Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Your organization is implementing a Zero Trust network architecture in Azure. Which TWO principles are foundational to Zero Trust?

⚠ Common exam trap

It's easy for candidates to confuse network segmentation (a tactical control) with the strategic Zero Trust principle of 'Assume breach', or mistakenly think 'Trust but verify' is acceptable when the exam requires the explicit 'Verify explicitly' and 'Assume breach' as the two foundational pillars.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify explicitly

Option B, 'Verify explicitly,' is correct because Zero Trust requires that every access request be authenticated and authorized based on all available data points—user identity, device health, location, and workload—rather than granting implicit trust based on network location. Option C, 'Assume breach,' is correct because Zero Trust operates on the assumption that the environment is already compromised, so organizations must minimize blast radius through micro-segmentation, end-to-end encryption, and continuous monitoring to detect and respond to threats. These two principles, along with 'Use least privilege access,' form the three core Zero Trust principles as defined by Microsoft and NIST SP 800-207. Option A, 'Use network segmentation,' is a technique or implementation control that supports Zero Trust rather than a foundational principle itself. Option D, 'Rely on perimeter security,' contradicts Zero Trust, which explicitly rejects the castle-and-moat model of trusting everything inside the corporate firewall. Option E, 'Trust but verify,' is a traditional security adage that still implies initial trust, which is incompatible with Zero Trust's requirement to never trust implicitly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use network segmentation

    Why it's wrong here

    Network segmentation is an important implementation tactic within zero trust, but it is not a foundational principle. Segmentation reduces lateral movement but still assumes that all traffic within a segment can be trusted, which violates the zero trust model. Zero trust requires dynamic, identity-and-attribute-based microsegmentation with continuous per-request verification, not just static network zones.

  • ✓

    Verify explicitly

    Why this is correct

    Verifying explicitly is the core zero trust principle: every access request is authenticated and authorized based on all available data points, including user identity, device posture, location, data classification, and anomaly signals. This eliminates implicit trust and ensures that access decisions are made for each session and each request, even for previously authenticated entities. It is the primary principle that distinguishes zero trust from traditional perimeter models.

  • ✓

    Assume breach

    Why this is correct

    Assume breach means designing security controls under the premise that attackers have already compromised your environment. This mindset drives strategies such as least-privilege access, network microsegmentation, and continuous monitoring to limit the blast radius of an intrusion. It forces proactive threat hunting and rapid incident response, because the network cannot be relied upon as a trustworthy boundary.

  • ✗

    Rely on perimeter security

    Why it's wrong here

    Relying on perimeter security is invalid in zero trust because the perimeter no longer exists with cloud workloads, remote users, and personal devices. Zero trust treats every network, including the corporate LAN, as hostile and requires per-request verification of any resource regardless of its physical location. The perimeter-based approach provides no protection from insider threats or already-compromised external connections.

  • ✗

    Trust but verify

    Why it's wrong here

    The phrase 'trust but verify' implies that an entity is initially trusted and then occasionally checked, which conflicts with zero trust's principle of never trusting without explicit verification. In zero trust, the default state is no trust, and every access attempt is verified against all available signals before access is granted. Even authenticated users and devices are continuously evaluated for risk, so there is no baseline trust for an attacker to exploit.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.