SC-100 Practice Question: Design solutions that align with security best practices and priorities
Which TWO of the following are key components of a Zero Trust architecture according to Microsoft? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse 'trust but verify' (a legacy model) with Zero Trust's 'never trust, always verify' principle, leading them to incorrectly select Option A as a key component.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use least privilege access
Option D, 'Verify explicitly,' is correct because Microsoft's Zero Trust model requires that every access request be authenticated and authorized based on all available data points, including user identity, device health, location, and data sensitivity, rather than assuming trust based on network location. Option C, 'Use least privilege access,' is correct because Zero Trust limits user access with just-in-time and just-enough-access (JIT/JEA) principles, risk-based adaptive policies, and data protection to minimize lateral movement and exposure. The three guiding principles Microsoft defines are verify explicitly, use least privilege access, and assume breach, so these two options align directly with that framework. Option A, 'Trust but verify,' is not a Zero Trust principle; it reflects a traditional perimeter mindset where trust is initially granted. Option B, 'Implicit trust for internal traffic,' contradicts Zero Trust, which removes implicit trust based on network location. Option E, 'Rely on a strong perimeter,' is also contrary to Zero Trust, which assumes the perimeter can be breached and therefore does not rely on it for security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trust but verify
Why it's wrong here
The phrase 'trust but verify' is often cited as a security model, but Zero Trust rejects the notion that any entity can be initially trusted. In practice, trust but verify still grants an implicit level of trust based on network location or prior authentication, which can be exploited through lateral movement. Zero Trust mandates that no subject is trusted a priori; every request for a resource goes through continuous identity validation, device attestation, and policy evaluation. Therefore, trust but verify is not a key component; it is a legacy fallback that retains a window of implicit trust.
- ✗
Implicit trust for internal traffic
Why it's wrong here
Assuming internal traffic is implicitly trusted is a fundamental flaw because it treats the network perimeter as an unbreakable boundary. Even if a user or device resides on the corporate LAN, an attacker who has compromised one node can move laterally to other systems without re-authentication. Zero Trust flattens the network and requires the same level of verification for internal and external access requests. By eliminating implicit trust inside the network, the blast radius is contained and each interaction is challenged.
- ✓
Use least privilege access
Why this is correct
Least privilege access is a cornerstone of Zero Trust because it directly reduces the potential blast radius of any compromised identity or device. Access is granted strictly on a need-to-know basis, often enforced with just-in-time (JIT) elevation and just-enough-access (JEA) scoping. This applies not only to human users but also to workloads, services, and APIs via fine-grained conditional access policies and microsegmentation. Implementing least privilege ensures that a single credential theft does not automatically grant access to downstream systems.
- ✓
Verify explicitly
Why this is correct
Explicit verification is the core decision-making principle where every single access request is authenticated and authorized using all available signals—user identity, device compliance, location, risk score, and data sensitivity. Zero Trust never allows access based on static rules alone; instead, each session can enforce step-up authentication if the context changes. It requires that access tokens be short-lived and that sessions be continuously revalidated. This stands in contrast to legacy approaches that authenticate once and extend trust for the full connection.
- ✗
Rely on a strong perimeter
Why it's wrong here
Relying on a strong perimeter assumes that the network boundary is the only line of defense, and once inside, trust is maintained. In modern hybrid and multi-cloud environments, there is no single physical perimeter: users access resources from anywhere, and resources live on-premises, in the cloud, and at the edge. Zero Trust operates under the assumption that the perimeter has already been breached, and it applies identity-based policies directly to individual resources and data. Thus, relying on a strong perimeter is not a component of Zero Trust; it is the legacy model Zero Trust seeks to replace.
Go deeper
Related to this question
Learn chapter
Governance, Risk, and Compliance Strategy Design
Key term
Microsoft 365 Security Design
Microsoft 365 Security Design is the process of planning and configuring built-in security features in Microsoft 365 to protect data, identities, and devices from cyber threats.
Key term
Zero Trust Strategy
A security model that requires continuous verification of every user, device, and connection before granting access to any resource, regardless of where the request originates.
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.