N10-009 exam dumps

N10-009 practice question 129 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 129

Single answerZero trust architecture (ZTA): Policy-based authentication, Authorization, Least privilege access

A company is replacing its legacy VPN with a zero trust architecture (ZTA) solution for internal web applications. The security team wants access decisions to be based on user identity, device security posture, and the sensitivity of the requested application. Developers should be able to access the code repository only from managed devices, while temporary contractors should have access only to a specific ticketing system and nothing else. Which solution BEST meets these requirements?

  1. A

    Place all internal applications behind a VPN and allow access to any authenticated user after successful login

  2. B

    Implement policy-based access that evaluates identity, device compliance, and application sensitivity before granting per-application access

  3. C

    Assign all users to the same remote access group and rely on network segmentation alone to restrict sensitive applications

  4. D

    Use a shared administrator account for contractors so their activity can be centrally managed and quickly revoked

Show answer and explanation

Correct answer: B

Explanation

The best answer is the policy-based access solution because zero trust architecture is built around the idea of explicitly verifying every access request based on multiple attributes, not just network location or a one-time login. In practice, this means evaluating identity, device posture, and the sensitivity of the requested resource before granting access. It also means enforcing least privilege by giving each user only the minimum access needed for their role. Per-application access is preferred over full network connectivity because it reduces lateral movement and limits exposure if credentials are compromised. This approach is consistent with zero trust guidance from NIST SP 800-207, which emphasizes continuous verification, policy decision points, and resource-specific access decisions rather than implicit trust based on network presence.

  • A. Incorrect.

    This is incorrect because a traditional VPN that grants broad network access after a single authentication event does not align well with zero trust principles. ZTA focuses on continuous or context-aware verification and limits access to specific resources rather than placing users on the internal network. Allowing any authenticated user broad access increases the attack surface and violates least privilege.

  • B. Correct.

    This is correct because policy-based access control is a core zero trust concept. It uses contextual signals such as user identity, device posture, and resource sensitivity to make authorization decisions. Granting per-application access instead of broad network access supports least privilege, and restricting developers to managed devices while limiting contractors to one application matches real-world zero trust enforcement.

  • C. Incorrect.

    This is incorrect because network segmentation can reduce lateral movement, but by itself it does not satisfy zero trust requirements for policy-based authentication and authorization. If all users are placed into the same access group, authorization is too broad and does not enforce least privilege at the user and application level.

  • D. Incorrect.

    This is incorrect because shared accounts are a security anti-pattern. Zero trust depends on strong identity and accountability for each subject requesting access. Shared administrator accounts prevent proper auditing, violate least privilege, and typically grant excessive permissions to contractors who should instead receive narrowly scoped individual access.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam