Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A financial services company is adopting a Zero Trust security model. The security team must implement controls that align with the principle of least privilege. Which two practices should they implement? (Choose two.)

⚠ Common exam trap

The trap here is assuming that least privilege means giving everyone admin rights for convenience or disabling security controls to improve usability, when it actually requires minimizing access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign users the minimum permissions required to perform their job duties.

Least privilege requires that users have only the minimum access necessary to perform their tasks. Assigning minimum permissions and using just-in-time access for privileged roles both enforce this principle. The other options either grant excessive access or weaken authentication, which are contrary to Zero Trust and least privilege. These two practices help limit the blast radius of a potential compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable multifactor authentication to streamline the user experience.

    Why it's wrong here

    Disabling multifactor authentication weakens security and contradicts Zero Trust, which requires explicit verification of every access request. MFA is a critical control for verifying identity. Least privilege focuses on minimizing permissions, but it does not mean reducing authentication strength. This practice would increase risk and is not aligned with the principle.

  • ✗

    Grant all employees permanent administrator rights to simplify IT support.

    Why it's wrong here

    Granting permanent administrator rights violates least privilege because it provides excessive access beyond what is needed for job functions. Least privilege requires users to have only the minimum permissions necessary. This practice increases the attack surface and risk of insider threats. It is the opposite of what the company should do when adopting Zero Trust and least privilege principles.

  • ✗

    Allow all users to access all company data to foster collaboration.

    Why it's wrong here

    Allowing all users to access all data violates least privilege and Zero Trust principles. Least privilege restricts access based on job requirements. Unrestricted access increases the risk of data breaches and non-compliance. This practice should be avoided; instead, access should be granted on a need-to-know basis with proper authorization controls.

  • ✓

    Assign users the minimum permissions required to perform their job duties.

    Why this is correct

    Assigning minimum permissions is a core implementation of least privilege. It ensures users can only access resources essential for their roles, reducing the potential impact of compromised accounts. In a Zero Trust model, this limits lateral movement and enforces strict access control. This practice directly supports the principle of least privilege and is a recommended security control.

  • ✓

    Use just-in-time (JIT) access for privileged roles, granting permissions only when needed.

    Why this is correct

    Just-in-time access elevates privileges only for a limited time and specific tasks, aligning with least privilege by avoiding standing access. In Microsoft Entra ID, Privileged Identity Management (PIM) enables JIT activation of roles. This reduces the window of exposure for privileged accounts. It is a key practice for implementing least privilege in a Zero Trust architecture.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.