Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityEasy
A company is implementing a new security framework that assumes every user, device, and application is potentially hostile, regardless of its location (inside or outside the network perimeter). Access decisions are made based on verifying identity, device health, and least privilege for every request. Which security model are they adopting?
- ADefense in Depth
- BPerimeter Security
- CTrust but Verify
- DZero Trust
Show answer & explanationAnswer & explanation
Correct answer: D. Zero Trust
The Zero Trust model operates on the principle of 'never trust, always verify,' meaning that no user, device, or application is inherently trusted, and access must be explicitly granted and continuously validated.
Why the other options are wrong
- A. Defense in Depth is a strategy of using multiple layers of security, which can include Zero Trust, but isn't the specific model described.
- B. Perimeter Security focuses on securing the network boundary, which Zero Trust moves beyond.
- C. Trust but Verify implies an initial trust, which is contrary to the 'potentially hostile' assumption of the scenario.
Zero Trust
Zero Trust is a security model that requires strict identity verification for every person and device trying to access resources on a private network, regardless of whether they are inside or outside the network perimeter.
- Never trust, always verify.
- Assumes breach.
- Micro-segmentation and least privilege are key tenets.
Memory trick: Zero Trust means everyone must prove themselves.