A department claims that deploying a VPN is enough to achieve Zero Trust for all municipal cloud apps. Why is that claim incomplete?
Select an answer to reveal the explanation.
Short Explanation
A VPN is a tunnel, not a complete Zero Trust program. Once someone is "inside," perimeter thinking often stops checking—Zero Trust keeps verifying. Location on a private link is only one signal, not the whole strategy.
Full Explanation
Zero Trust assumes breach and continuously validates identity, device, and other signals rather than treating VPN membership as sufficient trust. A VPN can be part of a broader architecture, but by itself it embodies classic perimeter assumptions. Fundamentals items test that distinction without requiring AZ-500 design depth.