SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A security administrator is explaining the Zero Trust model to a new colleague. The administrator states that trust should never be granted based solely on network location, and every access request must be fully authenticated and authorized using all available signals. Which Zero Trust principle does this statement describe?
⚠ Common exam trap
Microsoft often tests the distinction between 'Verify explicitly' and 'Assume breach' by presenting a scenario that emphasizes authentication and authorization signals, leading candidates to confuse the proactive verification step with the reactive breach containment strategy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify explicitly
The statement that trust should never be granted based solely on network location and that every access request must be fully authenticated and authorized using all available signals directly describes the 'Verify explicitly' principle of the Zero Trust model. This principle mandates that authentication and authorization are performed for every access attempt, regardless of the source (e.g., internal network, VPN, cloud), using all available data points such as user identity, device health, and location.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assume breach
Why it's wrong here
The 'Assume breach' principle in Zero Trust dictates that organizations must design their security architecture with the understanding that a breach is inevitable or has already occurred. This focuses on minimizing the blast radius of any compromise and ensuring rapid detection and response capabilities. While fundamental to Zero Trust resilience, it addresses post-compromise containment and recovery strategies, not the initial decision to grant or deny access based on a device's network location.
- ✓
Verify explicitly
Why this is correct
The 'Verify explicitly' principle is central to Zero Trust, requiring that all access requests are authenticated and authorized based on all available data points, rather than granting implicit trust. This includes evaluating user identity, device health, location, service, data classification, and potential anomalies continuously. It directly challenges traditional security models by explicitly rejecting the notion that network location alone can confer trustworthiness for any resource access.
- ✗
Use least privilege
Why it's wrong here
The 'Use least privilege' principle ensures that users and devices are granted only the absolute minimum access necessary to perform their specific tasks, thereby reducing the potential impact of a compromised account or system. While a critical component of Zero Trust for limiting lateral movement and containing damage, this principle primarily governs the *scope* of authorized access after verification, rather than the initial decision to trust or distrust based on network location.
- ✗
Segment access
Why it's wrong here
Segment access involves strategically dividing networks into smaller, isolated zones, often using micro-segmentation, to limit lateral movement and contain potential breaches within a smaller area. This is a crucial *implementation* strategy for achieving Zero Trust goals, particularly in support of 'Assume breach' and 'Least privilege.' However, it is a consequence of the Zero Trust philosophy, not the specific principle that dictates the rejection of implicit trust based on a device's network position.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Identity
Identity is the unique set of attributes that defines a user, device, or service in a computer system, determining what they can access and do.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.