Question 1
Q1A financial institution is migrating from a traditional perimeter-based security model to a Zero Trust Architecture (ZTA) following NIST SP 800-207 guidelines. The security test engineer is designing a test strategy to validate the 'Never Trust, Always Verify' principle for a critical internal banking application. The application previously relied solely on network segmentation (VLANs) for security. Which testing approach best validates the core Zero Trust requirement for this migration?
Show answer & explanation
Correct answer: A
Zero Trust mandates that no implicit trust is granted based on network location. Testing must confirm that every request is authenticated and authorized (dynamic authorization) and encrypted (mTLS), effectively treating the internal network as hostile.