Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

Which TWO components are part of the 'Zero Trust' security model? (Choose two.)

⚠ Common exam trap

SC-900 often tests the misconception that Zero Trust includes traditional perimeter security or VPNs, when in fact it explicitly rejects those models in favor of continuous verification and least privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Least privilege

Option A (Least privilege) is correct because Zero Trust requires granting users and workloads only the minimum access needed for a specific task, typically enforced through just-in-time and just-enough-access policies, which limits lateral movement if an identity is compromised. Option D (Verify explicitly) is correct because Zero Trust mandates authenticating and authorizing every request based on all available signals—identity, device health, location, and data sensitivity—rather than trusting anything implicitly based on network location. Options B (VPN access), C (Password complexity), and E (Perimeter-based security) do not belong: a VPN is a legacy network-centric tunneling control that grants broad internal access once connected, password complexity is a single authentication hygiene rule rather than a Zero Trust principle, and perimeter-based security is the traditional castle-and-moat model that Zero Trust explicitly replaces with 'never trust, always verify.'

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Least privilege

    Why this is correct

    Least privilege grants users only the access required for their tasks, limiting lateral movement if credentials are compromised. This directly implements Zero Trust's assume-breach principle by constraining each identity's permissions rather than trusting network location.

  • ✗

    VPN access

    Why it's wrong here

    VPN access grants broad network-level trust once the tunnel is established, which contradicts Zero Trust's per-request verification. It is tempting because it secures remote connectivity, and it would be correct for giving remote workers encrypted access to on-premises resources.

  • ✗

    Password complexity

    Why it's wrong here

    Password complexity is a credential-strength control, not a Zero Trust principle, which requires explicit verification, least privilege and assumed breach. It is tempting because it hardens authentication, and it would be correct as part of an identity policy within Microsoft Entra ID.

  • ✓

    Verify explicitly

    Why this is correct

    Verify explicitly is a core Zero Trust principle, requiring every access request to be authenticated and authorised using all available signals — user identity, device health, location and risk. This directly satisfies the model's premise of never trusting implicitly, so Microsoft Entra ID evaluates each request rather than assuming trust from network location.

  • ✗

    Perimeter-based security

    Why it's wrong here

    Perimeter-based security trusts everything inside the corporate network, directly opposing Zero Trust's assume-breach model. It is tempting because it historically protected internal resources, and it would be correct for a legacy castle-and-moat architecture with a clearly defined trusted internal network.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.