SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Which TWO components are part of the 'Zero Trust' security model? (Choose two.)
⚠ Common exam trap
SC-900 often tests the misconception that Zero Trust includes traditional perimeter security or VPNs, when in fact it explicitly rejects those models in favor of continuous verification and least privilege.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Least privilege
Option A (Least privilege) is correct because Zero Trust requires granting users and workloads only the minimum access needed for a specific task, typically enforced through just-in-time and just-enough-access policies, which limits lateral movement if an identity is compromised. Option D (Verify explicitly) is correct because Zero Trust mandates authenticating and authorizing every request based on all available signals—identity, device health, location, and data sensitivity—rather than trusting anything implicitly based on network location. Options B (VPN access), C (Password complexity), and E (Perimeter-based security) do not belong: a VPN is a legacy network-centric tunneling control that grants broad internal access once connected, password complexity is a single authentication hygiene rule rather than a Zero Trust principle, and perimeter-based security is the traditional castle-and-moat model that Zero Trust explicitly replaces with 'never trust, always verify.'
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Least privilege
Why this is correct
Least privilege grants users only the access required for their tasks, limiting lateral movement if credentials are compromised. This directly implements Zero Trust's assume-breach principle by constraining each identity's permissions rather than trusting network location.
- ✗
VPN access
Why it's wrong here
VPN access grants broad network-level trust once the tunnel is established, which contradicts Zero Trust's per-request verification. It is tempting because it secures remote connectivity, and it would be correct for giving remote workers encrypted access to on-premises resources.
- ✗
Password complexity
Why it's wrong here
Password complexity is a credential-strength control, not a Zero Trust principle, which requires explicit verification, least privilege and assumed breach. It is tempting because it hardens authentication, and it would be correct as part of an identity policy within Microsoft Entra ID.
- ✓
Verify explicitly
Why this is correct
Verify explicitly is a core Zero Trust principle, requiring every access request to be authenticated and authorised using all available signals — user identity, device health, location and risk. This directly satisfies the model's premise of never trusting implicitly, so Microsoft Entra ID evaluates each request rather than assuming trust from network location.
- ✗
Perimeter-based security
Why it's wrong here
Perimeter-based security trusts everything inside the corporate network, directly opposing Zero Trust's assume-breach model. It is tempting because it historically protected internal resources, and it would be correct for a legacy castle-and-moat architecture with a clearly defined trusted internal network.
Go deeper
Related to this question
Learn chapter
Data Residency, Sovereignty, and Privacy
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
Lateral movement
Lateral movement is the technique attackers use to move through a network from one compromised system to another, seeking sensitive data or higher privileges.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.