AZ-900 Describe cloud concepts Practice Question
What is 'zero trust' security model, and how does Azure support it?
⚠ Common exam trap
Test-takers frequently confuse zero trust with the traditional 'trust but verify' model (Option A) or assume it means no security at all (Option C), when in fact zero trust enforces strict verification for every request regardless of network location.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A model that verifies every access request regardless of network location
The zero trust security model operates on the principle of 'never trust, always verify,' meaning every access request is authenticated, authorized, and encrypted regardless of the user's location or network. Azure supports zero trust through services like Azure Active Directory (now Microsoft Entra ID) for conditional access policies, Azure Policy for enforcing compliance, and Azure Security Center for continuous monitoring and threat detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A model that trusts all traffic within the corporate network boundary
Why it's wrong here
In the traditional 'castle and moat' model, anything inside the corporate network boundary is trusted implicitly, allowing lateral movement once an attacker gains a foothold. Zero Trust inverts this by treating every network—internal or external—as untrusted, requiring verification of identity, device compliance, and context before granting access. The flaw in this option is that network location alone becomes the sole security decision, which fails against threats already inside the perimeter.
- ✓
A model that verifies every access request regardless of network location
Why this is correct
Zero Trust verifies every access request through continuous, explicit validation of identity, device health, and session context, regardless of whether the request originates from the corporate office, a home network, or the public internet. It never assumes trust based on IP address or virtual network placement; instead, policy enforcement evaluates multiple signals in real time and can challenge or block suspicious activity. This model directly addresses modern realities like remote work, cloud workloads, and insider threats by making location irrelevant to access decisions.
- ✗
A model that uses no security controls to maximize productivity
Why it's wrong here
The word 'zero' in Zero Trust modifies trust, not security controls. In fact, Zero Trust typically increases security controls by adding continuous authentication, least-privilege access, microsegmentation, and detailed auditing. This option describes a permissive environment with no controls, which is the opposite of the model's intent: Zero Trust assumes breach and enforces strict verification on every request, while still enabling productivity through risk-based policies.
- ✗
A model that allows only Microsoft-approved applications on Azure
Why it's wrong here
This option confuses Zero Trust with a vendor-specific restriction, but Zero Trust is a security framework that applies to any application, whether first-party Microsoft services, third-party SaaS, or custom on-premises workloads. Microsoft applications such as Office 365 or Dynamics 365 are not exempt from verification—they still require the same conditional access policies, multi-factor authentication, and device compliance checks as any other resource. The principle is impartial: every app gets the same scrutiny, not a curated allowlist.
Go deeper
Related to this question
Learn chapter
The Shared Responsibility Model
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This AZ-900 question is part of Courseiva's 981-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.