SC-900 Practice Question: Describe the concepts of security, compliance, and identity
According to the Zero Trust security model, which principle assumes that a breach has already occurred and therefore requires segmenting access and monitoring for lateral movement?
⚠ Common exam trap
Microsoft often tests the distinction between 'Assume breach' and 'Verify explicitly' by presenting a scenario where a candidate might confuse the proactive verification of every request with the reactive assumption that a breach has already occurred, leading them to incorrectly select 'Verify explicitly' when the question specifically asks about segmentation and lateral movement monitoring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assume breach
The 'Assume breach' principle of the Zero Trust security model explicitly operates under the mindset that a breach has already occurred or is inevitable. This drives the need for segmenting access (e.g., micro-segmentation using network policies or Azure Virtual Network security groups) and continuous monitoring for lateral movement (e.g., using Microsoft Defender for Identity to detect pass-the-hash or Kerberos ticket attacks).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify explicitly
Why it's wrong here
Verify explicitly is a core Zero Trust principle that mandates all access requests, regardless of origin, must be authenticated and authorized based on all available data points, including user identity, location, device health, and service/data classification. While crucial for robust security, this principle focuses on the *process* of authentication and authorization, rather than the foundational *assumption* that the environment is already compromised. It ensures every access attempt is validated, but it is not the principle that directly embodies the initial premise of a breach.
- ✗
Use least privilege
Why it's wrong here
The 'Use least privilege' principle in Zero Trust dictates that users and systems should only be granted the minimum necessary access rights to perform their required tasks for the shortest possible duration. This minimizes the potential blast radius if an account or system is compromised, thereby limiting an attacker's lateral movement within the environment. However, it is a strategy for *containing* damage and reducing risk, not the direct principle that *assumes* an initial breach has already occurred.
- ✓
Assume breach
Why this is correct
The 'Assume breach' principle is foundational to the Zero Trust security model, asserting that an organization's network and all its components should be treated as if they are already compromised, regardless of their location or previous security posture. This paradigm shift eliminates implicit trust and drives security strategies such as micro-segmentation, continuous monitoring, and robust incident response planning. It directly addresses the question by embodying the core idea that no user, device, or application can be inherently trusted, and therefore, defenses must be built with a breach in mind.
- ✗
Trust but verify
Why it's wrong here
'Trust but verify' represents a traditional, perimeter-focused security model where entities inside the network perimeter are implicitly trusted, and verification primarily occurs at the network edge. This approach fundamentally contradicts the Zero Trust philosophy, which eliminates implicit trust for all entities, whether internal or external, and assumes no inherent trust based on location. Unlike 'Assume breach,' which presumes compromise, 'Trust but verify' starts with an assumption of trustworthiness within the trusted zone, making it an outdated concept in modern security.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Internet Protocol Security
Internet Protocol Security (IPsec) is a suite of protocols that encrypts and authenticates data packets sent over IP networks to ensure private and secure communication.
Key term
Zero Trust Architecture
Zero Trust Architecture is a cybersecurity model that requires every user and device to be continuously verified before accessing any resource, regardless of where they are located.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.