Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityEasy

A security team is implementing a new framework where every access request, regardless of whether it originates from inside or outside the network, must be explicitly verified. This verification includes evaluating user identity, device compliance, and the sensitivity of the resource being accessed before granting least-privilege access. Which security model is being adopted?

  1. ADefense in Depth
  2. BPerimeter-based Security
  3. CShared Responsibility Model
  4. DZero Trust
Show answer & explanation

Correct answer: D. Zero Trust

The Zero Trust security model operates on the principle of 'never trust, always verify,' requiring explicit verification for every access request, regardless of origin, and granting least-privilege access based on multiple factors.

Why the other options are wrong

  • A. Defense in Depth is a strategy using multiple layers of security, not a specific model for access verification.
  • B. Perimeter-based Security relies on securing the network boundary, which Zero Trust explicitly moves beyond.
  • C. The Shared Responsibility Model defines security duties in cloud computing but is not an access control framework.

Zero Trust

Zero Trust is a security model that requires strict identity verification for every person and device trying to access resources on a private network, regardless of whether they are inside or outside the network perimeter.

  • Never trust, always verify.
  • Assumes breach.
  • Micro-segmentation and least privilege are key tenets.

Memory trick: Zero Trust: No free passes, prove it every time.

More Describe the concepts of security, compliance, and identity questions