MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Which three of the following are core components of Microsoft’s Zero Trust security model as implemented in Microsoft 365? (Choose three.)
⚠ Common exam trap
Candidates often confuse security best practices (like encryption or firewalls) with the core Zero Trust principles, or mistakenly think Zero Trust requires on-premises identity, when in fact it is designed to work with cloud-native identity providers like Microsoft Entra ID.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify explicitly
The Zero Trust security model is built on three foundational principles: verify explicitly, use least privileged access, and assume breach. In Microsoft 365, 'verify explicitly' means authenticating and authorizing every access request based on all available data points (user identity, device health, location, etc.). 'Use least privileged access' limits user permissions to only what is necessary, enforced through tools like Privileged Identity Management (PIM) and Conditional Access. 'Assume breach' designs the environment to minimize blast radius and segment access, assuming an attacker is already present, which drives practices like micro-segmentation and continuous monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify explicitly
Why this is correct
In Zero Trust, 'verify explicitly' means authentication and authorization are evaluated for every access request using all available signals—user identity, device compliance, location, data sensitivity, and anomaly detection—rather than assuming a user is trusted because they are inside the network. This continuous validation is a core pillar because it prevents an attacker from abusing established session trust after connectivity is achieved.
- ✓
Use least privileged access
Why this is correct
Least privilege restricts each user, service, or workload to only the permissions needed for the specific task, often combined with just-in-time elevation and risk-based adaptive policies. By shrinking each identity's blast radius, this core component limits lateral movement and reduces the impact of compromised credentials, which is essential to the Zero Trust model.
- ✓
Assume breach
Why this is correct
Assume breach treats the network as hostile, assuming an attacker may already be present, so Zero Trust requires segmentation, end-to-end encryption, continuous monitoring of user and entity behavior, and hunting for anomalies rather than waiting for a single perimeter failure. This mindset drives proactive detection and rapid response by minimizing the impact of an assumed compromise.
- ✗
Encrypt all data at rest only
Why it's wrong here
Encrypting all data at rest only addresses one part of the security lifecycle and ignores the Zero Trust requirement for protection during transmission and while in use by end users and applications. The model also needs identity-driven access controls and device policies, so a narrow cryptographic measure cannot replace the never trust, always verify foundation.
- ✗
Deploy a single firewall for all traffic
Why it's wrong here
Deploying a single firewall for all traffic reflects a classic perimeter-based architecture where anything inside the firewall is implicitly trusted, which contradicts Zero Trust's fundamental rejection of implicit trust. Zero Trust replaces this with per-request policy enforcement, micro-segmentation, and inspection of traffic at every network layer rather than funneling everything through one choke point.
- ✗
Require on-premises identity provider
Why it's wrong here
Requiring an on-premises identity provider forces a legacy trust boundary and reduces resilience to internet-based identity attacks, whereas Zero Trust is designed to work with modern cloud identity services such as Microsoft Entra ID to verify identities from anywhere. It also interrupts the ability to apply the same access policies across cloud and hybrid environments, so it is not a core component.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Microsoft Migration Tools: SharePoint and Exchange
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.