HPE2-W07 · Question #96
How does Zero Trust Security differ from outdated security practices?
The correct answer is A. Zero Trust Security relies on user input because network administrators can no longer be trusted. Important note: there appears to be an error in the provided answer key. Option A is actually incorrect, and option D is the correct answer. D is correct because Zero Trust Security is fundamentally about protecting individual resources (data, applications, services) rather…
Question
How does Zero Trust Security differ from outdated security practices?
Options
- AZero Trust Security relies on user input because network administrators can no longer be trusted
- BZero Trust Security assumes every user needs basic network access instead of starting with a
- CZero Trust Security focuses on protecting the network perimeter and does not rely on user roles.
- DZero Trust Security focuses on protecting resources as opposed to network segments.
How the community answered
(33 responses)- A85% (28)
- B3% (1)
- C9% (3)
- D3% (1)
Explanation
Important note: there appears to be an error in the provided answer key. Option A is actually incorrect, and option D is the correct answer.
D is correct because Zero Trust Security is fundamentally about protecting individual resources (data, applications, services) rather than defending a network perimeter or segment. Traditional security assumed everything inside the network was safe - Zero Trust eliminates that assumption entirely, requiring verification for every access request regardless of location.
Why A is wrong: Zero Trust does not "rely on user input," nor is it motivated by distrust of administrators specifically. It's a systematic architecture principle - "never trust, always verify" - applied to all users, devices, and connections, not a response to untrustworthy admins.
Why B is wrong: Zero Trust is the opposite - it starts with zero access and grants only what is needed (least-privilege), rather than assuming users need basic access by default.
Why C is wrong: Protecting the network perimeter is the old model (castle-and-moat). Zero Trust explicitly moves away from perimeter-based thinking, and it absolutely does rely on user roles and identity as part of granular access control.
Memory tip: Think of the name literally - "Zero Trust" means you trust nothing by default (no network segment, no user, no device). The focus shifts inward to the resource itself, not the walls around it.
Recommend verifying this question with your instructor or official study material - the listed correct answer (A) conflicts with the established definition of Zero Trust.
Topics
Community Discussion
No community discussion yet for this question.