Courseiva
hardMultiple Select

Key Zero Trust Principles Using Microsoft 365 Defender

A company is implementing a Zero Trust security model using Microsoft 365 Defender. Which THREE of the following are key principles they should follow?

Quick Answer

The answer is verifying explicitly based on all available data points, such as user identity, device health, and location. This is correct because Zero Trust eliminates implicit trust and requires continuous validation of every access request; Microsoft 365 Defender operationalizes this by aggregating signals across endpoints, identities, and cloud apps to enforce conditional access decisions in real time. On the Microsoft Cybersecurity Architect exam, this principle tests your understanding of how Defender’s correlation engine feeds into Azure AD Conditional Access policies, with a common trap being to confuse “verify explicitly” with simple multi-factor authentication—remember that explicit verification must consider dynamic risk signals, not just a static password. A memory tip: think of the acronym “V.E.D.”—Verify Explicitly using all Data points—to distinguish this from the other two core Zero Trust pillars of least privilege and assume breach.

⚠ Common exam trap

Watch out — candidates often confuse Zero Trust with traditional perimeter-based security, mistakenly believing that internal network origin or known user status should be trusted implicitly, when in fact Zero Trust requires explicit verification for every access request regardless of source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use least privilege access by limiting user permissions with Just-In-Time and Just-Enough-Access.

Option B is correct because Zero Trust requires least privilege access, and Microsoft recommends Just-In-Time (JIT) and Just-Enough-Access (JEA) with Privileged Identity Management (PIM) to grant permissions only when needed and only for the required scope. Option D is correct because the 'assume breach' principle means designing as if attackers are already present, using micro-segmentation, network segmentation, and conditional access to limit lateral movement and reduce blast radius. Option E is correct because 'verify explicitly' is the foundational Zero Trust principle: every access request must be authenticated and authorized using all available signals such as user identity, device compliance, location, and risk level via Conditional Access and Microsoft 365 Defender signals. Option A is incorrect because trusting all traffic from the corporate network is the traditional perimeter-based model that Zero Trust explicitly rejects; internal networks are not inherently trusted. Option C is incorrect because implicit trust for known users or devices contradicts Zero Trust, which requires continuous verification rather than granting trust based on prior knowledge or network location.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Trust all traffic originating from within the corporate network.

    Why it's wrong here

    Zero Trust rejects network location as a trust signal; internal traffic is verified exactly like external traffic. It is tempting because the corporate network was historically considered safe, but that castle-and-moat assumption is what Zero Trust replaces with explicit verification, least privilege and assume-breach principles.

  • ✓

    Use least privilege access by limiting user permissions with Just-In-Time and Just-Enough-Access.

    Why this is correct

    Least privilege with Just-In-Time and Just-Enough-Access limits standing permissions, granting elevated rights only when needed and for the minimum scope. This satisfies Zero Trust's explicit-verification and assume-breach principles by shrinking the persistent attack surface available to compromised identities.

  • ✗

    Provide implicit trust to known users and devices.

    Why it's wrong here

    Zero Trust grants no implicit trust based on identity or device alone; every access request is verified explicitly using least privilege and assume-breach thinking. It is tempting because known users appear lower risk, but that is perimeter-based trust, which Zero Trust principles explicitly reject in favour of continuous verification.

  • ✓

    Assume breach and segment access to minimize blast radius.

    Why this is correct

    Assuming breach removes implicit trust in any segment, so access is segmented to contain lateral movement and limit blast radius. This satisfies the Zero Trust requirement by designing controls that minimise damage when an identity or device is already compromised.

  • ✓

    Verify explicitly based on all available data points (user, device, location, etc.).

    Why this is correct

    Verifying explicitly uses every available signal — user identity, device health, location and risk — before granting access to a resource. This satisfies the Zero Trust requirement by replacing static, network-based trust with continuous, data-driven authentication decisions at each request.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A multinational company is implementing a Zero Trust security model. The security team needs to ensure that all access requests to critical applications are evaluated based on user identity, device health, and real-time risk signals. Which Microsoft solution should they use to centralize policy enforcement?

medium
  • A.Microsoft Defender for Cloud Apps
  • ✓ B.Microsoft Entra Conditional Access
  • C.Azure AD Identity Protection
  • D.Microsoft Purview Compliance Manager

Why B: Microsoft Entra Conditional Access is the correct choice because it is the policy engine in Microsoft Entra ID that centralizes access decisions by evaluating signals such as user identity, group membership, device compliance/health, location, and real-time risk before granting access to applications. This aligns directly with Zero Trust's 'verify explicitly' principle, since Conditional Access enforces grant controls (for example, require MFA or a compliant device) and session controls at the point of access. Microsoft Defender for Cloud Apps is a CASB for discovering and governing cloud app usage, not the central policy enforcement point for identity-based access. Azure AD Identity Protection detects and reports risky users and sign-ins and feeds risk signals into Conditional Access, but it does not itself centralize access policy enforcement. Microsoft Purview Compliance Manager is a compliance assessment and improvement tool, not an access control solution.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.