Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureEasy
A large healthcare organization is designing a Zero Trust architecture for its patient data systems. The organization needs to ensure that access to sensitive patient records is granted only after evaluating the user's identity, device health, location, and the sensitivity of the data being accessed. Which core principle of Zero Trust does this scenario primarily emphasize?
- AEnd-to-End Encryption
- BUse Least Privilege Access
- CAssume Breach
- DVerify Explicitly
Show answer & explanationAnswer & explanation
Correct answer: D. Verify Explicitly
The scenario describes a process of rigorously checking multiple attributes (user, device, location, data sensitivity) before granting access, which directly aligns with the 'Verify Explicitly' principle of Zero Trust.
Why the other options are wrong
- A. End-to-End Encryption protects data in transit and at rest, but doesn't dictate the access decision logic.
- B. Use Least Privilege Access focuses on granting only the necessary permissions once access is approved, not the initial verification.
- C. Assume Breach is about preparing for and minimizing damage from security incidents, not the access decision process itself.
Verify Explicitly
A core Zero Trust principle requiring all access requests to be authenticated and authorized based on all available data points, including user identity, location, device health, service or workload, data classification, and anomalies.
- Always authenticate and authorize
- Based on all available data points
- Context-aware access decisions
Memory trick: Always Be Checking Everything (ABCE) before granting access.