Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Entra ID and needs to implement a Zero Trust identity strategy. Which THREE principles should you apply?

⚠ Common exam trap

Many candidates confuse 'Trust implicitly' with the legacy perimeter-based security model and select it as a valid principle, or mistakenly think a single authentication method simplifies management, but Zero Trust explicitly rejects both for continuous verification and defense-in-depth.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use least privilege access

The Zero Trust identity model in Microsoft Entra ID is built on three core principles, and option B (Verify explicitly) is correct because every access request must be authenticated and authorized based on all available signals—user identity, device health, location, and risk—rather than trusting based on network location. Option A (Use least privilege access) is correct because Zero Trust requires granting just-enough, just-in-time access using tools like Privileged Identity Management (PIM) and conditional access so users only get the permissions needed for the task. Option E (Assume breach) is correct because Zero Trust assumes the network is already compromised and therefore uses micro-segmentation, end-to-end encryption, and analytics to minimize blast radius and detect threats. Option C (Trust implicitly) is incorrect because it is the opposite of Zero Trust—implicit trust based on being inside the corporate network is exactly what Zero Trust eliminates. Option D (Use a single authentication method) is incorrect because Zero Trust favors strong, phishing-resistant multi-factor authentication (such as FIDO2 or Windows Hello for Business) rather than relying on a single authentication factor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use least privilege access

    Why this is correct

    In Microsoft Entra ID, least privilege means assigning identities only the permissions required for their specific job, using built-in roles like Global Reader or custom roles instead of broad Global Administrator. Privileged Identity Management (PIM) provides time-bound, just-in-time role activation, further reducing standing access and the attack surface. This principle directly limits the blast radius if an account is compromised, making it a correct answer for Zero Trust.

  • ✓

    Verify explicitly

    Why this is correct

    Zero Trust's 'verify explicitly' pillar requires that every access request be authenticated and authorized based on multiple dynamic signals, not just a static password claim. In Entra ID, this is operationalized through Conditional Access policies that enforce MFA, device compliance, sign-in risk, or location and by using Microsoft's risk assessments. Even a previously validated session must be re-evaluated, which is why Entra ID issued tokens are continually checked at access and with Continuous Access Evaluation.

  • ✗

    Trust implicitly

    Why it's wrong here

    Trusting implicitly is the opposite of Zero Trust because it assumes that a user, device, or network connection is safe based solely on a previous authentication or an internal network location. In modern identity attacks, such implicit trust enables lateral movement once a credential is phished, since attackers inherit the original session's privileges. Zero Trust explicitly rejects this model, requiring verification for each request rather than assuming an initial logon is sufficient.

  • ✗

    Use a single authentication method

    Why it's wrong here

    Relying on a single authentication method, such as a password alone, leaves identities vulnerable to phishing, password spraying, and replay attacks. Zero Trust encourages multiple layers of authentication, specifically MFA that combines two or more factors, and in Entra ID you can require phishing-resistant methods like FIDO2 or Windows Hello for Business. Using just one method means a single stolen factor grants instant access, violating the 'verify explicitly' and 'least privilege' principles.

  • ✓

    Assume breach

    Why this is correct

    Assume breach means designing security so that if an attacker has already gained a foothold, you can minimize damage by segmenting access, encrypting data, and continuously validating all sessions. In Entra ID, this aligns with Continuous Access Evaluation (CAE) and Identity Protection, which detect compromised token use and force token revocation in near real-time. This prevents attacker movement by revoking access when user risk or device risk changes, rather than waiting for a scheduled token expiration.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.