SC-900 Practice Question: Describe the concepts of security, compliance, and identity
An organization implements a security policy where users must authenticate using a smart card and PIN. After successful authentication, the system checks whether the user's device is managed by the organization and complies with security baselines. If the device is compliant, the user is granted access to the corporate network. If not, access is denied. This approach most directly reflects which security model?
⚠ Common exam trap
Test-takers frequently confuse Zero Trust with Defense in depth because both involve multiple security layers, but Zero Trust specifically requires per-request verification of identity and device health, whereas Defense in depth relies on static layers without dynamic device compliance checks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Zero Trust
The scenario explicitly enforces 'never trust, always verify' by requiring authentication (smart card + PIN) and then validating device compliance before granting network access. This directly aligns with the Zero Trust model's core principle of conditional access based on identity and device health, rather than implicit trust from network location.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Defense in depth
Why it's wrong here
Defense in depth uses multiple layers of security controls. While this scenario includes two layers (authentication and device check), it specifically embodies the 'never trust, always verify' philosophy of Zero Trust, not just layered defenses.
- ✓
Zero Trust
Why this is correct
Zero Trust is an architectural model that mandates explicit verification for every access request, regardless of whether the user or device is inside or outside the traditional network perimeter. The policy of blocking access if a device is non-compliant directly embodies the 'never trust, always verify' principle by continuously validating device health and posture before granting access to organizational resources. This approach ensures that access decisions are dynamic and based on real-time context, rather than static network location.
- ✗
CIA triad
Why it's wrong here
The CIA triad represents the fundamental security objectives of Confidentiality, Integrity, and Availability for information. While the scenario describes security controls that *contribute* to achieving these goals, the CIA triad itself is a framework for defining desired security states for data, not an operational access control model or a specific methodology for enforcing access policies. The policy in question details *how* access is managed, rather than *what* security properties are being protected.
- ✗
Least privilege
Why it's wrong here
Least privilege limits user permissions to only what is necessary. While device compliance may be a factor, the scenario does not specify permission scope; it focuses on verifying identity and device before granting network access.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Device compliance
Device compliance is the process of ensuring that a device meets an organization's security and configuration policies before it can access network resources.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.