Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium

A large multinational corporation is designing a Zero Trust architecture for its global operations. The company has a significant number of legacy applications hosted on-premises and a growing number of cloud-native applications in Azure and AWS. Employees access resources from various locations, including corporate offices, remote work environments, and untrusted networks. The security architect needs to ensure that access decisions are made dynamically based on user identity, device health, location, and resource sensitivity, regardless of where the user or resource is located. Which core principle of Zero Trust is MOST critical to address this requirement?

  1. AAssume breach
  2. BUse least privilege access
  3. CVerify explicitly
  4. DEnd-to-end encryption
Show answer & explanation

Correct answer: C. Verify explicitly

The scenario emphasizes dynamic access decisions based on multiple attributes like user identity, device health, and location. 'Verify explicitly' directly addresses this need by ensuring all access requests are authenticated and authorized rigorously.

Why the other options are wrong

  • A. Assume breach is a core principle but focuses on minimizing blast radius and improving incident response, not dynamic access decisions.
  • B. Use least privilege access ensures users only have necessary permissions but doesn't cover the dynamic verification of the access request itself.
  • D. End-to-end encryption is a security control for data in transit and at rest, not a core principle for dynamic access decision-making.

Verify Explicitly (Zero Trust)

A core Zero Trust principle requiring all access requests to be authenticated and authorized based on all available data points, rather than implicit trust.

  • No implicit trust is granted.
  • Authentication and authorization are continuous.
  • Considers user identity, device health, location, data sensitivity, and anomaly detection.

Memory trick: Always Be Explicitly Least Privileged, Assuming Breach.

More Design a Zero Trust strategy and architecture questions