SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A security administrator is explaining the concept of defense in depth to a new team member. Which statement best describes this approach?
⚠ Common exam trap
Many exam-takers confuse defense in depth with a single strong control (like a firewall or encryption), failing to recognize that the core principle is layering multiple independent controls to provide redundancy and depth.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Layering multiple security controls across different areas of the IT environment
Defense in depth is a cybersecurity strategy that employs multiple layers of security controls across different areas of the IT environment (network, endpoint, application, data, and physical). This approach ensures that if one control fails, another is already in place to mitigate the threat, providing redundancy and reducing the risk of a single point of failure. Microsoft's security framework, including tools like Microsoft Defender for Cloud and Azure Firewall, operationalizes this concept by integrating protections at each layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using a single, strong firewall to block all external traffic
Why it's wrong here
Using a single, strong firewall to block all external traffic, while a crucial component of network security, represents a single point of failure and is inadequate for a defense-in-depth strategy. Even the most advanced firewall cannot protect against internal threats, zero-day exploits, sophisticated phishing attacks that bypass perimeter defenses, or misconfigurations within the network. A true layered defense requires multiple, overlapping network controls, such as intrusion detection/prevention systems, network segmentation, and endpoint protection, to provide resilience against diverse attack vectors.
When this WOULD be correct
If the question asked for a simple, cost-effective security approach for a small network with minimal threats, a single strong firewall might be considered sufficient.
- ✓
Layering multiple security controls across different areas of the IT environment
Why this is correct
Defense in depth fundamentally involves deploying a comprehensive array of security controls across various layers and domains within an IT environment. This layered strategy ensures that if one security control is compromised or bypassed, other independent controls are still in place to detect, prevent, or mitigate the attack. It encompasses physical, technical, and administrative safeguards, creating a resilient security posture that significantly increases the effort and resources required for an attacker to succeed.
- ✗
Relying solely on encryption to protect all data at rest and in transit
Why it's wrong here
Relying exclusively on encryption, whether for data at rest or in transit, provides robust confidentiality but is insufficient for a complete security strategy. While encryption is a critical technical control, it does not address other vital security aspects such as unauthorized access to systems, insider threats, or the availability and integrity of data and services. A holistic defense-in-depth approach requires additional layers like access controls, network segmentation, vulnerability management, and security monitoring to protect against a broader spectrum of threats.
When this WOULD be correct
In a question asking 'Which control best protects data confidentiality during transmission?', encryption (e.g., TLS) would be the correct answer, as it specifically secures data in transit.
- ✗
Implementing only physical security measures to protect the data center
Why it's wrong here
Implementing solely physical security measures, such as locks, guards, and surveillance for a data center, creates a strong perimeter but leaves the internal logical environment vulnerable. Physical security is an essential foundational layer, yet it does not protect against cyberattacks, software vulnerabilities, logical access breaches, or data exfiltration once an attacker has bypassed the physical boundary or gained remote access. A comprehensive defense-in-depth strategy mandates additional layers including network security, application security, data security, and robust administrative controls.
When this WOULD be correct
A question asking for the primary security control for a data center's perimeter, such as 'Which measure best prevents unauthorized physical access to a server room?' would make physical security the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Layering multiple security controls across different areas of the IT environmentCorrect answer▾
Why this is correct
Defense in depth fundamentally involves deploying a comprehensive array of security controls across various layers and domains within an IT environment. This layered strategy ensures that if one security control is compromised or bypassed, other independent controls are still in place to detect, prevent, or mitigate the attack. It encompasses physical, technical, and administrative safeguards, creating a resilient security posture that significantly increases the effort and resources required for an attacker to succeed.
✗Using a single, strong firewall to block all external trafficWrong answer — click to see why▾
Why this is wrong here
Defense in depth requires multiple layers of security, not a single firewall. A single firewall can be bypassed or fail, leaving the environment unprotected.
★ When this WOULD be the correct answer
If the question asked for a simple, cost-effective security approach for a small network with minimal threats, a single strong firewall might be considered sufficient.
Why candidates choose this
Candidates may think a strong firewall is a comprehensive solution, overlooking the need for layered defenses against diverse attack vectors.
✗Relying solely on encryption to protect all data at rest and in transitWrong answer — click to see why▾
Why this is wrong here
Defense in depth requires multiple layers of security, not a single control. Relying solely on encryption ignores other critical layers like network segmentation, access controls, and monitoring.
★ When this WOULD be the correct answer
In a question asking 'Which control best protects data confidentiality during transmission?', encryption (e.g., TLS) would be the correct answer, as it specifically secures data in transit.
Why candidates choose this
Candidates may overvalue encryption as a comprehensive security measure, mistakenly believing it alone can address all threats, rather than understanding it is just one layer in a defense-in-depth strategy.
✗Implementing only physical security measures to protect the data centerWrong answer — click to see why▾
Why this is wrong here
Defense in depth requires multiple layers of security, not just physical measures. Relying solely on physical security ignores network, application, and data security, leaving many attack vectors unprotected.
★ When this WOULD be the correct answer
A question asking for the primary security control for a data center's perimeter, such as 'Which measure best prevents unauthorized physical access to a server room?' would make physical security the correct answer.
Why candidates choose this
Candidates may think physical security is the foundation of all security and overlook the need for layered controls, especially if they focus on the data center aspect of the scenario.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Defender for Cloud
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides unified security management and threat protection across hybrid and multi-cloud environments.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.