Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A security administrator is explaining the Zero Trust model to a new colleague. The administrator states that trust should never be granted based solely on network location, and every access request must be fully authenticated and authorized using all available signals. Which Zero Trust principle does this statement describe?

⚠ Common exam trap

Microsoft often tests the distinction between 'Verify explicitly' and 'Assume breach' by presenting a scenario that emphasizes authentication and authorization signals, leading candidates to confuse the proactive verification step with the reactive breach containment strategy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify explicitly

The statement that trust should never be granted based solely on network location and that every access request must be fully authenticated and authorized using all available signals directly describes the 'Verify explicitly' principle of the Zero Trust model. This principle mandates that authentication and authorization are performed for every access attempt, regardless of the source (e.g., internal network, VPN, cloud), using all available data points such as user identity, device health, and location.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assume breach

    Why it's wrong here

    The 'Assume breach' principle in Zero Trust dictates that organizations must design their security architecture with the understanding that a breach is inevitable or has already occurred. This focuses on minimizing the blast radius of any compromise and ensuring rapid detection and response capabilities. While fundamental to Zero Trust resilience, it addresses post-compromise containment and recovery strategies, not the initial decision to grant or deny access based on a device's network location.

  • Verify explicitly

    Why this is correct

    The 'Verify explicitly' principle is central to Zero Trust, requiring that all access requests are authenticated and authorized based on all available data points, rather than granting implicit trust. This includes evaluating user identity, device health, location, service, data classification, and potential anomalies continuously. It directly challenges traditional security models by explicitly rejecting the notion that network location alone can confer trustworthiness for any resource access.

  • Use least privilege

    Why it's wrong here

    The 'Use least privilege' principle ensures that users and devices are granted only the absolute minimum access necessary to perform their specific tasks, thereby reducing the potential impact of a compromised account or system. While a critical component of Zero Trust for limiting lateral movement and containing damage, this principle primarily governs the *scope* of authorized access after verification, rather than the initial decision to trust or distrust based on network location.

  • Segment access

    Why it's wrong here

    Segment access involves strategically dividing networks into smaller, isolated zones, often using micro-segmentation, to limit lateral movement and contain potential breaches within a smaller area. This is a crucial *implementation* strategy for achieving Zero Trust goals, particularly in support of 'Assume breach' and 'Least privilege.' However, it is a consequence of the Zero Trust philosophy, not the specific principle that dictates the rejection of implicit trust based on a device's network position.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.