SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A financial services company is adopting a Zero Trust security model. The security team must implement controls that align with the principle of least privilege. Which two practices should they implement? (Choose two.)
⚠ Common exam trap
The trap here is assuming that least privilege means giving everyone admin rights for convenience or disabling security controls to improve usability, when it actually requires minimizing access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign users the minimum permissions required to perform their job duties.
Least privilege requires that users have only the minimum access necessary to perform their tasks. Assigning minimum permissions and using just-in-time access for privileged roles both enforce this principle. The other options either grant excessive access or weaken authentication, which are contrary to Zero Trust and least privilege. These two practices help limit the blast radius of a potential compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable multifactor authentication to streamline the user experience.
Why it's wrong here
Disabling multifactor authentication weakens security and contradicts Zero Trust, which requires explicit verification of every access request. MFA is a critical control for verifying identity. Least privilege focuses on minimizing permissions, but it does not mean reducing authentication strength. This practice would increase risk and is not aligned with the principle.
- ✗
Grant all employees permanent administrator rights to simplify IT support.
Why it's wrong here
Granting permanent administrator rights violates least privilege because it provides excessive access beyond what is needed for job functions. Least privilege requires users to have only the minimum permissions necessary. This practice increases the attack surface and risk of insider threats. It is the opposite of what the company should do when adopting Zero Trust and least privilege principles.
- ✗
Allow all users to access all company data to foster collaboration.
Why it's wrong here
Allowing all users to access all data violates least privilege and Zero Trust principles. Least privilege restricts access based on job requirements. Unrestricted access increases the risk of data breaches and non-compliance. This practice should be avoided; instead, access should be granted on a need-to-know basis with proper authorization controls.
- ✓
Assign users the minimum permissions required to perform their job duties.
Why this is correct
Assigning minimum permissions is a core implementation of least privilege. It ensures users can only access resources essential for their roles, reducing the potential impact of compromised accounts. In a Zero Trust model, this limits lateral movement and enforces strict access control. This practice directly supports the principle of least privilege and is a recommended security control.
- ✓
Use just-in-time (JIT) access for privileged roles, granting permissions only when needed.
Why this is correct
Just-in-time access elevates privileges only for a limited time and specific tasks, aligning with least privilege by avoiding standing access. In Microsoft Entra ID, Privileged Identity Management (PIM) enables JIT activation of roles. This reduces the window of exposure for privileged accounts. It is a key practice for implementing least privilege in a Zero Trust architecture.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Entra ID Roles and RBAC
Key term
RADIUS
RADIUS is a network protocol that provides centralized authentication, authorization, and accounting management for users who connect and use a network service.
Key term
Security model
A security model is a formal framework that defines how subjects (users, processes) can access objects (files, resources) based on rules, ensuring confidentiality, integrity, and availability.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.