcement mechanism, not a philosophical step. D (blocking BYOD) is a blanket restriction that contradicts Zero Trust's goal of granting conditional access to any device, not denying all unmanaged ones outright.
Memory tip: Think "Zero Trust = Verify Everything, Allow Only the Right" - map that to C (verify everything) and E (allow only the right users/devices). If an answer sounds like a blanket block or a legacy perimeter rule, it's a distractor.
Topics
Community Discussion
No community discussion yet for this question.