Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A company is implementing a new security framework that assumes every user, device, and application attempting to access resources, whether internal or external, is untrusted until proven otherwise. This framework mandates strict verification regardless of location or previous authentication. Which security concept is this company adopting?

  1. ASecurity by Obscurity
  2. BDefense in Depth
  3. CPerimeter Security
  4. DZero Trust
Show answer & explanation

Correct answer: D. Zero Trust

Zero Trust is a security model that operates on the principle of 'never trust, always verify.' It requires strict identity verification for every access request, regardless of whether the entity is inside or outside the network perimeter.

Why the other options are wrong

  • A. Security by Obscurity relies on hiding vulnerabilities, which is an ineffective and discouraged practice.
  • B. Defense in Depth uses multiple security layers, which can incorporate Zero Trust but isn't the core concept described.
  • C. Perimeter Security focuses on securing the network boundary, which Zero Trust moves beyond.

Zero Trust

A security model that requires strict identity verification for every person and device trying to access resources on a private network, regardless of whether they are inside or outside the network perimeter. It operates on the principle of 'never trust, always verify'.

  • Assumes breach and verifies every access.
  • Reduces attack surface and lateral movement.
  • Applies to users, devices, applications, and data.

Memory trick: Zero Trust: Trust NO ONE, verify EVERYONE, ALWAYS.

More Describe the concepts of security, compliance, and identity questions