SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company uses a cloud-based email service. The service provider ensures that the physical data centers are secure and that the email platform is patched and available. The company is responsible for managing user accounts and ensuring that employees use strong passwords. This division of responsibilities is an example of which concept?
⚠ Common exam trap
It's easy for candidates to confuse the shared responsibility model with defense in depth because both involve multiple security layers, but the question specifically tests the contractual and operational division of security tasks between cloud provider and customer, not the stacking of controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shared responsibility model
The scenario describes a clear division of security responsibilities between the cloud service provider (securing physical data centers, patching the platform) and the customer (managing user accounts, enforcing strong passwords). This is the core definition of the shared responsibility model, which is a foundational concept in cloud computing (as defined by NIST SP 800-145 and adopted by major providers like Microsoft 365). The model explicitly delineates that the provider is responsible for 'security of the cloud' (physical hosts, network, hypervisor) while the customer is responsible for 'security in the cloud' (user identities, data, client endpoints).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Defense in depth
Why it's wrong here
Defense in depth is a comprehensive security strategy that layers multiple, independent security controls to protect assets and data. This approach assumes that no single security measure is foolproof, so it establishes redundancy across administrative, technical, and physical safeguards. While crucial for robust security, it describes *how* security is implemented, not *who* is responsible for specific components in a cloud service agreement.
- ✓
Shared responsibility model
Why this is correct
The Shared Responsibility Model is a fundamental framework in cloud computing that explicitly delineates security obligations between the cloud service provider (CSP) and the customer. The CSP is responsible for the security *of* the cloud, encompassing the underlying infrastructure, physical facilities, and host operating systems. Conversely, the customer is accountable for security *in* the cloud, which includes their data, applications, network configurations, and identity and access management. This model ensures clarity on who manages what aspects of security, varying based on the service model adopted.
- ✗
Zero Trust
Why it's wrong here
Zero Trust is a modern security paradigm that operates on the principle of 'never trust, always verify,' regardless of whether the access request originates inside or outside the network perimeter. It mandates explicit verification for every user and device attempting to access resources, enforcing least privilege access and assuming breach at all times. This model dictates an approach to access control and network segmentation within an environment, rather than defining the division of security duties between a cloud provider and its customer.
- ✗
Principle of least privilege
Why it's wrong here
The Principle of Least Privilege is an essential security concept that dictates users, processes, or applications should only be granted the minimum necessary permissions to perform their specific, authorized tasks. This practice significantly reduces the potential attack surface and limits the scope of damage if an account or system is compromised. While critical for securing resources within a cloud environment, it is an access control policy applied by the customer or provider, not a model for allocating security responsibilities between them.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.