Microsoft Security, Compliance, and Identity Fundamentals Zero Trust Security Model Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Zero Trust Security Model flashcards as text
Which Zero Trust guiding principle states that access should be limited to only what is needed to perform a task?
Answer: Use least privilege access
The 'Use least privilege access' principle limits user access with just-in-time and just-enough-access policies to minimize exposure.
In Zero Trust, what does 'assume breach' mean for network design?
Answer: Segment networks to contain blast radius
Assuming breach means designing networks with segmentation so that if one area is compromised, attackers cannot move freely to other areas.
Which Microsoft service helps implement Zero Trust by providing conditional access policies?
Answer: Microsoft Entra ID (Azure AD)
Microsoft Entra ID provides Conditional Access policies that enforce Zero Trust by evaluating signals before granting access.
Zero Trust replaces which traditional security model?
Answer: Castle-and-moat (perimeter-based) model
Zero Trust replaces the castle-and-moat model where everything inside the network perimeter was trusted by default.
Which pillar of Zero Trust focuses on protecting data through classification and encryption?
Answer: Data
The Data pillar in Zero Trust focuses on classifying, labeling, and encrypting data and controlling access based on data sensitivity.
What technology enables Zero Trust by continuously verifying device health before granting access?
Answer: Device compliance policies
Device compliance policies assess device health, OS version, and configuration to ensure only healthy devices can access resources.
In the Zero Trust model, how should applications be treated regardless of where they are hosted?
Answer: Verify every app request as if it comes from an untrusted network
Zero Trust treats all applications as untrusted and requires verification of every request regardless of the hosting location.