SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company implements a security model where no user or device is automatically trusted, even if they are inside the corporate network. Every access request must be authenticated, authorized, and encrypted before granting access, regardless of the request origin. This model is known as:
⚠ Common exam trap
A common mix-up: candidates confuse Zero Trust with Defense in depth, assuming that multiple layers of security automatically remove implicit trust, but Zero Trust specifically targets the assumption of trust based on network location.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Zero Trust
Zero Trust is a security model that explicitly assumes no implicit trust based on network location. Every access request must be authenticated, authorized, and encrypted, regardless of whether it originates from inside or outside the corporate network. This aligns with the core Zero Trust principle of 'never trust, always verify'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Defense in depth
Why it's wrong here
Defense in depth is a strategy employing multiple, overlapping security controls to create layers of protection, ensuring that if one control fails, others are in place to mitigate the threat. While it enhances overall resilience by combining administrative, technical, and physical safeguards, it does not inherently mandate explicit verification for every single access request or distrust all internal traffic. Its primary goal is to slow down attackers and provide multiple opportunities for detection, rather than establishing a 'never trust, always verify' posture for every interaction.
When this WOULD be correct
A question asking: 'Which security model uses multiple layers of controls (e.g., firewalls, antivirus, IDS) to protect assets?' would make Defense in depth the correct answer, as it emphasizes layered defenses rather than trust verification.
- ✗
Perimeter security
Why it's wrong here
Perimeter security traditionally focuses on building a strong external defense, like a fortress wall, to keep threats out while implicitly trusting everything within its boundaries. This model relies heavily on firewalls and VPNs at the network edge, assuming that once a user or device is inside the perimeter, it is inherently safe and authorized. It fails in scenarios where internal threats or compromised devices can move laterally without further verification, directly contradicting a 'no automatic trust' principle.
When this WOULD be correct
A question that asks: 'A company uses firewalls, IDS/IPS, and VPNs to protect its network boundary from external threats. Which security model does this describe?' Then perimeter security would be correct.
- ✓
Zero Trust
Why this is correct
Zero Trust is the security model that fundamentally assumes no user, device, or application should be automatically trusted, regardless of its location inside or outside the network perimeter. It mandates explicit verification for every access request, ensuring identity and device health are validated before granting access. This model strictly enforces least privilege access and operates under an 'assume breach' mentality, continuously monitoring and re-validating trust throughout a session.
- ✗
Least privilege
Why it's wrong here
Least privilege is a fundamental security principle dictating that users, applications, and systems should be granted only the minimum necessary access rights required to perform their legitimate functions. While crucial for reducing the attack surface and limiting the impact of a breach, it is a component of a broader security strategy, not a complete security model itself. This principle alone does not encompass the continuous authentication, authorization, and encryption of every network request or the micro-segmentation inherent in a comprehensive 'no trust' environment.
When this WOULD be correct
A question that asks: 'Which security principle ensures that users and processes are granted only the minimum access rights needed to perform their job functions?' would have Least privilege as the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Zero TrustCorrect answer▾
Why this is correct
Zero Trust is the security model that fundamentally assumes no user, device, or application should be automatically trusted, regardless of its location inside or outside the network perimeter. It mandates explicit verification for every access request, ensuring identity and device health are validated before granting access. This model strictly enforces least privilege access and operates under an 'assume breach' mentality, continuously monitoring and re-validating trust throughout a session.
✗Defense in depthWrong answer — click to see why▾
Why this is wrong here
Defense in depth is a layered security strategy using multiple controls, but it does not inherently reject automatic trust for internal users or devices. The question specifically describes the core principle of Zero Trust: never trust, always verify.
★ When this WOULD be the correct answer
A question asking: 'Which security model uses multiple layers of controls (e.g., firewalls, antivirus, IDS) to protect assets?' would make Defense in depth the correct answer, as it emphasizes layered defenses rather than trust verification.
Why candidates choose this
Candidates may confuse the layered approach of defense in depth with the 'never trust' concept, assuming multiple layers inherently distrust internal traffic, when in fact traditional defense in depth often trusts the internal network.
✗Perimeter securityWrong answer — click to see why▾
Why this is wrong here
Perimeter security relies on a trusted internal network and a defended boundary, but the question explicitly states that no user or device is automatically trusted even inside the network, which contradicts the perimeter model.
★ When this WOULD be the correct answer
A question that asks: 'A company uses firewalls, IDS/IPS, and VPNs to protect its network boundary from external threats. Which security model does this describe?' Then perimeter security would be correct.
Why candidates choose this
Candidates may confuse perimeter security with Zero Trust because both involve security controls, but they fail to recognize that Zero Trust eliminates implicit trust, whereas perimeter security trusts internal traffic by default.
✗Least privilegeWrong answer — click to see why▾
Why this is wrong here
Least privilege is a principle that restricts users to only the permissions necessary for their tasks, but it does not address the core concept of never trusting any request by default, regardless of origin, which is the defining characteristic of Zero Trust.
★ When this WOULD be the correct answer
A question that asks: 'Which security principle ensures that users and processes are granted only the minimum access rights needed to perform their job functions?' would have Least privilege as the correct answer.
Why candidates choose this
Candidates may confuse least privilege with Zero Trust because both involve limiting access, but they focus on different aspects: least privilege is about permission levels, while Zero Trust is about continuous verification of every request.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.