Which Security Model Provides Secure Zones and Reduces Threat Scope?

A systems administrator is working on a solution with the following requirements: • Provide a secure zone. • Enforce a company-wide access control policy. • Reduce the scope of threats. Which of the following is the systems administrator setting up?

  1. Zero Trust Source Reference Answer
  2. AAA
  3. Non-repudiation
  4. CIA

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the ability to distinguish between actionable security architectures and abstract security principles, often trapping candidates who confuse implementation frameworks with foundational data protection concepts.

This question evaluates the Zero Trust security model's ability to enforce strict access controls while minimizing threat exposure through architectural design. The community unanimously identifies Zero Trust as the only framework that directly satisfies all three stated operational requirements.

Candidates frequently select CIA because it is a universally recognized security triad, but they overlook that CIA defines data protection objectives rather than an implementable network architecture or access enforcement mechanism.

Community Discussion (4 comments)

dbrowndiver 👍 10 Selected: A
Zero Trust is a security framework that aligns perfectly with the given requirements. It emphasizes strict access control, minimizing trust, and ensuring that all access requests are verified, making it an ideal choice for creating a secure environment.
squishy_fishy 👍 1 Selected: A
The Zero Trust security model is based on the principle of “never trust, always verify.” It aligns with the given requirements: Provide a secure zone – Zero Trust micro-segmentation ensures that only authorized users and devices can access specific network areas. Enforce a company-wide access control policy – Zero Trust implements strict access controls using authentication and least privilege principles. Reduce the scope of threats – By assuming that threats exist inside and outside the network, Zero Trust reduces attack surfaces and prevents lateral movement by attackers. Zero Trust requires continuous authentication and authorization, using technologies such as multi-factor authentication (MFA), identity-based access controls, and network segmentation.
9149f41 👍 2 Selected: A
Why D. CIA is not correct: CIA (Confidentiality, Integrity, Availability): CIA is a security model that focuses on protecting data, but it is not a framework or architecture like Zero Trust. It does not directly address the requirements listed.
Shaman73 👍 1 Selected: A
A. Zero Trust

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Framework vs. Abstract Concepts

The scenario outlines three critical operational goals: creating a secure zone, enforcing centralized access policies, and minimizing threat impact. These are hallmark characteristics of Zero Trust, a modern security paradigm built on the principle of "never trust, always verify." Unlike traditional perimeter-based models, Zero Trust assumes breach and continuously validates every user, device, and application before granting access.

Mapping Requirements to Zero Trust

As highlighted by community contributors like squishy_fishy, Zero Trust naturally aligns with the prompt's demands. It utilizes micro-segmentation to create isolated secure zones, ensuring lateral movement is restricted. Simultaneously, it enforces company-wide access control policies through identity-centric authentication and least-privilege access rules. By constantly verifying credentials and device health, it inherently reduces the scope of threats and limits potential damage from compromised assets.

Evaluating the Incorrect Options

While AAA (Authentication, Authorization, Accounting) provides the underlying mechanisms for access management, it is a protocol framework rather than a comprehensive security architecture designed specifically for threat reduction and secure zoning. Non-repudiation ensures users cannot deny their actions, which relates to auditing and legal accountability, not network segmentation or access enforcement. Finally, as noted in the discussion, CIA represents a foundational security triad focused on data properties, not an implementable system or zone configuration.

Conclusion

Choosing Zero Trust demonstrates an understanding of how modern security architectures proactively manage risk through continuous verification and strict compartmentalization, making it the definitive answer for this scenario.

Official Reference

Exam Strategy

When encountering questions that list multiple operational goals like "secure zone," "access control," and "threat reduction," prioritize identifying a holistic security architecture over isolated protocols or theoretical models. Look for keywords implying continuous verification, least privilege, and network compartmentalization, which strongly point toward Zero Trust implementations.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide