220-1102 exam dumps

220-1102 practice question 337 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 337

Single answerZero Trust model

A company is redesigning remote access for employees who use both company-owned laptops and personal tablets. Management wants a Zero Trust approach that reduces the risk of compromised devices reaching internal applications. Which action BEST aligns with the Zero Trust model when users connect to the company's HR portal?

  1. A

    Allow access to the HR portal after a successful VPN connection from any device, because the VPN tunnel makes the device trusted

  2. B

    Require users to authenticate with MFA and verify device compliance before granting application access, even if the user is already on the corporate network

  3. C

    Place all remote users on the same internal network segment after login so security tools can monitor them centrally

  4. D

    Create a permanent allow rule for employee home IP addresses so repeated logins are not challenged

Show answer and explanation

Correct answer: B

Explanation

The best answer is to require MFA and verify device compliance before granting access to the HR portal. Zero Trust follows the principle of 'never trust, always verify.' In practice, this means access decisions are based on identity, device health, location, risk, and least-privilege policy rather than assuming users or devices are trusted because they are on the internal network or using a VPN. This approach is consistent with widely accepted Zero Trust guidance from NIST SP 800-207, which emphasizes continuous verification, policy-based access, and limiting implicit trust. For A+ Core 2, candidates should recognize that Zero Trust shifts security from perimeter-based trust to identity- and context-driven access control.

  • A. Incorrect.

    This is incorrect because Zero Trust does not treat a device as trusted simply because it connected through a VPN. A VPN can encrypt traffic, but it does not prove the device is secure, compliant, or low risk. This option reflects the older perimeter-based model where being 'inside the tunnel' implies trust.

  • B. Correct.

    This is correct because Zero Trust is based on verifying explicitly and continuously. Requiring multifactor authentication and checking device posture or compliance before allowing access to the HR application matches core Zero Trust principles such as least privilege, strong identity verification, and conditional access based on device health and context. It also fits a real-world scenario where both managed and unmanaged devices may attempt to connect.

  • C. Incorrect.

    This is incorrect because Zero Trust favors segmentation and least-privilege access, not broad internal network access. Putting all remote users on the same internal segment increases exposure and lateral movement risk if one account or device is compromised. Centralized monitoring is useful, but it should not come at the cost of excessive access.

  • D. Incorrect.

    This is incorrect because trusting a home IP address is weak security and does not align with Zero Trust. Home IPs can change, be shared, or be used by an attacker who has stolen credentials. Zero Trust focuses on user identity, device state, and contextual verification rather than assuming a connection is safe because it comes from a known network location.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam