Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard
A security team is implementing a new framework where every access request, regardless of whether it originates from inside or outside the network, is explicitly verified. This includes verifying user identity, device health, and the context of the access attempt before granting least-privilege access. Which security framework are they adopting?
- APerimeter Security
- BDefense in Depth
- CZero Trust
- DBring Your Own Device (BYOD)
Show answer & explanationAnswer & explanation
Correct answer: C. Zero Trust
Zero Trust is a security model based on the principle of 'never trust, always verify.' It requires all users, devices, and applications to be authenticated and authorized before granting access, regardless of their location, and applies least privilege access.
Why the other options are wrong
- A. Perimeter Security focuses on securing the network boundary, assuming internal trust, which contradicts the 'never trust' principle.
- B. Defense in Depth is a strategy of layering security controls, but doesn't specifically define the 'never trust' philosophy of Zero Trust.
- D. BYOD is a policy allowing personal devices, not a comprehensive security framework for access verification.
Zero Trust
A security model that assumes no implicit trust is granted to assets or user accounts based solely on their physical or network location. Instead, every access request is explicitly verified.
- Principle: Never trust, always verify.
- Verifies identity, device, and context for every access.
- Emphasizes least privilege access.
Memory trick: Zero Trust: No one is trusted, verify all