Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

An organization adopts a Zero Trust security model. Which principle requires that every access request must be explicitly verified and granted least privilege regardless of the user's location or device?

⚠ Common exam trap

A common mix-up: candidates confuse the popular phrase 'Never trust, always verify' with the official Microsoft Zero Trust principle 'Verify explicitly,' but the exam expects the exact terminology from the Microsoft documentation, not the generic slogan.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify explicitly

The Zero Trust principle 'Verify explicitly' mandates that every access request—regardless of the user's location, device, or network—must be authenticated and authorized based on all available data points (e.g., user identity, device health, location, and real-time risk signals). This ensures that no implicit trust is granted, and least privilege is applied as a separate but complementary principle. In Microsoft's Zero Trust model, this is enforced through conditional access policies and continuous evaluation of session risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Verify explicitly

    Why this is correct

    In a Zero Trust model, "Verify explicitly" mandates that all access requests are rigorously authenticated and authorized based on all available data points. This includes user identity, device health, location, service or workload, data classification, and any detected anomalies. Access is never implicitly granted; instead, it is always explicitly validated against policy before being permitted, ensuring a robust security posture.

  • Use least privilege access

    Why it's wrong here

    The "Use least privilege access" principle dictates that users and systems are granted only the minimum necessary permissions to perform their specific tasks, for the shortest possible duration. While crucial for minimizing the blast radius in the event of a compromise, this principle primarily addresses the *scope* of access rather than the *act* of verifying each individual access request. It assumes that once access is granted, it is limited, but doesn't define the continuous, explicit verification process itself.

  • Assume breach

    Why it's wrong here

    The "Assume breach" principle posits that security perimeters can and will be breached, necessitating a proactive approach to security. It focuses on minimizing the impact of a breach by segmenting networks, encrypting data, and implementing micro-segmentation, thereby limiting an attacker's lateral movement. While foundational to Zero Trust resilience, this principle describes a mindset and mitigation strategy post-compromise, rather than the continuous, explicit verification of every access attempt.

  • Never trust, always verify

    Why it's wrong here

    "Never trust, always verify" is a widely recognized mantra that encapsulates the core philosophy of Zero Trust, emphasizing that no user or device should be inherently trusted, regardless of their location. However, while it accurately reflects the underlying sentiment, it is not one of the three formally defined guiding principles of Zero Trust as articulated by Microsoft. The specific principle that mandates rigorous, continuous validation of every access request is "Verify explicitly".

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.