nerdexam
Cisco

700-760 · Question #10

What are two steps customers can take to evolve to a trust-centric security philosophy? (Choose two.)

The correct answer is C. Always verify and never trust everything inside and outside the perimeter. E. Only grant access to authorized users and devices. A trust-centric (Zero Trust) security philosophy is built on two foundational principles: never assume anything is safe by default, and restrict access to only those who are verified and authorized - making C and E the correct answers. C ("Always verify and never trust…

Cisco Security Solution Design and Selling

Question

What are two steps customers can take to evolve to a trust-centric security philosophy? (Choose two.)

Options

  • ALimit internal access to networks.
  • BRequire and install agents on mobile devices.
  • CAlways verify and never trust everything inside and outside the perimeter.
  • DBlock BYOD devices.
  • EOnly grant access to authorized users and devices.

How the community answered

(16 responses)
  • C
    94% (15)
  • D
    6% (1)

Explanation

A trust-centric (Zero Trust) security philosophy is built on two foundational principles: never assume anything is safe by default, and restrict access to only those who are verified and authorized - making C and E the correct answers.

C ("Always verify and never trust everything inside and outside the perimeter") captures the core Zero Trust mantra: eliminate implicit trust regardless of whether traffic originates inside or outside the corporate network. E ("Only grant access to authorized users and devices") reflects the least-privilege access model - a pillar of Zero Trust that ensures access is earned through identity verification, not assumed.

The distractors fail because they describe perimeter-based or overly restrictive tactics, not a trust-centric philosophy: A (limiting internal access) is a legacy perimeter control, not a trust philosophy shift. B (requiring agents on mobile devices) is a specific enforcement mechanism, not a philosophical step. D (blocking BYOD) is a blanket restriction that contradicts Zero Trust's goal of granting conditional access to any device, not denying all unmanaged ones outright.

Memory tip: Think "Zero Trust = Verify Everything, Allow Only the Right" - map that to C (verify everything) and E (allow only the right users/devices). If an answer sounds like a blanket block or a legacy perimeter rule, it's a distractor.

Topics

#Zero Trust#Trust-Centric Philosophy#Least Privilege#Verification

Community Discussion

No community discussion yet for this question.

Full 700-760 Practice