Microsoft Cybersecurity Architect (SC-100)Design a Zero Trust strategy and architectureMedium

A global financial services company is designing a Zero Trust architecture for its critical applications and data. They need to ensure that access decisions are made in real-time, considering user behavior, device posture, and environmental factors, and that these decisions can adapt dynamically to changing conditions. Which Zero Trust principle is MOST directly addressed by this requirement?

  1. AAssume Breach
  2. BVerify Explicitly
  3. CUse Least Privilege Access
  4. DEmploy End-to-End Encryption
Show answer & explanation

Correct answer: B. Verify Explicitly

Verify Explicitly is the Zero Trust principle that mandates all access requests are authenticated and authorized based on all available data points, rather than assuming trust. This includes real-time evaluation of user identity, device health, location, and other contextual factors to make dynamic access decisions.

Why the other options are wrong

  • A. Assume Breach focuses on minimizing blast radius and segmenting access, not primarily on dynamic real-time access decisions.
  • C. Use Least Privilege Access ensures users only have the permissions needed for their task, but doesn't specifically cover the dynamic, real-time evaluation of access conditions.
  • D. Employ End-to-End Encryption protects data in transit and at rest, but is not directly about the dynamic decision-making process for granting access.

Verify Explicitly (Zero Trust)

A core Zero Trust principle requiring all access requests to be authenticated and authorized based on all available data points, not just assumed trust.

  • Never trust, always verify.
  • Considers user identity, device posture, location, service, workload, data classification, and anomalies.
  • Access decisions are dynamic and policy-driven.

Memory trick: Always Verify Every User's Device and Access, Assuming Breach.

More Design a Zero Trust strategy and architecture questions