Open cardosec

Case 1358F4 · GRC · L3 Applied

Zero Trust Architecture

Practise as: Explain it · Interview · Deep dive

Interview questionZero trust is often called a buzzword. What does it actually mean architecturally, and how would you start adopting it?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Core idea (NIST SP 800-207): no implicit trust from network location; every request authenticated and authorized.
  2. Components: Policy Engine and Policy Administrator (the PDP) drive a Policy Enforcement Point in front of resources.
  3. Decisions use identity, device posture, context and resource sensitivity, evaluated per session, not once at login.
  4. Practical moves: phishing-resistant MFA, device compliance checks, ZTNA replacing flat VPN, microsegmentation.
  5. It is a journey: CISA Zero Trust Maturity Model pillars are Identity, Devices, Networks, Apps/Workloads, Data.

If the interviewer pushes back

  • How does zero trust handle east-west traffic between legacy workloads that cannot speak modern auth?
  • Where does a ZTNA product stop and zero trust as a strategy begin? Give a case where buying ZTNA is not zero trust.

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.