Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

Which TWO are principles of the Zero Trust security model?

⚠ Common exam trap

SC-900 often tests whether candidates can distinguish the three named Zero Trust principles from related but separate concepts like defense in depth, VPN usage, or network segmentation — candidates pick 'layer defenses' because it sounds security-sound but isn't one of the three principles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify explicitly

Option A, "Verify explicitly," is a core Zero Trust principle: every access request must be authenticated and authorized based on all available data points, including user identity, device health, location, and resource sensitivity, rather than granting implicit trust based on network location. Option C, "Assume breach," is the other foundational Zero Trust principle: organizations must operate as if an attacker is already present, which drives micro-segmentation, least-privilege access, end-to-end encryption, and continuous monitoring to minimize blast radius and detect threats. Option B, "Trust everything inside the network," is the opposite of Zero Trust, which explicitly rejects the castle-and-moat assumption that internal traffic is inherently trustworthy. Option D, "Use a VPN for remote access," is a connectivity mechanism, not a Zero Trust principle; Zero Trust instead favors per-request, identity-based access controls over implicit network-level trust. Option E, "Layer defenses," describes defense in depth, a complementary but distinct security strategy, not one of the three canonical Zero Trust principles (verify explicitly, use least-privilege access, assume breach).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Verify explicitly

    Why this is correct

    Verify explicitly requires authentication and authorisation decisions using all available signals, including identity, device health and location. It satisfies the Zero Trust principle that every access request is fully authenticated before resource access is granted.

  • ✗

    Trust everything inside the network

    Why it's wrong here

    Zero Trust assumes breach and verifies every request explicitly, so blanket trust for anything inside the perimeter contradicts its core tenet. The phrase tempts because legacy castle-and-moat designs did treat the internal network as trusted.

  • ✓

    Assume breach

    Why this is correct

    "Assume breach" is a core Zero Trust principle, operating on the premise that no network segment is trusted and an attacker may already be present. It drives micro-segmentation, end-to-end encryption, and analytics to minimise blast radius and verify every request, directly satisfying the model's requirement to eliminate implicit trust.

  • ✗

    Use a VPN for remote access

    Why it's wrong here

    A VPN extends implicit trust to everything inside the tunnel once connected, contradicting Zero Trust's verify-explicitly and assume-breach principles. It is tempting because VPNs do encrypt remote traffic, and they remain a valid access method where legacy systems cannot integrate modern identity controls.

  • ✗

    Layer defenses

    Why it's wrong here

    Layer defences describes defence in depth, a separate architectural principle, not one of the Zero Trust tenets of verify explicitly, least privilege and assume breach. It tempts because layered controls complement Zero Trust implementations, yet the model itself mandates no such principle.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.