SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A security architect is implementing a Zero Trust security model. The architect insists that the network perimeter should not be trusted and that security controls must be applied to all traffic, even within the corporate network. They also emphasize the need for continuous monitoring and detection of threats as if a breach has already occurred. Which Zero Trust principle is the architect primarily applying?
⚠ Common exam trap
Microsoft often tests the distinction between 'Assume breach' and 'Verify explicitly' by describing a scenario that includes both continuous monitoring and strict access controls, leading candidates to confuse the proactive verification requirement with the reactive breach-assumption mindset.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assume breach
The architect's emphasis on not trusting the network perimeter and applying security controls to all traffic, combined with continuous monitoring as if a breach has already occurred, directly aligns with the 'Assume breach' principle of Zero Trust. This principle operates on the mindset that a breach is inevitable or has already happened, thus requiring constant verification and monitoring of all network traffic, even within the corporate network, rather than relying on a trusted internal zone.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify explicitly
Why it's wrong here
While "Verify explicitly" is a fundamental Zero Trust principle, it primarily dictates that all access requests are authenticated and authorized based on all available data points, including user identity, device health, location, and data classification. It establishes trust dynamically before granting access. However, this principle does not directly encapsulate the proactive mindset of expecting a breach to occur or already be in progress, which is the core tenet of "Assume breach."
- ✗
Least privilege access
Why it's wrong here
"Least privilege access" is a critical security concept and a key component of Zero Trust, ensuring that users and systems are granted only the minimum permissions necessary to perform their specific tasks. This principle significantly reduces the attack surface and limits the potential damage from a compromised account or system. Nevertheless, it serves as a control mechanism for access rights rather than a guiding philosophy that mandates continuous monitoring and the proactive expectation of a security compromise, which is the essence of "Assume breach."
- ✓
Assume breach
Why this is correct
"Assume breach" is a foundational Zero Trust principle that mandates organizations operate under the constant premise that their network and resources have already been compromised or will inevitably be. This mindset drives proactive security measures such as micro-segmentation, continuous threat detection, robust incident response planning, and regular security posture assessments. It shifts focus from perimeter defense to protecting individual resources and minimizing the blast radius of any successful attack, making it central to a resilient Zero Trust architecture.
- ✗
Trust but verify
Why it's wrong here
The concept of "Trust but verify" originates from traditional perimeter-based security models where, once an entity gained access inside the network, it was largely afforded implicit trust. This approach fundamentally contradicts Zero Trust's core tenet of "never trust, always verify," which demands explicit verification for every access request, regardless of the entity's location or previous authentication status. Zero Trust explicitly rejects any inherent trust, making "Trust but verify" an outdated and incompatible security philosophy for modern environments.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Security model
A security model is a formal framework that defines how subjects (users, processes) can access objects (files, resources) based on rules, ensuring confidentiality, integrity, and availability.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.