Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A company is redesigning its network architecture with the principle that no user, device, or application should be trusted by default, regardless of whether it is inside or outside the network perimeter. Every access request must be verified. Which security model are they adopting?

  1. ADefense in Depth
  2. BPerimeter Security
  3. CLeast Privilege
  4. DZero Trust
Show answer & explanation

Correct answer: D. Zero Trust

Zero Trust is a security model that requires strict identity verification for every person and device trying to access resources on a private network, regardless of whether they are inside or outside the network perimeter. It operates on the principle of 'never trust, always verify'.

Why the other options are wrong

  • A. Defense in Depth is a strategy of layering multiple security controls, not a specific trust model.
  • B. Perimeter security focuses on protecting the network edge, which is contrary to 'no trust by default'.
  • C. Least Privilege grants only necessary access, which is a component of Zero Trust but not the overarching model described.

Zero Trust

A security model that requires strict identity verification for every person and device trying to access resources on a private network, regardless of whether they are inside or outside the network perimeter.

  • Operates on the principle 'never trust, always verify'.
  • Assumes breach is inevitable and continuously verifies.
  • Applies to all users, devices, applications, and data.

Memory trick: Zero Trust: No one gets a free pass.

More Describe the concepts of security, compliance, and identity questions