Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium
A security architect is designing a system where access decisions are not based on implicit trust derived from network location or ownership, but instead require continuous verification of every access request. This approach mandates verifying the user, device, and resource every time, assuming breach at all times. Which security framework is being adopted?
- APerimeter Security
- BZero Trust
- CSecurity Information and Event Management (SIEM)
- DDefense in Depth
Show answer & explanationAnswer & explanation
Correct answer: B. Zero Trust
Zero Trust is a security framework that dictates 'never trust, always verify'. It assumes that a breach is inevitable or has already occurred and requires continuous verification of every access request based on user, device, and resource context, regardless of location.
Why the other options are wrong
- A. Perimeter Security focuses on securing the network boundary, which Zero Trust moves beyond.
- C. SIEM is a tool for collecting and analyzing security logs, not a security framework for access decisions.
- D. Defense in Depth is about layering security controls, but doesn't specifically define the 'never trust, always verify' principle for every access request.
Zero Trust
A security model that requires strict identity verification for every person and device trying to access resources on a private network, regardless of whether they are inside or outside the network perimeter.
- Never trust, always verify.
- Assumes breach.
- Focuses on continuous verification based on context.
Memory trick: Zero Trust: 'Don't trust anyone, check everyone, all the time.'