Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard

A global enterprise is implementing a new security framework. They want to achieve a state where, even if an attacker manages to compromise a single component or system, the impact of that breach is contained and does not lead to a widespread compromise of their entire network. This approach emphasizes limiting the blast radius of any potential security incident. Which security concept does this strategy represent?

  1. ALeast Privilege
  2. BDefense in Depth
  3. CZero Trust
  4. DShared Responsibility Model
Show answer & explanation

Correct answer: C. Zero Trust

Zero Trust is a security model that operates on the principle of 'never trust, always verify'. It assumes that a breach is inevitable or has already occurred and therefore explicitly verifies every access request, regardless of where it originates. A key tenet is micro-segmentation and limiting the 'blast radius' of any compromise, aligning perfectly with the goal of containing breaches to prevent widespread impact.

Why the other options are wrong

  • A. Least Privilege grants minimal necessary permissions, which is a component of Zero Trust but not the overarching strategy described.
  • B. Defense in Depth uses multiple layers of security, but Zero Trust specifically focuses on limiting damage *after* a potential breach.
  • D. The Shared Responsibility Model defines security duties between cloud providers and customers, not an internal security strategy for limiting breach impact.

Zero Trust

A security model that assumes no implicit trust is granted to assets or user accounts based solely on their physical or network location; instead, trust is verified continuously.

  • Never trust, always verify.
  • Assumes breach is inevitable.
  • Focuses on micro-segmentation and least privilege to limit blast radius.
  • Verifies every access request.

Memory trick: Zero Trust: No Trust, Just Verify.

More Describe the concepts of security, compliance, and identity questions