Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Which TWO actions align with the Zero Trust principle of 'verify explicitly'? (Select two.)

⚠ Common exam trap

Microsoft often tests the misconception that encryption or network segmentation are forms of verification, but they are actually data protection and containment controls, respectively, and do not satisfy the 'verify explicitly' requirement of Zero Trust.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use conditional access policies to evaluate user and device risk before granting access

Option B is correct because conditional access policies in Microsoft Entra ID evaluate signals such as user risk, sign-in risk, device compliance, and location at the moment of each access request, which is the essence of 'verify explicitly' — authenticating and authorizing based on all available contextual signals rather than a one-time check. Option D is correct because requiring multifactor authentication for all users forces verification of identity through multiple independent credential factors (something you know plus something you have or are), directly implementing the 'verify explicitly' tenet instead of trusting a single password. The unmarked options do not belong: A (VPN for remote access) primarily establishes a secure tunnel and perimeter-style access, which is more aligned with network-based trust than explicit per-request verification; C (encrypting data at rest) supports the 'assume breach' tenet by protecting data confidentiality, not identity verification; and E (network segmentation) limits lateral movement, which also maps to 'assume breach' rather than 'verify explicitly'.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy a VPN for remote access

    Why it's wrong here

    VPNs extend the traditional network perimeter by granting authenticated users broad access to internal resources after a single point-in-time authentication. Zero Trust's 'verify explicitly' requires evaluating user and device risk signals, session context, and compliance status on every access request, not once per tunnel. Because a VPN establishes an implicit trust zone for the duration of the session, it fails to continuously verify identity and security posture, and often grants more access than the user actually needs.

  • ✓

    Use conditional access policies to evaluate user and device risk before granting access

    Why this is correct

    Conditional Access policies in Microsoft Entra ID act on real-time signals such as user risk, device compliance state, sign-in location, and session risk to allow access, block it, or trigger step-up authentication. This is a direct implementation of 'verify explicitly' because every access attempt is evaluated against multiple context-aware criteria before a token is issued or access is granted. The same user can be permitted on a compliant managed device but blocked or challenged when the same request originates from an unmanaged personal device, embodying never-trust-always-verify.

  • ✗

    Encrypt all data at rest

    Why it's wrong here

    Encryption at rest is a foundation of data protection, but it addresses confidentiality if physical media is stolen and does not verify who or what is requesting the data. Zero Trust's verify-explicitly principle focuses on authenticating and authorizing every request based on user identity, device posture, and contextual signals. Static encryption, even with strong key management, never evaluates the risk of the caller, so it cannot be the action that implements identity-centric verification.

  • ✓

    Require multifactor authentication for all users

    Why this is correct

    Requiring multifactor authentication ensures that possession of a password alone is insufficient; users must prove identity with an additional factor such as an authenticator app, biometric, or hardware key. This is a core expression of 'verify explicitly' because the system challenges the user's assertion of identity in real time before any session is established. MFA drastically reduces the impact of stolen or weak passwords and is a baseline control in many Zero Trust architectures, but it should be combined with device and risk signals for complete verification.

  • ✗

    Implement network segmentation to limit lateral movement

    Why it's wrong here

    Network segmentation is a classic 'assume breach' defense that limits lateral movement by isolating workloads and users into separate zones, but it does not verify the identity or posture of the entity requesting access. The Zero Trust pillar 'assume breach' assumes a compromise may already exist and constrains blast radius, whereas 'verify explicitly' demands authentication and authorization of every individual access request. Segmentation is a valuable containment control but is conceptually different from explicit verification; it cannot be credited with verifying the user or device, only with restricting movement after a breach.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.