Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Which THREE are components of Microsoft's Zero Trust model?

⚠ Common exam trap

It's easy for candidates to confuse the Zero Trust guiding principles (like 'Assume breach') with the architectural components (identities, endpoints, data, apps, infrastructure, network), leading them to select 'Assume breach' as a component rather than a principle.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data

Microsoft's Zero Trust model is built on three foundational principles—verify explicitly, use least privilege access, and assume breach—and it organizes its architecture around six core components: identities, devices (endpoints), applications, data, infrastructure, and networks. Option A (Data) is correct because data is one of those six pillars, protected through classification, labeling, and encryption so that access is granted based on sensitivity and policy. Option D (Identities) is correct because identities are the primary control plane in Zero Trust, verified with strong authentication (such as MFA and conditional access) before any resource is reached. Option E (Endpoints) is correct because devices/endpoints are a core component, validated for health and compliance before being trusted to access corporate resources. Option B (Assume breach) is not a component but one of the three guiding principles of Zero Trust, and Option C (Microsoft Defender for Cloud) is a specific product/CNAPP offering rather than a structural component of the model.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Data

    Why this is correct

    Data is the ultimate security target and is protected at rest, in transit, and in use through classification, encryption, and rights management. Zero Trust enforces granular access policies based on data sensitivity, with DLP and DRM ensuring protection even after access is granted. Without data protection, all other components become moot, making data one of the central pillars of the model.

  • ✗

    Assume breach

    Why it's wrong here

    Assume breach is one of the three guiding principles of Zero Trust, but it is not a component, pillar, or control. It represents a mindset that presumes compromise and mandates continuous verification, microsegmentation, and encrypted traffic to reduce blast radius. While it shapes architecture, it does not correspond to a specific asset that must be protected like identities, devices, or data.

  • ✗

    Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud is a CSPM and workload protection tool that helps operationalize Zero Trust, but it is not a defined component of the model. The Zero Trust components are the protection planes such as identities, endpoints, data, networks, applications, and infrastructure. Confusing tools with components leads to implementation gaps; Defender for Cloud is an enabler, not a pillar.

  • ✓

    Identities

    Why this is correct

    Identities form the primary security boundary, covering users, services, and workload identities, and are verified explicitly with strong authentication and conditional access. Least privilege is enforced through just-in-time and just-enough access, limiting what an identity can do after authentication. Since attackers target identities to gain initial foothold, this component is central to Zero Trust architecture.

  • ✓

    Endpoints

    Why this is correct

    Endpoints represent every device that requests access to resources, including desktops, mobile devices, and IoT sensors. Zero Trust requires continuous health and compliance checks on endpoints, treating any unmanaged or compromised device as hostile. These devices are a distinct pillar, separate from identities, because they add device state as a condition for granting access.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.