Courseiva

Implementing Zero Trust: Verify Explicitly, Least Privilege, Assume Breach

Your organization uses Microsoft Entra ID and has strict security requirements. You need to implement a Zero Trust security model. Which THREE of the following are foundational principles of Zero Trust that should be implemented?

Quick Answer

The answer is verify explicitly, least privilege, and assume breach. These three foundational principles of Zero Trust form the core of Microsoft’s security model, requiring every access request to be authenticated and authorized based on all available data points, granting only the minimum permissions necessary for a task, and continuously monitoring for threats as if a breach has already occurred. On the Microsoft 365 Administrator MS-102 exam, this question tests your ability to distinguish these core pillars from supporting technologies like multifactor authentication or device compliance, which are implementation tools rather than principles. A common trap is confusing “verify explicitly” with simple password checks—remember it demands real-time risk evaluation, not just static credentials. To lock in the concept, use the mnemonic VLA: Verify, Least, Assume—the three non-negotiable legs of the Zero Trust stool.

⚠ Common exam trap

Microsoft often tests the distinction between security best practices (like segmentation) and the specific foundational principles of Zero Trust, causing candidates to select 'Segment access' because it sounds correct, but it is not one of the three core pillars defined by Microsoft.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use least privilege access

Least privilege access is a foundational principle of Zero Trust, ensuring users and devices are granted only the minimum permissions necessary to perform their tasks. In Microsoft Entra ID, this is implemented through features like Privileged Identity Management (PIM) and conditional access policies that restrict access based on role and context, reducing the attack surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assume trust based on location

    Why it's wrong here

    Zero Trust assumes no implicit trust.

  • Segment access

    Why it's wrong here

    Network segmentation is a tactic, not a core principle.

  • Use least privilege access

    Why this is correct

    Limit user access with Just-In-Time and Just-Enough-Access (JIT/JEA).

  • Assume breach

    Why this is correct

    Assume that breaches have happened and will happen, and design accordingly.

  • Verify explicitly

    Why this is correct

    Always authenticate and authorize based on all available data points.

About these practice questions

One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MS-102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization is implementing a zero-trust security model. Which TWO Microsoft Entra ID features should you enable to enforce least-privilege access and continuous verification?

medium
  • A.Conditional Access
  • B.Self-service password reset (SSPR)
  • C.Privileged Identity Management (PIM)
  • D.Application Proxy
  • E.Microsoft Entra Join

Why A: Conditional Access (A) is correct because it enforces least-privilege access by applying policies that require specific conditions (e.g., device compliance, location, risk level) before granting access to resources. It also enables continuous verification by evaluating signals in real time during each authentication request, ensuring that access is revoked if conditions change (e.g., user risk increases). This aligns directly with the zero-trust principle of 'never trust, always verify.'

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.