SC-100 Practice Question: Design solutions that align with security best practices and priorities
A company is implementing a Zero Trust security model. Which principle requires verifying every access request as if it originates from an uncontrolled network?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify explicitly
The 'Assume breach' principle is not about verifying requests. 'Verify explicitly' is the Zero Trust principle that mandates authenticating and authorizing every access request. 'Least privilege' limits access rights. 'Micro-segmentation' is a network isolation technique.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Least privilege
Why it's wrong here
Least privilege is a security principle that restricts users and processes to only the minimum permissions necessary for their responsibilities, thereby reducing the attack surface. However, it does not require re-validation of each request; permissions are typically static and granted in advance. Zero Trust's verify explicitly demands dynamic, per-request authorization that considers real-time signals like device health and anomaly scores, rendering least privilege alone insufficient.
- ✗
Micro-segmentation
Why it's wrong here
Micro-segmentation is a network architecture technique that divides data center or cloud workloads into isolated zones, preventing lateral movement by enforcing granular firewall policies between segments. While it aligns with Zero Trust goals, it is an implementation tactic rather than a core principle; it operates at the network layer and does not authenticate or authorize individual requests. If an attacker reaches a segment using stolen credentials, micro-segmentation alone does not verify that the request is legitimate.
- ✗
Assume breach
Why it's wrong here
Assume breach is a Zero Trust design assumption that an attacker is already inside the environment, prompting continuous monitoring, logging, and blast-radius reduction. It informs security architecture but does not itself validate every access request; instead, it motivates the need for verification. In contrast, verify explicitly is the active mechanism that checks identity, context, and policy adherence on each request, whereas assume breach simply sets the precautionary mindset.
- ✓
Verify explicitly
Why this is correct
Verify explicitly is the foundational Zero Trust principle mandating that every access request is continuously authenticated and authorized based on all available data points, including user identity, device compliance, location, data sensitivity, and behavioral anomalies. No implicit trust is granted, even for requests originating from internal networks or previously trusted endpoints. This principle directly addresses the 'always verify' core by evaluating each request dynamically at the policy enforcement point.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.