- Home
- All questions
- Question 22
CISSP study material · question 22 of 500
A retailer is redesigning access after a breach in which an intruder who reached one internal subnet moved freely between servers. The architects want the model described in NIST SP 800-207 zero trust architecture. Which principle should drive the redesign?
Show the answer
Answer: A. Grant no implicit trust from an asset's network location or ownership, and evaluate each request on its own merits.
Zero trust withholds implicit trust from network location and asset ownership; enterprise ownership earns no free pass, so trusting managed devices simply rebuilds the perimeter assumption inside the network.
Source: NIST SP 800-207 (NIST) — SP 800-207 > Abstract