This lab demonstrates a Zero Trust model where internal applications are not exposed to the public internet. Access is enforced via identity-based policies.