Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A security architect is designing a defense strategy for the organization's network. The architect assumes that an attacker may already have breached the perimeter and is operating inside the network. Therefore, the design does not automatically trust any user or device, even if they are inside the corporate network, and requires continuous verification for every access request. Which security principle does this approach best represent?

⚠ Common exam trap

Watch out — candidates often confuse Zero Trust with defense in depth because both involve multiple security layers, but Zero Trust specifically requires continuous verification and assumes breach, whereas defense in depth does not mandate per-request trust evaluation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Zero Trust

The Zero Trust security principle is based on the assumption that an attacker may already be inside the network, so no user or device is automatically trusted, regardless of location. This model requires continuous verification for every access request, enforcing strict identity verification and least-privilege access controls at each step. The scenario directly describes the core tenet of Zero Trust: 'never trust, always verify.'

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Defense in depth

    Why it's wrong here

    Defense in depth is a security strategy that employs multiple, overlapping security controls to protect assets, creating layers of defense. While highly effective in slowing down attackers and providing redundancy, it does not inherently mandate the continuous verification of every access request from a position of zero implicit trust. Its focus is on layering diverse controls, such as firewalls, intrusion detection, and endpoint protection, rather than the fundamental principle of 'never trust, always verify' for every interaction.

    When this WOULD be correct

    A question asking: 'Which security strategy involves implementing multiple layers of security controls (e.g., firewalls, antivirus, IDS) to protect against threats?' would make Defense in depth the correct answer.

  • Zero Trust

    Why this is correct

    Zero Trust is the foundational security model that mandates explicit verification for every access request, regardless of its origin or the resource being accessed. It operates on the principle of 'never trust, always verify,' assuming that a breach is inevitable or has already occurred. This strategy requires continuous validation of identity, device health, and service context before granting and maintaining access, making it ideal for designing a robust defense against both external and internal threats.

  • Shared responsibility

    Why it's wrong here

    The Shared Responsibility model delineates the specific security obligations between a cloud service provider and its customer. While crucial for understanding accountability in cloud deployments, it primarily defines who is responsible for what aspects of security, such as physical infrastructure versus customer data. It does not, however, prescribe the methodology or strategy for how access requests should be continuously verified or how to operate under an 'assume breach' mindset within an organization's defense architecture.

    When this WOULD be correct

    In a question asking: 'A company uses a cloud provider for IaaS. Who is responsible for securing the operating system and applications?' Shared responsibility would be correct because it delineates provider vs. customer security duties.

  • Least privilege

    Why it's wrong here

    The principle of least privilege dictates that users, applications, and systems should be granted only the minimum necessary permissions to perform their required tasks. This is a critical component of any robust security posture, reducing the potential blast radius of a compromise. However, it is a granular access control principle, not an overarching security model that addresses continuous verification of identity and device health or assumes a breach for every access attempt, which are core tenets of a comprehensive defense strategy.

    When this WOULD be correct

    A question that asks: 'A security architect wants to ensure that users and applications have only the minimum permissions necessary to perform their tasks, reducing the risk of excessive access. Which principle does this represent?' In that context, least privilege would be the correct answer.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Zero TrustCorrect answer

Why this is correct

Zero Trust is the foundational security model that mandates explicit verification for every access request, regardless of its origin or the resource being accessed. It operates on the principle of 'never trust, always verify,' assuming that a breach is inevitable or has already occurred. This strategy requires continuous validation of identity, device health, and service context before granting and maintaining access, making it ideal for designing a robust defense against both external and internal threats.

Defense in depthWrong answer — click to see why

Why this is wrong here

Defense in depth uses multiple layers of security controls, but it does not inherently assume a breach or require continuous verification of every access request; it focuses on layered defenses rather than the 'never trust, always verify' principle.

★ When this WOULD be the correct answer

A question asking: 'Which security strategy involves implementing multiple layers of security controls (e.g., firewalls, antivirus, IDS) to protect against threats?' would make Defense in depth the correct answer.

Why candidates choose this

Candidates may confuse Zero Trust's continuous verification with the layered approach of Defense in depth, as both involve multiple security measures, but they differ in core assumptions about trust.

Shared responsibilityWrong answer — click to see why

Why this is wrong here

Shared responsibility is a cloud security model that defines security obligations between provider and customer, not a principle for continuous verification and distrust of internal network traffic.

★ When this WOULD be the correct answer

In a question asking: 'A company uses a cloud provider for IaaS. Who is responsible for securing the operating system and applications?' Shared responsibility would be correct because it delineates provider vs. customer security duties.

Why candidates choose this

Candidates may confuse 'shared responsibility' with a security strategy that involves multiple layers or parties, but it specifically refers to division of security tasks in cloud environments, not network trust assumptions.

Least privilegeWrong answer — click to see why

Why this is wrong here

The question describes a model where no user or device is trusted by default, even inside the network, and every access request is continuously verified. This is the core definition of Zero Trust, not least privilege. Least privilege focuses on granting only the minimum permissions needed, not on continuous verification or assuming breach.

★ When this WOULD be the correct answer

A question that asks: 'A security architect wants to ensure that users and applications have only the minimum permissions necessary to perform their tasks, reducing the risk of excessive access. Which principle does this represent?' In that context, least privilege would be the correct answer.

Why candidates choose this

Candidates may confuse least privilege with Zero Trust because both involve limiting access. However, least privilege is about permission levels, while Zero Trust is about continuous verification and assuming breach. The phrase 'does not automatically trust' might be misassociated with limiting permissions rather than verifying every request.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.