Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A security architect is implementing a Zero Trust security model. The architect insists that the network perimeter should not be trusted and that security controls must be applied to all traffic, even within the corporate network. They also emphasize the need for continuous monitoring and detection of threats as if a breach has already occurred. Which Zero Trust principle is the architect primarily applying?

⚠ Common exam trap

Microsoft often tests the distinction between 'Assume breach' and 'Verify explicitly' by describing a scenario that includes both continuous monitoring and strict access controls, leading candidates to confuse the proactive verification requirement with the reactive breach-assumption mindset.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assume breach

The architect's emphasis on not trusting the network perimeter and applying security controls to all traffic, combined with continuous monitoring as if a breach has already occurred, directly aligns with the 'Assume breach' principle of Zero Trust. This principle operates on the mindset that a breach is inevitable or has already happened, thus requiring constant verification and monitoring of all network traffic, even within the corporate network, rather than relying on a trusted internal zone.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Verify explicitly

    Why it's wrong here

    While "Verify explicitly" is a fundamental Zero Trust principle, it primarily dictates that all access requests are authenticated and authorized based on all available data points, including user identity, device health, location, and data classification. It establishes trust dynamically before granting access. However, this principle does not directly encapsulate the proactive mindset of expecting a breach to occur or already be in progress, which is the core tenet of "Assume breach."

  • Least privilege access

    Why it's wrong here

    "Least privilege access" is a critical security concept and a key component of Zero Trust, ensuring that users and systems are granted only the minimum permissions necessary to perform their specific tasks. This principle significantly reduces the attack surface and limits the potential damage from a compromised account or system. Nevertheless, it serves as a control mechanism for access rights rather than a guiding philosophy that mandates continuous monitoring and the proactive expectation of a security compromise, which is the essence of "Assume breach."

  • Assume breach

    Why this is correct

    "Assume breach" is a foundational Zero Trust principle that mandates organizations operate under the constant premise that their network and resources have already been compromised or will inevitably be. This mindset drives proactive security measures such as micro-segmentation, continuous threat detection, robust incident response planning, and regular security posture assessments. It shifts focus from perimeter defense to protecting individual resources and minimizing the blast radius of any successful attack, making it central to a resilient Zero Trust architecture.

  • Trust but verify

    Why it's wrong here

    The concept of "Trust but verify" originates from traditional perimeter-based security models where, once an entity gained access inside the network, it was largely afforded implicit trust. This approach fundamentally contradicts Zero Trust's core tenet of "never trust, always verify," which demands explicit verification for every access request, regardless of the entity's location or previous authentication status. Zero Trust explicitly rejects any inherent trust, making "Trust but verify" an outdated and incompatible security philosophy for modern environments.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.