SC-900 Practice Question: Describe the concepts of security, compliance, and identity
An organization adopts a Zero Trust security model. Which principle requires that every access request must be explicitly verified and granted least privilege regardless of the user's location or device?
⚠ Common exam trap
A common mix-up: candidates confuse the popular phrase 'Never trust, always verify' with the official Microsoft Zero Trust principle 'Verify explicitly,' but the exam expects the exact terminology from the Microsoft documentation, not the generic slogan.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify explicitly
The Zero Trust principle 'Verify explicitly' mandates that every access request—regardless of the user's location, device, or network—must be authenticated and authorized based on all available data points (e.g., user identity, device health, location, and real-time risk signals). This ensures that no implicit trust is granted, and least privilege is applied as a separate but complementary principle. In Microsoft's Zero Trust model, this is enforced through conditional access policies and continuous evaluation of session risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify explicitly
Why this is correct
In a Zero Trust model, "Verify explicitly" mandates that all access requests are rigorously authenticated and authorized based on all available data points. This includes user identity, device health, location, service or workload, data classification, and any detected anomalies. Access is never implicitly granted; instead, it is always explicitly validated against policy before being permitted, ensuring a robust security posture.
- ✗
Use least privilege access
Why it's wrong here
The "Use least privilege access" principle dictates that users and systems are granted only the minimum necessary permissions to perform their specific tasks, for the shortest possible duration. While crucial for minimizing the blast radius in the event of a compromise, this principle primarily addresses the *scope* of access rather than the *act* of verifying each individual access request. It assumes that once access is granted, it is limited, but doesn't define the continuous, explicit verification process itself.
- ✗
Assume breach
Why it's wrong here
The "Assume breach" principle posits that security perimeters can and will be breached, necessitating a proactive approach to security. It focuses on minimizing the impact of a breach by segmenting networks, encrypting data, and implementing micro-segmentation, thereby limiting an attacker's lateral movement. While foundational to Zero Trust resilience, this principle describes a mindset and mitigation strategy post-compromise, rather than the continuous, explicit verification of every access attempt.
- ✗
Never trust, always verify
Why it's wrong here
"Never trust, always verify" is a widely recognized mantra that encapsulates the core philosophy of Zero Trust, emphasizing that no user or device should be inherently trusted, regardless of their location. However, while it accurately reflects the underlying sentiment, it is not one of the three formally defined guiding principles of Zero Trust as articulated by Microsoft. The specific principle that mandates rigorous, continuous validation of every access request is "Verify explicitly".
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Zero Trust Architecture
Zero Trust Architecture is a cybersecurity model that requires every user and device to be continuously verified before accessing any resource, regardless of where they are located.
Key term
Zero Trust
Zero Trust is a security framework that assumes no user, device, or network is automatically trusted, requiring verification for every access request regardless of its origin.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.