← All SC-900 Flashcard Decks

Microsoft Security, Compliance, and Identity Fundamentals Zero Trust Security Model Flashcards

7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Zero Trust Security Model flashcards as text
  1. Which Zero Trust pillar is addressed when implementing Azure Private Link to restrict access to Azure services?

    Answer: Networks

    Azure Private Link restricts Azure service access to private network connections, directly supporting the Zero Trust Networks pillar.

  2. Multi-factor authentication (MFA) is a core Zero Trust control that primarily strengthens which pillar?

    Answer: Identities

    MFA strengthens the Identities pillar by adding additional verification factors beyond passwords, reducing the risk of compromised credentials.

  3. What does Zero Trust mean by 'never trust, always verify'?

    Answer: No user or device is trusted automatically, even on the internal network

    Zero Trust's 'never trust, always verify' means that trust is never implicit—every access request must be authenticated and authorized regardless of origin.

  4. Which feature in Microsoft Entra ID provides risk-based Zero Trust enforcement by detecting suspicious sign-in behaviors?

    Answer: Identity Protection

    Microsoft Entra ID Protection uses machine learning to detect risky sign-ins and users, triggering step-up authentication or access blocks.

  5. How does Zero Trust handle east-west traffic (traffic between internal servers)?

    Answer: Inspects and controls it the same as north-south traffic

    Zero Trust treats east-west (lateral) traffic with the same scrutiny as north-south traffic because threats can originate from inside the network.

  6. Which Microsoft solution helps organizations visualize their Zero Trust posture and track improvement across all six pillars?

    Answer: Microsoft Secure Score

    Microsoft Secure Score tracks an organization's security posture and provides recommended actions aligned to Zero Trust principles across all pillars.

  7. In Zero Trust architecture, what is the primary purpose of session controls?

    Answer: Monitor and limit what users can do during an active session

    Session controls in Zero Trust limit what authenticated users can do during a session, such as blocking downloads or requiring re-authentication for sensitive actions.