SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization wants to implement a Zero Trust security model. Which TWO principles are part of the Zero Trust model? (Select TWO.)
⚠ Common exam trap
Many exam-takers confuse Zero Trust with traditional network segmentation or VPN-based access, mistakenly thinking that internal traffic or IP-based rules are inherently trusted, when in fact Zero Trust requires explicit verification for every request regardless of origin.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assume breach
Option A (Assume breach) is correct because Zero Trust operates on the principle of assuming that any part of the environment may already be compromised, so systems should minimize blast radius, segment access, and use end-to-end encryption rather than trusting internal networks. Option C (Verify explicitly) is correct because Zero Trust requires authenticating and authorizing every access request based on all available data points, including user identity, device health, location, and resource sensitivity, rather than granting access based on network location. Options B, D, and E are incorrect because they reflect traditional perimeter-based security assumptions: granting access by IP address, relying on network perimeter defenses, and applying implicit trust to internal traffic all contradict the Zero Trust tenets of explicit verification and least-privilege access regardless of network origin.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assume breach
Why this is correct
The "Assume breach" principle dictates that organizations should design their security architecture and operations with the mindset that an attacker has already successfully penetrated their defenses. This proactive approach drives the implementation of robust detection, response, and recovery capabilities, alongside micro-segmentation and least-privilege access to minimize the blast radius of any potential compromise. It shifts focus from solely preventing breaches to building resilience and ensuring business continuity even when security controls are inevitably bypassed.
- ✗
Grant access based on IP address
Why it's wrong here
Granting access solely based on an IP address is a legacy security model that is fundamentally incompatible with Zero Trust principles. IP addresses can be easily spoofed, reassigned, or associated with compromised devices, providing an insufficient and unreliable basis for establishing trust. Zero Trust mandates explicit verification of user identity, device health, location, and other contextual attributes for every access request, rather than relying on a static network-layer identifier.
- ✓
Verify explicitly
Why this is correct
The "Verify explicitly" principle is a cornerstone of Zero Trust, requiring that all access requests, regardless of their origin, are thoroughly authenticated and authorized before access is granted. This involves evaluating all available data points in real-time, including user identity, device health, location, service, workload, and data classification. It ensures that trust is never assumed but is continuously and dynamically established based on a comprehensive assessment of the current context and risk.
- ✗
Rely on network perimeter security
Why it's wrong here
Relying primarily on network perimeter security is antithetical to the Zero Trust model, which recognizes that traditional boundaries are no longer sufficient to protect modern, distributed environments. Perimeter-based security assumes that everything inside the network is inherently trustworthy, a dangerous assumption given the prevalence of insider threats and sophisticated external attacks. Zero Trust moves beyond this by applying security controls at the individual resource level, treating all network traffic and access requests as untrusted, regardless of their origin.
- ✗
Use implicit trust for internal traffic
Why it's wrong here
Using implicit trust for internal network traffic directly contradicts the foundational tenets of Zero Trust, which operates on the principle of "never trust, always verify." The Zero Trust model explicitly rejects the notion that resources or users within an organization's internal network are inherently trustworthy simply because they are inside a traditional perimeter. Instead, every access request, whether originating internally or externally, must be explicitly verified and authorized based on identity and context before access is granted, enforcing consistent security policies everywhere.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Azure Resource Locks: ReadOnly and Delete
Key term
Remote Authentication Dial-in User Service
RADIUS is a network protocol that provides centralized authentication, authorization, and accounting for users trying to connect to a network service.
Key term
Security model
A security model is a formal framework that defines how subjects (users, processes) can access objects (files, resources) based on rules, ensuring confidentiality, integrity, and availability.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.