SC-900 Practice Question: Describe the concepts of security, compliance, and identity
An organization is implementing a Zero Trust security model. Which principle requires that every access request must be fully authenticated, authorized, and verified based on all available signals, regardless of the user's network location?
⚠ Common exam trap
Watch out — candidates often confuse 'Verify explicitly' with 'Least privilege' because both involve access control, but 'Verify explicitly' is about continuous authentication and authorization of every request, while 'Least privilege' is about limiting permissions after access is granted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify explicitly
The 'Verify explicitly' principle of Zero Trust mandates that every access request must be fully authenticated, authorized, and encrypted based on all available data points—including user identity, device health, location, and behavioral signals—regardless of whether the request originates from inside or outside the corporate network. This contrasts with traditional perimeter-based models that implicitly trust internal traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify explicitly
Why this is correct
This foundational Zero Trust principle mandates that all access requests, regardless of their origin or the resource being accessed, must be authenticated and authorized continuously. It requires leveraging all available data points, such as user identity, device health, location, service, and data classification, to make dynamic access decisions. This 'never trust, always verify' approach ensures that trust is never implicit and is re-evaluated with every interaction, moving beyond traditional perimeter-based security.
- ✗
Least privilege
Why it's wrong here
While a critical component of any robust security architecture, the principle of least privilege primarily dictates that users and systems should only be granted the minimum necessary permissions to perform their required tasks. It focuses on limiting the scope of access to specific resources and actions, thereby reducing the potential impact should an account or system become compromised. This principle defines what an entity can do after being verified, rather than how that verification process itself is conducted within a Zero Trust model.
- ✗
Assume breach
Why it's wrong here
The 'Assume Breach' principle is a strategic mindset within Zero Trust, acknowledging the inevitability of security compromises and designing systems to minimize their impact. It involves proactive measures like micro-segmentation, robust monitoring, and incident response planning to contain breaches rapidly and limit the 'blast radius.' This principle focuses on resilience and response post-compromise, rather than the initial, continuous verification of every access request that defines the 'Verify Explicitly' principle.
- ✗
Defense in depth
Why it's wrong here
Defense in depth is a comprehensive security strategy that layers multiple, independent security controls to protect information and systems. It aims to create redundancy, so if one security control fails, another can provide protection, encompassing physical, technical, and administrative safeguards. While a fundamental security concept, it describes a layered methodology for building overall security, distinct from the specific Zero Trust principle that governs the continuous, explicit verification of every access attempt.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Verify explicitly
Verify explicitly means that a system must actively confirm a user's identity or permissions before granting access, rather than trusting implied or cached credentials.
Key term
Zero Trust Architecture
Zero Trust Architecture is a cybersecurity model that requires every user and device to be continuously verified before accessing any resource, regardless of where they are located.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.