SC-100 Practice Question: Design solutions that align with security best practices and priorities
Which THREE are components of Microsoft's Zero Trust model?
⚠ Common exam trap
It's easy for candidates to confuse the Zero Trust guiding principles (like 'Assume breach') with the architectural components (identities, endpoints, data, apps, infrastructure, network), leading them to select 'Assume breach' as a component rather than a principle.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data
Microsoft's Zero Trust model is built on three foundational principles—verify explicitly, use least privilege access, and assume breach—and it organizes its architecture around six core components: identities, devices (endpoints), applications, data, infrastructure, and networks. Option A (Data) is correct because data is one of those six pillars, protected through classification, labeling, and encryption so that access is granted based on sensitivity and policy. Option D (Identities) is correct because identities are the primary control plane in Zero Trust, verified with strong authentication (such as MFA and conditional access) before any resource is reached. Option E (Endpoints) is correct because devices/endpoints are a core component, validated for health and compliance before being trusted to access corporate resources. Option B (Assume breach) is not a component but one of the three guiding principles of Zero Trust, and Option C (Microsoft Defender for Cloud) is a specific product/CNAPP offering rather than a structural component of the model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data
Why this is correct
Data is the ultimate security target and is protected at rest, in transit, and in use through classification, encryption, and rights management. Zero Trust enforces granular access policies based on data sensitivity, with DLP and DRM ensuring protection even after access is granted. Without data protection, all other components become moot, making data one of the central pillars of the model.
- ✗
Assume breach
Why it's wrong here
Assume breach is one of the three guiding principles of Zero Trust, but it is not a component, pillar, or control. It represents a mindset that presumes compromise and mandates continuous verification, microsegmentation, and encrypted traffic to reduce blast radius. While it shapes architecture, it does not correspond to a specific asset that must be protected like identities, devices, or data.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud is a CSPM and workload protection tool that helps operationalize Zero Trust, but it is not a defined component of the model. The Zero Trust components are the protection planes such as identities, endpoints, data, networks, applications, and infrastructure. Confusing tools with components leads to implementation gaps; Defender for Cloud is an enabler, not a pillar.
- ✓
Identities
Why this is correct
Identities form the primary security boundary, covering users, services, and workload identities, and are verified explicitly with strong authentication and conditional access. Least privilege is enforced through just-in-time and just-enough access, limiting what an identity can do after authentication. Since attackers target identities to gain initial foothold, this component is central to Zero Trust architecture.
- ✓
Endpoints
Why this is correct
Endpoints represent every device that requests access to resources, including desktops, mobile devices, and IoT sensors. Zero Trust requires continuous health and compliance checks on endpoints, treating any unmanaged or compromised device as hostile. These devices are a distinct pillar, separate from identities, because they add device state as a condition for granting access.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.