SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Which THREE of the following are components of the Zero Trust security model?
⚠ Common exam trap
SC-900 often tests the three Zero Trust principles by mixing in adjacent technologies (SSO, MFA, perimeter firewalls) that sound security-related but are not the model's foundational pillars — candidates over-select because SSO feels integral to Zero Trust.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use least privilege access
The Zero Trust security model is built on three core principles, and option E 'Verify explicitly' is one of them: every access request must be authenticated and authorized based on all available data points (identity, device, location, workload, etc.) rather than trusting anything implicitly. Option A 'Use least privilege access' is also a core Zero Trust principle, implemented through just-in-time and just-enough-access (JIT/JEA), risk-based adaptive policies, and data protection to limit user and workload permissions. Option D 'Assume breach' is the third core principle, requiring organizations to minimize blast radius, segment access, verify end-to-end encryption, use analytics for threat detection, and design as if a breach has already occurred. Option B 'Single sign-on (SSO)' is an authentication convenience/identity mechanism that can support Zero Trust but is not itself one of its defining components, and option C 'Network perimeter security' is the traditional castle-and-moat model that Zero Trust explicitly rejects in favor of identity-centric, perimeter-less controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use least privilege access
Why this is correct
The "Use least privilege access" principle dictates that users and devices should only be granted the minimum necessary permissions to perform their specific tasks, for the shortest possible duration. This is often implemented through Just-In-Time (JIT) and Just-Enough-Access (JEA) mechanisms, significantly reducing the potential blast radius and impact should an account or system become compromised. It ensures that even if an attacker gains access, their lateral movement and damage are severely limited.
- ✗
Single sign-on (SSO)
Why it's wrong here
Single sign-on (SSO) is a valuable identity management feature that streamlines user authentication by allowing access to multiple applications with one set of credentials. However, SSO itself is not a core Zero Trust principle; it primarily enhances user experience and can improve security by reducing password fatigue. Zero Trust demands continuous, explicit verification and granular authorization for every access request, which goes beyond the initial authentication facilitated by SSO.
- ✗
Network perimeter security
Why it's wrong here
Network perimeter security, which relies on a strong boundary to protect an assumed-trusted internal network, is fundamentally at odds with Zero Trust principles. Zero Trust explicitly rejects the concept of a trusted network segment, treating all network traffic and access requests, whether originating internally or externally, as untrusted. It mandates explicit verification for every access attempt, regardless of its network origin, thereby eliminating reliance on a traditional perimeter.
- ✓
Assume breach
Why this is correct
The "Assume breach" principle mandates that organizations design their security architecture with the expectation that a breach will eventually occur, rather than trying to prevent all intrusions. This proactive mindset leads to strategies like micro-segmentation, robust monitoring, and rapid incident response capabilities to contain and mitigate potential compromises quickly. It focuses on minimizing the blast radius and ensuring business continuity even in the face of a successful attack.
- ✓
Verify explicitly
Why this is correct
The "Verify explicitly" principle requires that all access requests are authenticated and authorized based on all available data points, rather than relying on implicit trust. This comprehensive verification process incorporates user identity, device health, location, service, data sensitivity, and behavioral anomalies. It ensures that trust is never assumed but is continuously and dynamically evaluated before granting access to any resource, regardless of where the request originates.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Defence-in-Depth Security Layers
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Verify explicitly
Verify explicitly means that a system must actively confirm a user's identity or permissions before granting access, rather than trusting implied or cached credentials.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are core principles of the Zero Trust security model? (Choose three.)
hard- ✓ A.Verify explicitly
- B.Trust but verify
- ✓ C.Assume breach
- ✓ D.Least privilege
- E.Single factor authentication
Why A: Option A (Verify explicitly) is correct because Zero Trust requires every access request to be authenticated and authorized based on all available data points, including user identity, device health, location, and resource sensitivity, rather than granting implicit trust based on network location. Option C (Assume breach) is correct because Zero Trust operates on the premise that threats may already exist inside the environment, so organizations must minimize blast radius, segment access, encrypt traffic, and use analytics to detect and respond to anomalies. Option D (Least privilege) is correct because Zero Trust limits user and workload access to only what is needed for the task, using just-in-time and just-enough-access policies to reduce lateral movement. Option B (Trust but verify) is not a Zero Trust principle; it reflects a traditional perimeter-based mindset where trust is initially granted and then checked, which contradicts Zero Trust's explicit verification of every request. Option E (Single factor authentication) is not a Zero Trust principle; Zero Trust strongly favors strong authentication such as multifactor authentication and phishing-resistant methods, not single-factor authentication.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.