Courseiva
Question 837 of 1,250

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A security architect is implementing a Zero Trust strategy. They state that all access requests must be verified continuously, regardless of where the request originates (corporate network or remote). They also emphasize that access is granted based on a policy that evaluates user identity, device health, location, and risk in real-time. Which Zero Trust guiding principle does this scenario primarily illustrate?

⚠ Common exam trap

A common mix-up: candidates confuse 'Verify explicitly' with 'Assume breach' because both involve continuous monitoring, but 'Verify explicitly' is specifically about authenticating and authorizing every request, while 'Assume breach' is about containment and detection after a compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify explicitly

The scenario explicitly describes continuous verification of all access requests based on real-time signals (user identity, device health, location, risk). This directly maps to the 'Verify explicitly' Zero Trust principle, which mandates that every access attempt must be authenticated and authorized using all available data points before granting access, regardless of network location.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Verify explicitly

    Why this is correct

    "Verify explicitly" is a foundational principle of Zero Trust, mandating that all access requests, regardless of origin, must be thoroughly authenticated and authorized before granting access. This involves evaluating multiple dynamic data points, including user identity, device health, service or workload, data classification, location, and detected anomalies, to make an informed, real-time access decision. It fundamentally shifts security from perimeter-based trust to continuous, granular validation, never implicitly trusting anything inside or outside the network.

  • Use least privilege access

    Why it's wrong here

    While an essential component of a robust security posture and often implemented within a Zero Trust framework, "Use least privilege access" is a distinct principle focused on minimizing the scope of permissions granted to users and systems. It ensures that entities only have the necessary access for their specific tasks and for the shortest possible duration (just-in-time, just-enough access), rather than defining the continuous verification process itself. This principle primarily helps limit the potential blast radius in case of a compromise.

  • Assume breach

    Why it's wrong here

    "Assume breach" is a foundational mindset for Zero Trust, dictating that organizations should design their security architecture and operations as if an attacker has already gained access to the network. This principle drives strategies like micro-segmentation, robust monitoring, and incident response planning to contain and mitigate potential threats quickly and minimize damage. However, it describes a strategic posture and risk management approach, not one of the three core operational principles directly governing the continuous verification and authorization of access requests.

  • Enforce session controls

    Why it's wrong here

    Enforcing session controls, such as requiring reauthentication for sensitive actions, limiting session duration, or monitoring session activity, is a valuable security mechanism often deployed as part of a comprehensive Zero Trust implementation. These controls help maintain security post-authentication by continuously evaluating user and device behavior during an active session and adjusting access accordingly. However, it represents a specific technical control or capability rather than one of the overarching, foundational principles of Zero Trust, which are "Verify explicitly," "Use least privilege access," and "Assume breach."

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.