SC-100 Practice Question: Design solutions that align with security best practices and priorities
Your organization is implementing a Zero Trust network architecture in Azure. Which TWO principles are foundational to Zero Trust?
⚠ Common exam trap
It's easy for candidates to confuse network segmentation (a tactical control) with the strategic Zero Trust principle of 'Assume breach', or mistakenly think 'Trust but verify' is acceptable when the exam requires the explicit 'Verify explicitly' and 'Assume breach' as the two foundational pillars.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify explicitly
Option B, 'Verify explicitly,' is correct because Zero Trust requires that every access request be authenticated and authorized based on all available data points—user identity, device health, location, and workload—rather than granting implicit trust based on network location. Option C, 'Assume breach,' is correct because Zero Trust operates on the assumption that the environment is already compromised, so organizations must minimize blast radius through micro-segmentation, end-to-end encryption, and continuous monitoring to detect and respond to threats. These two principles, along with 'Use least privilege access,' form the three core Zero Trust principles as defined by Microsoft and NIST SP 800-207. Option A, 'Use network segmentation,' is a technique or implementation control that supports Zero Trust rather than a foundational principle itself. Option D, 'Rely on perimeter security,' contradicts Zero Trust, which explicitly rejects the castle-and-moat model of trusting everything inside the corporate firewall. Option E, 'Trust but verify,' is a traditional security adage that still implies initial trust, which is incompatible with Zero Trust's requirement to never trust implicitly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use network segmentation
Why it's wrong here
Network segmentation is an important implementation tactic within zero trust, but it is not a foundational principle. Segmentation reduces lateral movement but still assumes that all traffic within a segment can be trusted, which violates the zero trust model. Zero trust requires dynamic, identity-and-attribute-based microsegmentation with continuous per-request verification, not just static network zones.
- ✓
Verify explicitly
Why this is correct
Verifying explicitly is the core zero trust principle: every access request is authenticated and authorized based on all available data points, including user identity, device posture, location, data classification, and anomaly signals. This eliminates implicit trust and ensures that access decisions are made for each session and each request, even for previously authenticated entities. It is the primary principle that distinguishes zero trust from traditional perimeter models.
- ✓
Assume breach
Why this is correct
Assume breach means designing security controls under the premise that attackers have already compromised your environment. This mindset drives strategies such as least-privilege access, network microsegmentation, and continuous monitoring to limit the blast radius of an intrusion. It forces proactive threat hunting and rapid incident response, because the network cannot be relied upon as a trustworthy boundary.
- ✗
Rely on perimeter security
Why it's wrong here
Relying on perimeter security is invalid in zero trust because the perimeter no longer exists with cloud workloads, remote users, and personal devices. Zero trust treats every network, including the corporate LAN, as hostile and requires per-request verification of any resource regardless of its physical location. The perimeter-based approach provides no protection from insider threats or already-compromised external connections.
- ✗
Trust but verify
Why it's wrong here
The phrase 'trust but verify' implies that an entity is initially trusted and then occasionally checked, which conflicts with zero trust's principle of never trusting without explicit verification. In zero trust, the default state is no trust, and every access attempt is verified against all available signals before access is granted. Even authenticated users and devices are continuously evaluated for risk, so there is no baseline trust for an attacker to exploit.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.