In a zero-trust security model, what is the foundational assumption that drives access control decisions?
-
A
All internal network traffic is trusted by default
-
B
No entity — internal or external — is implicitly trusted; every request must be verified
-
C
Firewalls provide sufficient perimeter protection
-
D
Authenticated users retain trust for the duration of their session