nerdexam
Palo_Alto_Networks

PCCET · Question #171

Which capability of the network-as-a-service layer uses the philosophy of "never trust, always verify"?

The correct answer is A. Zero Trust network access (ZTNA). Zero Trust Network Access (ZTNA) embodies the 'never trust, always verify' philosophy within the network-as-a-service layer, ensuring continuous authentication and authorization for all access requests.

Submitted by certguy· Apr 18, 2026Network Security

Question

Which capability of the network-as-a-service layer uses the philosophy of "never trust, always verify"?

Options

  • AZero Trust network access (ZTNA)
  • BSoftware-defined wide area network (SD-WAN)
  • CQuality of service (QoS)
  • DVirtual private network (VPN)

How the community answered

(65 responses)
  • A
    91% (59)
  • B
    3% (2)
  • C
    2% (1)
  • D
    5% (3)

Why each option

Zero Trust Network Access (ZTNA) embodies the 'never trust, always verify' philosophy within the network-as-a-service layer, ensuring continuous authentication and authorization for all access requests.

AZero Trust network access (ZTNA)Correct

Zero Trust Network Access (ZTNA) is a key component of a Zero Trust architecture, which operates on the principle of 'never trust, always verify.' ZTNA ensures that every user and device is authenticated and authorized before gaining access to applications and resources, regardless of their network location, eliminating implicit trust based on network segmentation.

BSoftware-defined wide area network (SD-WAN)

Software-Defined Wide Area Network (SD-WAN) primarily focuses on optimizing network performance, traffic routing, and management across geographically dispersed locations, not on a security trust model.

CQuality of service (QoS)

Quality of Service (QoS) mechanisms are used to prioritize specific types of network traffic to ensure predictable performance for critical applications, rather than implementing a security trust philosophy.

DVirtual private network (VPN)

A Virtual Private Network (VPN) traditionally establishes an encrypted tunnel, and once a user is authenticated to the VPN gateway, they are often implicitly trusted to access the internal network, which contradicts the 'never trust, always verify' principle.

Concept tested: Zero Trust Network Access (ZTNA) principles

Source: https://learn.microsoft.com/en-us/security/zero-trust/understand/zero-trust-overview

Topics

#Zero Trust#ZTNA#Network Security#Access Control

Community Discussion

No community discussion yet for this question.

Full PCCET Practice