700-760 · Question #32
Which statement embodies trust-centric security?
The correct answer is D. Verify before granting access via identity-based policies for users, devices, apps. and locations. Option D is correct because "trust-centric security" (also called Zero Trust) is built on the principle of never trust, always verify - and verification must span all four pillars: identity (users), devices, applications, and locations. This comprehensive verification across…
Question
Which statement embodies trust-centric security?
Options
- AVerify before granting access via MDM software
- BPrevent attacks via an intelligence-based policy, then detect, investigate, and remediate
- CProtect users from attacks by enabling strict security policies.
- DVerify before granting access via identity-based policies for users, devices, apps. and locations
How the community answered
(31 responses)- A3% (1)
- B3% (1)
- D94% (29)
Explanation
Option D is correct because "trust-centric security" (also called Zero Trust) is built on the principle of never trust, always verify - and verification must span all four pillars: identity (users), devices, applications, and locations. This comprehensive verification across every access dimension is the defining characteristic of a Zero Trust architecture.
Why the distractors fail:
- A is too narrow - MDM (Mobile Device Management) only verifies devices, ignoring users, apps, and locations.
- B describes a threat intelligence / detect-and-respond model (like XDR/SIEM), which is a reactive security posture, not a trust-verification framework.
- C describes perimeter-based or policy enforcement security (e.g., firewalls, web filters) - protecting users from external threats rather than continuously verifying access trustworthiness.
Memory tip: Think of Zero Trust as asking "Who are you, what are you using, what do you want, and where are you?" before granting any access. Option D is the only choice that checks all four of those boxes (users, devices, apps, locations). If an answer only mentions one of these, it's incomplete - and therefore wrong.
Topics
Community Discussion
No community discussion yet for this question.