A county moves from trusting the internal LAN by default to verifying every access request. Which principle best describes that shift?
Select an answer to reveal the explanation.
Short Explanation
Old castle thinking said 'inside the moat equals safe.' Zero trust says 'show your badge every door, every time' — even on the so-called inside. It is continuous verification, not 'throw away the VPN and hope.'
Full Explanation
Zero trust reduces implicit trust based on network location and instead continuously verifies identity, context, and policy before granting access. Moving from 'trust the internal LAN' to verifying each request aligns with that model. Zero trust is not defined as deleting all remote access, disabling encryption, or expanding standing privileges. Security+ frames zero trust around always-verify concepts and related control/data-plane ideas rather than vendor slogans alone.