Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A company wants to implement a Zero Trust security model. Which TWO of the following are core principles of Zero Trust?

⚠ Common exam trap

SC-900 often tests the distinction between traditional perimeter security assumptions (trust by location, implicit trust) and the three Zero Trust principles, tricking candidates who confuse 'trust but verify' with 'verify explicitly'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify explicitly

Option B (Verify explicitly) is correct because Zero Trust requires every access request to be authenticated and authorized based on all available data points—user identity, device health, location, and workload—rather than assuming trust from network position. Option E (Least privilege access) is correct because Zero Trust limits user and workload access to only what is needed for the task, typically enforced through just-in-time and just-enough-access policies and micro-segmentation. Option A (Trust based on network location) is wrong because Zero Trust explicitly rejects the idea that being inside a corporate network grants trust. Option C (Perimeter-based security) is wrong because Zero Trust moves away from a castle-and-moat perimeter model toward identity-centric controls. Option D (Implicit trust for internal users) is wrong because Zero Trust assumes breach and requires continuous verification, never granting implicit trust to internal users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Trust based on network location

    Why it's wrong here

    Zero Trust verifies every request explicitly using identity, device health and context signals regardless of where it originates, so network location never confers trust. It is tempting because internal subnets were historically treated as trusted zones, which is precisely the assumption Zero Trust replaces with per-session verification.

  • ✓

    Verify explicitly

    Why this is correct

    Verify explicitly is a core Zero Trust principle: every access request is authenticated and authorised using all available signals — identity, device, location and risk — before granting access. This satisfies the model's requirement to never trust implicitly based on network location alone.

  • ✗

    Perimeter-based security

    Why it's wrong here

    Perimeter-based security trusts everything inside a network boundary, which contradicts Zero Trust's verify-explicitly and assume-breach principles. It is tempting because firewalls and VPNs remain useful controls, but Zero Trust instead requires identity-based, per-request verification regardless of network location.

  • ✗

    Implicit trust for internal users

    Why it's wrong here

    Zero Trust grants least privilege per request after verification, so internal users receive no implicit trust from being inside the corporate network. It is tempting because domain membership once implied broad access, yet Microsoft Entra ID now requires explicit authentication and authorisation for every resource.

  • ✓

    Least privilege access

    Why this is correct

    Least privilege access is a core Zero Trust principle: it limits each identity to only the permissions required for its task, reducing blast radius if credentials are compromised. This directly satisfies the model's assume-breach stance by constraining lateral movement across resources.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your company is implementing a zero-trust security model. Which principle requires verifying every access request as though it originates from an untrusted network, even if the request comes from within the corporate network?

medium
  • A.Least privilege
  • B.Trust but verify
  • ✓ C.Explicit verification
  • D.Assume breach

Why C: Explicit verification is one of the three core Zero Trust principles (alongside least privilege and assume breach) and specifically requires authenticating and authorizing every access request based on all available data points — identity, location, device health, service, and workload — regardless of whether the request originates inside or outside the corporate network. It rejects the traditional 'trusted internal network' assumption.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.