A successful login establishes evidence about identity. It does not mean the user should receive every permission on every resource. Security+ zero trust and least-privilege questions often test whether you can keep authentication, authorization, and network location separate.
An original access request
An employee signs in from a company-managed laptop on the office network. The employee works in customer support but requests access to payroll administration. The scenario says the employee has no payroll duties or approved payroll role.
Should the system allow the request simply because the device is corporate-owned and on the internal network? No. Those facts do not establish authorization for payroll administration. The request still needs to satisfy the relevant access policy.
An answer that grants every employee access after one successful login overlooks the difference between proving identity and deciding what that identity may do.
Apply least privilege to the resource
Suppose the same employee needs read access to a specific support dashboard. Granting that limited access can fit the stated job need. Making the employee a global administrator to avoid future access requests grants far more capability than the scenario requires.
Use the Security+ access control practice questions to identify the subject, resource, requested action, and policy condition in each example. “User needs access” is incomplete; read, modify, delete, and administer are different permissions.
Zero trust is not a product name
NIST's zero trust architecture publication describes a model that does not grant implicit trust solely from network location or ownership. An organization applies that principle through architecture, identity controls, policy decisions, and enforcement.
Installing a tool labeled “zero trust” does not automatically prove that all access is appropriately limited. Similarly, using a VPN does not mean every internal resource should trust the connected user without further authorization checks.
Change the scenario and reassess
Now imagine a payroll specialist with an approved role requesting a specific payroll function from a device that fails a required security check. The role is relevant, but the failing condition may still cause the request to be denied or require additional action under policy. One favorable fact does not erase every other condition.
Review the CompTIA Security+ access control study guide when connecting zero trust with role-based access, conditional access, and privileged accounts. A useful answer explains why the requested permission is necessary, which conditions must be satisfied, and where enforcement occurs. That gives you a practical way to evaluate unfamiliar questions instead of choosing every option that happens to contain the words “verify” or “secure.”