SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Which THREE of the following are core principles of the Zero Trust security model? (Choose three.)
⚠ Common exam trap
SC-900 often tests the exact wording of Zero Trust principles; the trap is selecting 'trust but verify' (a legacy concept) or 'single factor authentication' (insufficient) instead of the three official principles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify explicitly
Option A (Verify explicitly) is correct because Zero Trust requires every access request to be authenticated and authorized based on all available data points, including user identity, device health, location, and resource sensitivity, rather than granting implicit trust based on network location. Option C (Assume breach) is correct because Zero Trust operates on the premise that threats may already exist inside the environment, so organizations must minimize blast radius, segment access, encrypt traffic, and use analytics to detect and respond to anomalies. Option D (Least privilege) is correct because Zero Trust limits user and workload access to only what is needed for the task, using just-in-time and just-enough-access policies to reduce lateral movement. Option B (Trust but verify) is not a Zero Trust principle; it reflects a traditional perimeter-based mindset where trust is initially granted and then checked, which contradicts Zero Trust's explicit verification of every request. Option E (Single factor authentication) is not a Zero Trust principle; Zero Trust strongly favors strong authentication such as multifactor authentication and phishing-resistant methods, not single-factor authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify explicitly
Why this is correct
This principle mandates that all access requests, regardless of origin or resource, must be authenticated and authorized rigorously. It involves continuously evaluating user identity, device health, location, and other contextual signals before granting or maintaining access. This explicit verification ensures that no entity is inherently trusted and access is always granted based on real-time policy enforcement.
- ✗
Trust but verify
Why it's wrong here
The "trust but verify" approach is characteristic of traditional perimeter-based security models, where entities inside the network are implicitly trusted once they've passed an initial verification at the network edge. In contrast, Zero Trust fundamentally rejects this concept, asserting that trust should never be assumed, even for internal users or devices. This traditional model often leads to lateral movement vulnerabilities if an attacker breaches the perimeter.
- ✓
Assume breach
Why this is correct
This core principle dictates that organizations must operate under the assumption that their network has already been compromised or will be at some point. Consequently, security architectures are designed to minimize the "blast radius" of any potential breach by segmenting networks, isolating resources, and implementing granular access controls. This proactive mindset shifts focus from prevention alone to detection, response, and containment.
- ✓
Least privilege
Why this is correct
The principle of least privilege ensures that users and devices are granted only the minimum necessary access to perform their specific tasks, and for the shortest possible duration. This involves implementing just-in-time (JIT) and just-enough-access (JEA) permissions, significantly reducing the potential impact if an account or device is compromised. It prevents over-privileged accounts from being exploited for unauthorized lateral movement or data exfiltration.
- ✗
Single factor authentication
Why it's wrong here
Single-factor authentication (SFA) relies on only one piece of evidence, such as a password, to verify an identity, making it highly susceptible to phishing, brute-force attacks, and credential stuffing. Zero Trust explicitly mandates the use of strong multi-factor authentication (MFA) for all access requests, significantly enhancing identity verification by requiring two or more distinct authentication factors. SFA is fundamentally incompatible with the rigorous verification demands of a Zero Trust architecture.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Cross-Tenant Access Settings
Key term
Remote Authentication Dial-in User Service
RADIUS is a network protocol that provides centralized authentication, authorization, and accounting for users trying to connect to a network service.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.