Zero trust admits a stolen but valid credential on a compliant device - what did the model actually remove?
answer
- the tenet is about position
- the engine answered correctly
- true input, wrong holder
- acceptance proves credential, not person
- residual equals the grant's breadth
basics
~20 sZero trust removed network position as evidence, so being inside no longer grants reach. It never claimed to remove credential theft: a real credential on a compliant device is a true input, and every enforcement point downstream will correctly allow it.
solid answer
~50 sThe core tenet of NIST SP 800-207 is that network location is not evidence: each request is decided on identity, device and context rather than on which subnet it arrived from. That removes one adversary - the one whose whole advantage was arriving from an already-trusted position. It removes nothing about a credential that is genuinely valid. If an adversary holds the user's credential and satisfies the same factors from a device that passes posture, the decision returns allow, and it is right to. The input was true and wrong. What the adversary then gets is the union of everything that identity is standing-granted. The honest sentence for a sponsor is that zero trust converts lateral movement *across the network* into lateral reach *across an identity's grants*, and the residual you now carry is how broad those grants are and how fast a true-but-wrong allow becomes visible.
go deeper
Be ready to say in one sentence what the model claims - network position is not evidence - and to name one thing it never claimed, such as stopping a credential that is genuinely valid.
Explain why the policy engine is correct when it admits a stolen credential: the inputs it evaluates are identity, device state and context, none of which assert that the legitimate holder is present.
Show how you bound the damage instead: narrow the standing grants that decide reach, and be specific about what you would measure to notice a true-but-wrong allow after the fact.
Own the framing given to a sponsor who was sold an end to lateral movement. State the residual in writing and defend that it lives in grant breadth and review capacity, not in the gateways.
## The claim, stated precisely Zero trust is not a product and not a promise that intrusions stop. Its central assertion, written down in NIST SP 800-207, is negative: **network position is not evidence**. Being on a corporate subnet, inside a VPN concentrator, or on a wire that terminates in a building you own tells the system nothing about whether this request should be allowed. Every request is decided instead on signals about the subject (an authenticated identity), the device (a posture or compliance claim), and context (the resource, the sensitivity, the time, sometimes behavioural signals), and the decision is made per request rather than once at admission. That is a real removal. The adversary whose entire advantage was reaching a position - having a foothold on a flat internal network where services answered anybody who could route to them - loses that advantage. Services stop answering unauthenticated callers; a foothold on a subnet stops being a key. ## What survives untouched What the model never claimed to remove is a credential that is genuinely valid. Consider the sequence honestly: 1. An adversary holds a real credential for a real employee. 2. They satisfy whatever factors the policy requires. 3. The request comes from a device that is enrolled, patched, encrypted and passing every posture check. 4. The policy engine evaluates its inputs. Every one of them is true. 5. The decision is **allow**, and every enforcement point downstream faithfully enforces it. There is no failure anywhere in that chain. The gateway did not fail open, the rules were not misconfigured, nobody skipped a check. The control worked and the answer was correct - it was simply a correct answer to a question that was never 'is this the right person?'. Authentication establishes that an acceptable credential was presented. It does not establish presence, intent, or that the human named on the account is the one at the keyboard. That distinction - **acceptance proves the credential, not the person** - is the single most common thing candidates get wrong when they describe zero trust as ending intrusions. ## Where the risk went The risk did not disappear; it moved, and knowing where it moved is what an interviewer is testing. Under a perimeter model, an adversary's reach was roughly *everything the compromised host could route to*. Under zero trust, their reach is roughly *everything the compromised identity is entitled to*. Whether that is an improvement depends entirely on how narrow the grants are. An estate that ported every legacy group membership straight into its new access policies has not shrunk anything - it has re-expressed the same broad reach in a new vocabulary, and it now has a dashboard that says every request was authorised. Three things concretely survive the model, and a good answer names them: - **A real credential in the wrong hands.** The decision is correct; the input is true and wrong. - **A compliant but compromised device.** A posture claim is a statement about a machine's configuration. Configuration can be perfect while an adversary is operating on the machine. - **An over-broad grant.** The blast radius is the union of the standing entitlements the identity holds, and over-breadth is only visible on inspection - which is a human review cost, not a technical one. And one thing is newly concentrated: because position no longer carries any weight, *everything* now rests on the identity and device signals feeding the decision. That is deliberate and it is the right trade, but it means the quality of those signals, and of the grants they unlock, is the whole control. ## Saying this without undermining the programme Candidates often swing to the cynical reading - 'so zero trust does nothing'. That is as wrong as the sponsor's reading. The right framing is that it changed the *shape* of the problem: from an adversary who gains reach by moving to an adversary who gains reach by holding an identity. Movement between hosts is now less useful, per-request logging gives you a record of exactly which identity touched which resource, and revocation has a place to bite. What you must not do is let anyone believe lateral movement is impossible, because the next incident will show an authorised-looking access trail and the response will begin with the wrong question - 'which control failed?' - when the answer is that none did. ## What an interviewer wants back One sentence on the claim (position is not evidence), one sentence on the residual (a valid credential inside a real grant), and one sentence on what you would do about it: narrow the grants, since the reach an adversary inherits is exactly the breadth of the entitlements you handed the identity.
- Does requiring multi-factor authentication on every request change that answer?It raises the cost of holding a usable credential, which is worth having, but it does not change the shape. An adversary able to satisfy the second factor at all presents an input the engine must accept, and the decision stays correct. Multi-factor changes how hard a credential is to obtain and hold; it does not change what acceptance proves, which is still that an acceptable credential was presented, not that the named person was present.
- If the enforcement worked and the decision was correct, where do you look for the failure?Not at the gateway. Look at the grant - how much that identity is standing-entitled to, since that is the adversary's whole reach - and at the signals feeding the decision, which asserted an identity and a device state and nothing about intent. The failure is scoped in, not enforced around, so the useful questions are how narrow the grant was and how quickly a true-but-wrong allow becomes visible.
- How would you phrase this in one line for an executive who was told zero trust ends lateral movement?Something like: it ends movement that relies on being inside, and it does not end movement that relies on being someone. An adversary who holds an employee's identity still reaches whatever that employee is entitled to, so the remaining work is narrowing entitlements rather than adding gateways. Put it in writing before an incident, not after, because afterwards it reads as an excuse.
saying these in an interview costs you the question
- Says zero trust prevents credential theft
- Claims lateral movement is impossible once zero trust ships
- Treats a successful access decision as proof the user was present
- Assumes per-request checks re-verify the human each time
- Believes multi-factor turns a stolen credential into a blocked one