Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityMedium

A security team is implementing a new framework where every access request, regardless of whether it originates from inside or outside the network, is explicitly verified. They assume that no user or device can be inherently trusted, and access is granted only after strict validation of identity, device health, and other contextual factors. Which security model are they adopting?

  1. APerimeter Security
  2. BDefense in Depth
  3. CZero Trust
  4. DShared Responsibility Model
Show answer & explanation

Correct answer: C. Zero Trust

The Zero Trust security model operates on the principle of 'never trust, always verify,' meaning no user or device is inherently trusted, and all access requests are strictly authenticated and authorized.

Why the other options are wrong

  • A. Perimeter Security focuses on securing the network boundary, assuming internal users are trusted.
  • B. Defense in Depth involves multiple layers of security, but Zero Trust specifically focuses on continuous verification and explicit trust.
  • D. The Shared Responsibility Model defines security duties between cloud providers and customers, not an operational security model.

Zero Trust

A security model that dictates that no user, device, or application should be trusted by default, regardless of whether they are inside or outside the network perimeter.

  • 'Never trust, always verify' is its core principle.
  • Requires explicit verification for every access request.
  • Considers identity, device, location, and data sensitivity.

Memory trick: Zero Trust: Never trust, always verify.

More Describe the concepts of security, compliance, and identity questions