SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A security architect is designing a defense strategy for the organization's network. The architect assumes that an attacker may already have breached the perimeter and is operating inside the network. Therefore, the design does not automatically trust any user or device, even if they are inside the corporate network, and requires continuous verification for every access request. Which security principle does this approach best represent?
⚠ Common exam trap
Watch out — candidates often confuse Zero Trust with defense in depth because both involve multiple security layers, but Zero Trust specifically requires continuous verification and assumes breach, whereas defense in depth does not mandate per-request trust evaluation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Zero Trust
The Zero Trust security principle is based on the assumption that an attacker may already be inside the network, so no user or device is automatically trusted, regardless of location. This model requires continuous verification for every access request, enforcing strict identity verification and least-privilege access controls at each step. The scenario directly describes the core tenet of Zero Trust: 'never trust, always verify.'
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Defense in depth
Why it's wrong here
Defense in depth is a security strategy that employs multiple, overlapping security controls to protect assets, creating layers of defense. While highly effective in slowing down attackers and providing redundancy, it does not inherently mandate the continuous verification of every access request from a position of zero implicit trust. Its focus is on layering diverse controls, such as firewalls, intrusion detection, and endpoint protection, rather than the fundamental principle of 'never trust, always verify' for every interaction.
When this WOULD be correct
A question asking: 'Which security strategy involves implementing multiple layers of security controls (e.g., firewalls, antivirus, IDS) to protect against threats?' would make Defense in depth the correct answer.
- ✓
Zero Trust
Why this is correct
Zero Trust is the foundational security model that mandates explicit verification for every access request, regardless of its origin or the resource being accessed. It operates on the principle of 'never trust, always verify,' assuming that a breach is inevitable or has already occurred. This strategy requires continuous validation of identity, device health, and service context before granting and maintaining access, making it ideal for designing a robust defense against both external and internal threats.
- ✗
Shared responsibility
Why it's wrong here
The Shared Responsibility model delineates the specific security obligations between a cloud service provider and its customer. While crucial for understanding accountability in cloud deployments, it primarily defines who is responsible for what aspects of security, such as physical infrastructure versus customer data. It does not, however, prescribe the methodology or strategy for how access requests should be continuously verified or how to operate under an 'assume breach' mindset within an organization's defense architecture.
When this WOULD be correct
In a question asking: 'A company uses a cloud provider for IaaS. Who is responsible for securing the operating system and applications?' Shared responsibility would be correct because it delineates provider vs. customer security duties.
- ✗
Least privilege
Why it's wrong here
The principle of least privilege dictates that users, applications, and systems should be granted only the minimum necessary permissions to perform their required tasks. This is a critical component of any robust security posture, reducing the potential blast radius of a compromise. However, it is a granular access control principle, not an overarching security model that addresses continuous verification of identity and device health or assumes a breach for every access attempt, which are core tenets of a comprehensive defense strategy.
When this WOULD be correct
A question that asks: 'A security architect wants to ensure that users and applications have only the minimum permissions necessary to perform their tasks, reducing the risk of excessive access. Which principle does this represent?' In that context, least privilege would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Zero TrustCorrect answer▾
Why this is correct
Zero Trust is the foundational security model that mandates explicit verification for every access request, regardless of its origin or the resource being accessed. It operates on the principle of 'never trust, always verify,' assuming that a breach is inevitable or has already occurred. This strategy requires continuous validation of identity, device health, and service context before granting and maintaining access, making it ideal for designing a robust defense against both external and internal threats.
✗Defense in depthWrong answer — click to see why▾
Why this is wrong here
Defense in depth uses multiple layers of security controls, but it does not inherently assume a breach or require continuous verification of every access request; it focuses on layered defenses rather than the 'never trust, always verify' principle.
★ When this WOULD be the correct answer
A question asking: 'Which security strategy involves implementing multiple layers of security controls (e.g., firewalls, antivirus, IDS) to protect against threats?' would make Defense in depth the correct answer.
Why candidates choose this
Candidates may confuse Zero Trust's continuous verification with the layered approach of Defense in depth, as both involve multiple security measures, but they differ in core assumptions about trust.
✗Shared responsibilityWrong answer — click to see why▾
Why this is wrong here
Shared responsibility is a cloud security model that defines security obligations between provider and customer, not a principle for continuous verification and distrust of internal network traffic.
★ When this WOULD be the correct answer
In a question asking: 'A company uses a cloud provider for IaaS. Who is responsible for securing the operating system and applications?' Shared responsibility would be correct because it delineates provider vs. customer security duties.
Why candidates choose this
Candidates may confuse 'shared responsibility' with a security strategy that involves multiple layers or parties, but it specifically refers to division of security tasks in cloud environments, not network trust assumptions.
✗Least privilegeWrong answer — click to see why▾
Why this is wrong here
The question describes a model where no user or device is trusted by default, even inside the network, and every access request is continuously verified. This is the core definition of Zero Trust, not least privilege. Least privilege focuses on granting only the minimum permissions needed, not on continuous verification or assuming breach.
★ When this WOULD be the correct answer
A question that asks: 'A security architect wants to ensure that users and applications have only the minimum permissions necessary to perform their tasks, reducing the risk of excessive access. Which principle does this represent?' In that context, least privilege would be the correct answer.
Why candidates choose this
Candidates may confuse least privilege with Zero Trust because both involve limiting access. However, least privilege is about permission levels, while Zero Trust is about continuous verification and assuming breach. The phrase 'does not automatically trust' might be misassociated with limiting permissions rather than verifying every request.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.