Zero trust: never trust the network
P58.zero-trust.01 · Audience: guest, it-ml, language-pro · Prerequisites: The network attack surface, AuthZ models: RBAC, ABAC, ReBAC
The perimeter model says inside the network is trusted. It fails because getting inside is cheap — one phished credential or one compromised container — and on a flat network the attacker then moves laterally, accepted everywhere because of where the packets came from.
Zero trust changes the unit of decision: authenticate and authorise every request on user identity and device posture. The source address becomes context, never permission. That is P56's authorization thinking applied at the network layer.
This module builds the decision function, then steps back to the migration question: what do you change first in a real network?
Ask the mentor about this module
Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.
Keeping your files on this device
Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.
Rung 1 — decide on identity, not on IP
Loading exercise…
Interview rung — migrating to zero trust (free-form)
Loading exercise…
My notes on this module
Loading your notes...
Where next?
Go up a level