SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company wants to implement a Zero Trust security model. Which TWO of the following are core principles of Zero Trust?
⚠ Common exam trap
SC-900 often tests the distinction between traditional perimeter security assumptions (trust by location, implicit trust) and the three Zero Trust principles, tricking candidates who confuse 'trust but verify' with 'verify explicitly'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify explicitly
Option B (Verify explicitly) is correct because Zero Trust requires every access request to be authenticated and authorized based on all available data points—user identity, device health, location, and workload—rather than assuming trust from network position. Option E (Least privilege access) is correct because Zero Trust limits user and workload access to only what is needed for the task, typically enforced through just-in-time and just-enough-access policies and micro-segmentation. Option A (Trust based on network location) is wrong because Zero Trust explicitly rejects the idea that being inside a corporate network grants trust. Option C (Perimeter-based security) is wrong because Zero Trust moves away from a castle-and-moat perimeter model toward identity-centric controls. Option D (Implicit trust for internal users) is wrong because Zero Trust assumes breach and requires continuous verification, never granting implicit trust to internal users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trust based on network location
Why it's wrong here
Zero Trust verifies every request explicitly using identity, device health and context signals regardless of where it originates, so network location never confers trust. It is tempting because internal subnets were historically treated as trusted zones, which is precisely the assumption Zero Trust replaces with per-session verification.
- ✓
Verify explicitly
Why this is correct
Verify explicitly is a core Zero Trust principle: every access request is authenticated and authorised using all available signals — identity, device, location and risk — before granting access. This satisfies the model's requirement to never trust implicitly based on network location alone.
- ✗
Perimeter-based security
Why it's wrong here
Perimeter-based security trusts everything inside a network boundary, which contradicts Zero Trust's verify-explicitly and assume-breach principles. It is tempting because firewalls and VPNs remain useful controls, but Zero Trust instead requires identity-based, per-request verification regardless of network location.
- ✗
Implicit trust for internal users
Why it's wrong here
Zero Trust grants least privilege per request after verification, so internal users receive no implicit trust from being inside the corporate network. It is tempting because domain membership once implied broad access, yet Microsoft Entra ID now requires explicit authentication and authorisation for every resource.
- ✓
Least privilege access
Why this is correct
Least privilege access is a core Zero Trust principle: it limits each identity to only the permissions required for its task, reducing blast radius if credentials are compromised. This directly satisfies the model's assume-breach stance by constraining lateral movement across resources.
Go deeper
Related to this question
Learn chapter
Zero Trust Architecture Principles
Key term
Zero Trust Architecture
Zero Trust Architecture is a cybersecurity model that requires every user and device to be continuously verified before accessing any resource, regardless of where they are located.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your company is implementing a zero-trust security model. Which principle requires verifying every access request as though it originates from an untrusted network, even if the request comes from within the corporate network?
medium- A.Least privilege
- B.Trust but verify
- ✓ C.Explicit verification
- D.Assume breach
Why C: Explicit verification is one of the three core Zero Trust principles (alongside least privilege and assume breach) and specifically requires authenticating and authorizing every access request based on all available data points — identity, location, device health, service, and workload — regardless of whether the request originates inside or outside the corporate network. It rejects the traditional 'trusted internal network' assumption.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.