Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

According to the Zero Trust security model, which principle assumes that a breach has already occurred and therefore requires segmenting access and monitoring for lateral movement?

⚠ Common exam trap

Microsoft often tests the distinction between 'Assume breach' and 'Verify explicitly' by presenting a scenario where a candidate might confuse the proactive verification of every request with the reactive assumption that a breach has already occurred, leading them to incorrectly select 'Verify explicitly' when the question specifically asks about segmentation and lateral movement monitoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assume breach

The 'Assume breach' principle of the Zero Trust security model explicitly operates under the mindset that a breach has already occurred or is inevitable. This drives the need for segmenting access (e.g., micro-segmentation using network policies or Azure Virtual Network security groups) and continuous monitoring for lateral movement (e.g., using Microsoft Defender for Identity to detect pass-the-hash or Kerberos ticket attacks).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Verify explicitly

    Why it's wrong here

    Verify explicitly is a core Zero Trust principle that mandates all access requests, regardless of origin, must be authenticated and authorized based on all available data points, including user identity, location, device health, and service/data classification. While crucial for robust security, this principle focuses on the *process* of authentication and authorization, rather than the foundational *assumption* that the environment is already compromised. It ensures every access attempt is validated, but it is not the principle that directly embodies the initial premise of a breach.

  • Use least privilege

    Why it's wrong here

    The 'Use least privilege' principle in Zero Trust dictates that users and systems should only be granted the minimum necessary access rights to perform their required tasks for the shortest possible duration. This minimizes the potential blast radius if an account or system is compromised, thereby limiting an attacker's lateral movement within the environment. However, it is a strategy for *containing* damage and reducing risk, not the direct principle that *assumes* an initial breach has already occurred.

  • Assume breach

    Why this is correct

    The 'Assume breach' principle is foundational to the Zero Trust security model, asserting that an organization's network and all its components should be treated as if they are already compromised, regardless of their location or previous security posture. This paradigm shift eliminates implicit trust and drives security strategies such as micro-segmentation, continuous monitoring, and robust incident response planning. It directly addresses the question by embodying the core idea that no user, device, or application can be inherently trusted, and therefore, defenses must be built with a breach in mind.

  • Trust but verify

    Why it's wrong here

    'Trust but verify' represents a traditional, perimeter-focused security model where entities inside the network perimeter are implicitly trusted, and verification primarily occurs at the network edge. This approach fundamentally contradicts the Zero Trust philosophy, which eliminates implicit trust for all entities, whether internal or external, and assumes no inherent trust based on location. Unlike 'Assume breach,' which presumes compromise, 'Trust but verify' starts with an assumption of trustworthiness within the trusted zone, making it an outdated concept in modern security.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.