Zero Trust: Why Identity Is the New Security Perimeter
A security architect is explaining the Zero Trust model to the board. The architect emphasizes that the network perimeter can no longer be considered a safe zone. Which statement best describes the modern primary security perimeter according to Zero Trust principles?
Quick Answer
The answer is the identity of the user and device. This is correct because Zero Trust flips the old model on its head: instead of trusting anything inside a network firewall, it assumes breach and treats every access request as a potential threat, making identity—not network location—the new security perimeter. On the SC-900 exam, this concept tests your understanding that Zero Trust shifts the control plane from IP addresses to who and what is requesting access, with a common trap being to select “network segmentation” or “VPN” as the primary perimeter. A solid memory tip is to think of “ID as the new firewall”—if you can’t verify the user and device, no network location earns trust.
⚠ Common exam trap
Many candidates confuse the Zero Trust model with traditional defense-in-depth layers, mistakenly selecting the corporate firewall or VPN as the primary perimeter, when in fact Zero Trust shifts the trust boundary to the identity of the user and device.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The identity of the user and device
In the Zero Trust model, the primary security perimeter is the identity of the user and device, not the network location. This is because Zero Trust assumes breach and requires explicit verification for every access request, regardless of whether it originates from inside or outside the corporate network. By treating identity as the new control plane, organizations enforce least-privilege access and continuous authentication, making the user and device identity the critical trust boundary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The corporate network firewall and VPN
Why it's wrong here
Zero Trust explicitly moves away from relying on network perimeters like firewalls and VPNs as the sole security boundary.
- ✓
The identity of the user and device
Why this is correct
Identity is the fundamental building block of Zero Trust; it is used to verify every access request and enforce least privilege, forming the new perimeter.
- ✗
The physical on-premises data center
Why it's wrong here
Zero Trust applies equally to on-premises and cloud resources; physical location is not a trust factor.
- ✗
The endpoint antivirus and anti-malware solution
Why it's wrong here
While endpoint protection is important, it is just one component. The primary perimeter is identity, not a specific security tool.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Trust boundary
A trust boundary is the logical or physical line that separates a trusted, secure area from an untrusted, potentially hostile environment in a computer system or network.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security architect is designing a defense strategy for the organization's network. The architect assumes that an attacker may already have breached the perimeter and is operating inside the network. Therefore, the design does not automatically trust any user or device, even if they are inside the corporate network, and requires continuous verification for every access request. Which security principle does this approach best represent?
easy- A.Defense in depth
- ✓ B.Zero Trust
- C.Shared responsibility
- D.Least privilege
Why B: The Zero Trust security principle is based on the assumption that an attacker may already be inside the network, so no user or device is automatically trusted, regardless of location. This model requires continuous verification for every access request, enforcing strict identity verification and least-privilege access controls at each step. The scenario directly describes the core tenet of Zero Trust: 'never trust, always verify.'
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.