Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureEasy
A large multinational corporation is designing a Zero Trust strategy for its geographically dispersed workforce. The security architects need to ensure that access to internal resources is granted only after evaluating all available signals, including user identity, device health, location, and behavior patterns. Which core principle of Zero Trust is most directly addressed by this requirement?
- AVerify Explicitly
- BUse Least Privilege Access
- CAssume Breach
- DEnd-to-End Encryption
Show answer & explanationAnswer & explanation
Correct answer: A. Verify Explicitly
Verify Explicitly is a core Zero Trust principle that mandates all access attempts are authenticated and authorized based on all available data points, not just user credentials. This aligns with evaluating user, device, location, and behavior patterns.
Why the other options are wrong
- B. Use Least Privilege Access focuses on granting only the necessary permissions for a task, not the initial verification process.
- C. Assume Breach is about preparing for and minimizing the impact of a security incident, not access evaluation.
- D. End-to-End Encryption is a data protection mechanism, not a principle for access evaluation.
Verify Explicitly
A core Zero Trust principle requiring all access requests to be authenticated and authorized based on all available data points, rather than implicit trust.
- No implicit trust is granted.
- Evaluates user, device, location, data sensitivity, and other attributes.
- Forms the basis for dynamic access policies.
Memory trick: Trust No One, Verify Everyone, Grant Least.