Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Which three of the following are core components of Microsoft’s Zero Trust security model as implemented in Microsoft 365? (Choose three.)

⚠ Common exam trap

Candidates often confuse security best practices (like encryption or firewalls) with the core Zero Trust principles, or mistakenly think Zero Trust requires on-premises identity, when in fact it is designed to work with cloud-native identity providers like Microsoft Entra ID.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify explicitly

The Zero Trust security model is built on three foundational principles: verify explicitly, use least privileged access, and assume breach. In Microsoft 365, 'verify explicitly' means authenticating and authorizing every access request based on all available data points (user identity, device health, location, etc.). 'Use least privileged access' limits user permissions to only what is necessary, enforced through tools like Privileged Identity Management (PIM) and Conditional Access. 'Assume breach' designs the environment to minimize blast radius and segment access, assuming an attacker is already present, which drives practices like micro-segmentation and continuous monitoring.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Verify explicitly

    Why this is correct

    In Zero Trust, 'verify explicitly' means authentication and authorization are evaluated for every access request using all available signals—user identity, device compliance, location, data sensitivity, and anomaly detection—rather than assuming a user is trusted because they are inside the network. This continuous validation is a core pillar because it prevents an attacker from abusing established session trust after connectivity is achieved.

  • ✓

    Use least privileged access

    Why this is correct

    Least privilege restricts each user, service, or workload to only the permissions needed for the specific task, often combined with just-in-time elevation and risk-based adaptive policies. By shrinking each identity's blast radius, this core component limits lateral movement and reduces the impact of compromised credentials, which is essential to the Zero Trust model.

  • ✓

    Assume breach

    Why this is correct

    Assume breach treats the network as hostile, assuming an attacker may already be present, so Zero Trust requires segmentation, end-to-end encryption, continuous monitoring of user and entity behavior, and hunting for anomalies rather than waiting for a single perimeter failure. This mindset drives proactive detection and rapid response by minimizing the impact of an assumed compromise.

  • ✗

    Encrypt all data at rest only

    Why it's wrong here

    Encrypting all data at rest only addresses one part of the security lifecycle and ignores the Zero Trust requirement for protection during transmission and while in use by end users and applications. The model also needs identity-driven access controls and device policies, so a narrow cryptographic measure cannot replace the never trust, always verify foundation.

  • ✗

    Deploy a single firewall for all traffic

    Why it's wrong here

    Deploying a single firewall for all traffic reflects a classic perimeter-based architecture where anything inside the firewall is implicitly trusted, which contradicts Zero Trust's fundamental rejection of implicit trust. Zero Trust replaces this with per-request policy enforcement, micro-segmentation, and inspection of traffic at every network layer rather than funneling everything through one choke point.

  • ✗

    Require on-premises identity provider

    Why it's wrong here

    Requiring an on-premises identity provider forces a legacy trust boundary and reduces resilience to internet-based identity attacks, whereas Zero Trust is designed to work with modern cloud identity services such as Microsoft Entra ID to verify identities from anywhere. It also interrupts the ability to apply the same access policies across cloud and hybrid environments, so it is not a core component.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.