SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Entra ID and needs to implement a Zero Trust identity strategy. Which THREE principles should you apply?
⚠ Common exam trap
Many candidates confuse 'Trust implicitly' with the legacy perimeter-based security model and select it as a valid principle, or mistakenly think a single authentication method simplifies management, but Zero Trust explicitly rejects both for continuous verification and defense-in-depth.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use least privilege access
The Zero Trust identity model in Microsoft Entra ID is built on three core principles, and option B (Verify explicitly) is correct because every access request must be authenticated and authorized based on all available signals—user identity, device health, location, and risk—rather than trusting based on network location. Option A (Use least privilege access) is correct because Zero Trust requires granting just-enough, just-in-time access using tools like Privileged Identity Management (PIM) and conditional access so users only get the permissions needed for the task. Option E (Assume breach) is correct because Zero Trust assumes the network is already compromised and therefore uses micro-segmentation, end-to-end encryption, and analytics to minimize blast radius and detect threats. Option C (Trust implicitly) is incorrect because it is the opposite of Zero Trust—implicit trust based on being inside the corporate network is exactly what Zero Trust eliminates. Option D (Use a single authentication method) is incorrect because Zero Trust favors strong, phishing-resistant multi-factor authentication (such as FIDO2 or Windows Hello for Business) rather than relying on a single authentication factor.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use least privilege access
Why this is correct
In Microsoft Entra ID, least privilege means assigning identities only the permissions required for their specific job, using built-in roles like Global Reader or custom roles instead of broad Global Administrator. Privileged Identity Management (PIM) provides time-bound, just-in-time role activation, further reducing standing access and the attack surface. This principle directly limits the blast radius if an account is compromised, making it a correct answer for Zero Trust.
- ✓
Verify explicitly
Why this is correct
Zero Trust's 'verify explicitly' pillar requires that every access request be authenticated and authorized based on multiple dynamic signals, not just a static password claim. In Entra ID, this is operationalized through Conditional Access policies that enforce MFA, device compliance, sign-in risk, or location and by using Microsoft's risk assessments. Even a previously validated session must be re-evaluated, which is why Entra ID issued tokens are continually checked at access and with Continuous Access Evaluation.
- ✗
Trust implicitly
Why it's wrong here
Trusting implicitly is the opposite of Zero Trust because it assumes that a user, device, or network connection is safe based solely on a previous authentication or an internal network location. In modern identity attacks, such implicit trust enables lateral movement once a credential is phished, since attackers inherit the original session's privileges. Zero Trust explicitly rejects this model, requiring verification for each request rather than assuming an initial logon is sufficient.
- ✗
Use a single authentication method
Why it's wrong here
Relying on a single authentication method, such as a password alone, leaves identities vulnerable to phishing, password spraying, and replay attacks. Zero Trust encourages multiple layers of authentication, specifically MFA that combines two or more factors, and in Entra ID you can require phishing-resistant methods like FIDO2 or Windows Hello for Business. Using just one method means a single stolen factor grants instant access, violating the 'verify explicitly' and 'least privilege' principles.
- ✓
Assume breach
Why this is correct
Assume breach means designing security so that if an attacker has already gained a foothold, you can minimize damage by segmenting access, encrypting data, and continuously validating all sessions. In Entra ID, this aligns with Continuous Access Evaluation (CAE) and Identity Protection, which detect compromised token use and force token revocation in near real-time. This prevents attacker movement by revoking access when user risk or device risk changes, rather than waiting for a scheduled token expiration.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.