The city is adopting zero trust so a finance clerk on the "inside" VLAN is still challenged and granted only the access needed for the job. What does that design actually mean?
Select an answer to reveal the explanation.
Short Explanation
Zero trust is not "take the city wall down." It is the bouncer who still checks ID in the employee lounge — inside VLAN or not, prove it and get only the keys you need. Killing the firewall or handing out domain admin is the opposite idea.
Full Explanation
Zero trust assumes no implicit trust from network location, so an inside-VLAN civic user is still authenticated, authorized, and limited to least privilege. It is not perimeter abolition, and it does not replace Splunk Enterprise Security monitoring with a VPN box. Granting broad inside-VLAN admin rights re-creates the castle-and-moat failure zero trust is meant to prevent. Defense Analysts should describe the city's program as continuous verification plus least privilege, then look for ES notables on privilege use rather than treating VLAN membership as a free pass.