Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Which TWO actions should you take to implement a Zero Trust security strategy for identity and access? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse VPN (a perimeter-based network access solution) with Zero Trust network access (ZTNA), mistakenly thinking VPNs are a valid Zero Trust identity action, when in fact they violate the core Zero Trust principle of not trusting any network segment implicitly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require Multi-Factor Authentication for all users.

Option A is correct because requiring Multi-Factor Authentication (MFA) for all users enforces the Zero Trust principle of verifying identity explicitly, ensuring that a compromised password alone cannot grant access. Option C is correct because Conditional Access policies evaluate signals such as user identity, device compliance, and location to make dynamic, context-aware access decisions, which is central to Zero Trust's 'never trust, always verify' model. Options B, D, and E do not belong: VPNs grant broad network-level access once authenticated rather than per-resource verification, strong passwords alone are a single factor vulnerable to credential theft, and shared accounts eliminate individual accountability and violate least-privilege and explicit-verification principles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Require Multi-Factor Authentication for all users.

    Why this is correct

    Multi-factor authentication (MFA) requires users to prove identity with at least two distinct factors—typically a password, a device-bound key, and biometrics—so that a stolen password alone cannot unlock access. In the Zero Trust model, MFA operationalizes 'verify explicitly' by forcing each authentication attempt through a nontrivial identity check. Although MFA alone does not comprise full Zero Trust, it is a mandatory baseline that reduces the impact of credential theft and phishing.

  • ✗

    Use VPN for remote access to the corporate network.

    Why it's wrong here

    A VPN creates an encrypted tunnel that places the remote user onto the corporate network, effectively granting broad inheritance to internal resources once the tunnel is established. This approach embodies classic perimeter trust—access is based primarily on network location rather than on continuous, per-request validation of the user, device, and session risk. Under Zero Trust, a VPN also concentrates vulnerability because any compromised endpoint can move laterally across the entire trusted network segment.

  • ✓

    Implement Conditional Access policies that evaluate user, device, and location.

    Why this is correct

    Conditional Access is a policy engine that evaluates dynamic signals—including user identity, device compliance status, location, and real-time risk—before allowing or restricting access to resources. This directly implements Zero Trust's 'trust nothing, verify everything' principle by making every access decision a live computation instead of a static entitlement. For example, an admin can block a non-compliant device or require step-up authentication when access originates from an anomalous location, which is impossible with a binary network-based trust model.

  • ✗

    Rely on strong passwords only.

    Why it's wrong here

    Even very strong passwords—long, random, rotated frequently—remain a single factor of authentication and are inherently susceptible to phishing, keyloggers, and credential stuffing. A breached but complex password gives an attacker exactly the same access as a trivial one because passwords are just static knowledge, not proof of identity. Zero Trust requires continuous verification that goes beyond shared secrets, such as device attestation and session risk scoring, so passwords alone cannot satisfy the 'always verify' mandate.

  • ✗

    Create shared accounts for temporary workers.

    Why it's wrong here

    Shared accounts for temporary workers remove individual accountability and make it impossible to enforce least privilege, because two people cannot be meaningfully assigned distinct permissions through one identity. They also blind security monitoring—an attacker using the account is indistinguishable from a legitimate temporary employee—so a Zero Trust environment, which relies on per-identity analytics and auditing, cannot function effectively. Each worker must possess a unique identity, even if only for a limited tenure, so that access can be revoked precisely and every action attributed.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.