SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company implements multiple layers of security controls, including firewalls, antivirus software, access controls, and security awareness training. Which security concept does this approach best represent?
⚠ Common exam trap
A common mix-up: candidates confuse the layered approach of defense in depth with the Zero Trust model, but Zero Trust is specifically about eliminating implicit trust and enforcing per-request verification, not just adding multiple security layers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defense in depth
Defense in depth is the correct concept because it involves layering multiple independent security controls—such as firewalls, antivirus, access controls, and training—so that if one layer fails, others continue to protect the asset. This approach reduces the likelihood of a single point of failure and is a foundational strategy in cybersecurity architecture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Zero Trust
Why it's wrong here
Zero Trust is a strategic security model that fundamentally assumes no user, device, or application should be implicitly trusted, regardless of its location inside or outside the network perimeter. Instead, it mandates continuous verification of identity, device health, and service authorization for every access request. While Zero Trust principles often lead to the implementation of strong, layered controls, the model itself describes the *philosophy* of trust and verification, rather than the *act* of deploying multiple, distinct security layers as a primary definition.
- ✓
Defense in depth
Why this is correct
Defense in depth is a cybersecurity strategy that employs multiple, overlapping layers of security controls to protect information and systems. This approach ensures that if one security control fails or is bypassed, another control is in place to prevent or detect an intrusion, thereby increasing the overall resilience of the system. Examples include physical security, network firewalls, endpoint protection, identity and access management, data encryption, and security awareness training, all working in concert to create a robust security posture.
- ✗
Shared responsibility
Why it's wrong here
Shared responsibility is a cloud security model that clearly delineates the security obligations between a cloud service provider (CSP) and its customers. The CSP is typically responsible for the security *of* the cloud (e.g., physical infrastructure, hypervisor), while the customer is responsible for security *in* the cloud (e.g., data, applications, network configuration, identity management). This model defines who performs which security tasks, rather than describing the implementation of multiple, diverse security layers within an organization's environment.
- ✗
Least privilege
Why it's wrong here
Least privilege is an essential security principle that dictates users, applications, and systems should be granted only the minimum necessary access rights and permissions required to perform their legitimate functions. This minimizes the potential damage from a compromised account or system by restricting its scope of action. It is a fundamental access control concept focused on permission granularity, not a comprehensive architectural strategy for deploying multiple, distinct types of security controls across an entire infrastructure.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security awareness
Security awareness is the ongoing practice of educating people within an organization about cybersecurity risks, safe behaviors, and their individual responsibilities to protect information assets.
Key term
Defense in depth
Defense in depth is a cybersecurity strategy that uses multiple layers of security controls to protect information and systems, so if one layer fails, another layer is already in place to stop the attack.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.