Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

An organization implements a security policy where users must authenticate using a smart card and PIN. After successful authentication, the system checks whether the user's device is managed by the organization and complies with security baselines. If the device is compliant, the user is granted access to the corporate network. If not, access is denied. This approach most directly reflects which security model?

⚠ Common exam trap

Test-takers frequently confuse Zero Trust with Defense in depth because both involve multiple security layers, but Zero Trust specifically requires per-request verification of identity and device health, whereas Defense in depth relies on static layers without dynamic device compliance checks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Zero Trust

The scenario explicitly enforces 'never trust, always verify' by requiring authentication (smart card + PIN) and then validating device compliance before granting network access. This directly aligns with the Zero Trust model's core principle of conditional access based on identity and device health, rather than implicit trust from network location.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Defense in depth

    Why it's wrong here

    Defense in depth uses multiple layers of security controls. While this scenario includes two layers (authentication and device check), it specifically embodies the 'never trust, always verify' philosophy of Zero Trust, not just layered defenses.

  • Zero Trust

    Why this is correct

    Zero Trust is an architectural model that mandates explicit verification for every access request, regardless of whether the user or device is inside or outside the traditional network perimeter. The policy of blocking access if a device is non-compliant directly embodies the 'never trust, always verify' principle by continuously validating device health and posture before granting access to organizational resources. This approach ensures that access decisions are dynamic and based on real-time context, rather than static network location.

  • CIA triad

    Why it's wrong here

    The CIA triad represents the fundamental security objectives of Confidentiality, Integrity, and Availability for information. While the scenario describes security controls that *contribute* to achieving these goals, the CIA triad itself is a framework for defining desired security states for data, not an operational access control model or a specific methodology for enforcing access policies. The policy in question details *how* access is managed, rather than *what* security properties are being protected.

  • Least privilege

    Why it's wrong here

    Least privilege limits user permissions to only what is necessary. While device compliance may be a factor, the scenario does not specify permission scope; it focuses on verifying identity and device before granting network access.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.