SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Which TWO are principles of the Zero Trust security model?
⚠ Common exam trap
SC-900 often tests whether candidates can distinguish the three named Zero Trust principles from related but separate concepts like defense in depth, VPN usage, or network segmentation — candidates pick 'layer defenses' because it sounds security-sound but isn't one of the three principles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify explicitly
Option A, "Verify explicitly," is a core Zero Trust principle: every access request must be authenticated and authorized based on all available data points, including user identity, device health, location, and resource sensitivity, rather than granting implicit trust based on network location. Option C, "Assume breach," is the other foundational Zero Trust principle: organizations must operate as if an attacker is already present, which drives micro-segmentation, least-privilege access, end-to-end encryption, and continuous monitoring to minimize blast radius and detect threats. Option B, "Trust everything inside the network," is the opposite of Zero Trust, which explicitly rejects the castle-and-moat assumption that internal traffic is inherently trustworthy. Option D, "Use a VPN for remote access," is a connectivity mechanism, not a Zero Trust principle; Zero Trust instead favors per-request, identity-based access controls over implicit network-level trust. Option E, "Layer defenses," describes defense in depth, a complementary but distinct security strategy, not one of the three canonical Zero Trust principles (verify explicitly, use least-privilege access, assume breach).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Verify explicitly
Why this is correct
Verify explicitly requires authentication and authorisation decisions using all available signals, including identity, device health and location. It satisfies the Zero Trust principle that every access request is fully authenticated before resource access is granted.
- ✗
Trust everything inside the network
Why it's wrong here
Zero Trust assumes breach and verifies every request explicitly, so blanket trust for anything inside the perimeter contradicts its core tenet. The phrase tempts because legacy castle-and-moat designs did treat the internal network as trusted.
- ✓
Assume breach
Why this is correct
"Assume breach" is a core Zero Trust principle, operating on the premise that no network segment is trusted and an attacker may already be present. It drives micro-segmentation, end-to-end encryption, and analytics to minimise blast radius and verify every request, directly satisfying the model's requirement to eliminate implicit trust.
- ✗
Use a VPN for remote access
Why it's wrong here
A VPN extends implicit trust to everything inside the tunnel once connected, contradicting Zero Trust's verify-explicitly and assume-breach principles. It is tempting because VPNs do encrypt remote traffic, and they remain a valid access method where legacy systems cannot integrate modern identity controls.
- ✗
Layer defenses
Why it's wrong here
Layer defences describes defence in depth, a separate architectural principle, not one of the Zero Trust tenets of verify explicitly, least privilege and assume breach. It tempts because layered controls complement Zero Trust implementations, yet the model itself mandates no such principle.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Cloud Security Posture Management (CSPM)
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
VPN
A VPN creates an encrypted tunnel over a public network to securely connect remote users or sites to a private network.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.