Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard
A manufacturing company is integrating its operational technology (OT) systems with its IT network. They need to implement security measures that assume any entity, whether inside or outside the network perimeter, could be a potential threat. All access requests must be verified explicitly, regardless of origin. Which security model is being adopted?
- ADefense in Depth
- BPerimeter Security
- CZero Trust
- DShared Responsibility Model
Show answer & explanationAnswer & explanation
Correct answer: C. Zero Trust
Zero Trust is a security model that assumes no implicit trust is granted to assets or user accounts based solely on their physical or network location. It requires verification of every access request as if it originated from an untrusted network.
Why the other options are wrong
- A. Defense in Depth is a strategy of layering security controls, but doesn't specifically mandate 'no implicit trust' for all entities like Zero Trust does.
- B. Perimeter Security focuses on securing the network boundary, which is directly contradicted by the 'assume any entity...could be a potential threat' principle.
- D. Shared Responsibility Model defines who is responsible for what in cloud computing, not a security model for verifying all access.
Zero Trust
A security model where no user or device is inherently trusted, regardless of whether they are inside or outside the network perimeter. All access requests are explicitly verified.
- Never trust, always verify.
- Assumes breach.
- Requires explicit verification for every access attempt.
Memory trick: Zero Trust: Verify Everything