SC-900 Microsoft Security, Compliance, and Identity Fundamentals Zero Trust Security Model 3 β Questions and Answers
Question 1: Which Zero Trust signal is evaluated when a user attempts to access a resource from an unfamiliar location?
- Device encryption status
- User location and IP address (Correct answer)
- Application version
- Storage capacity
Correct answer: User location and IP address
User location and IP address are key signals evaluated in Zero Trust to detect anomalous access patterns and enforce conditional access.
Question 2: Just-in-time (JIT) access is a Zero Trust practice primarily used to manage which type of accounts?
- Guest user accounts
- Privileged administrator accounts (Correct answer)
- Service accounts
- External partner accounts
Correct answer: Privileged administrator accounts
JIT access grants privileged administrator accounts elevated permissions only when needed and for a limited time, reducing standing access risk.
Question 3: Which Microsoft Defender product aligns with the Zero Trust 'Endpoints' pillar?
- Microsoft Defender for Cloud Apps
- Microsoft Defender for Endpoint (Correct answer)
- Microsoft Defender for Office 365
- Microsoft Defender for Identity
Correct answer: Microsoft Defender for Endpoint
Microsoft Defender for Endpoint protects devices and provides health signals used to enforce Zero Trust endpoint compliance.
Question 4: What is the purpose of microsegmentation in a Zero Trust network architecture?
- Speed up network traffic routing
- Isolate workloads to prevent lateral movement (Correct answer)
- Combine all VLANs into one
- Replace firewalls entirely
Correct answer: Isolate workloads to prevent lateral movement
Microsegmentation divides the network into small zones so that even if an attacker gains access, they cannot move laterally to other segments.
Question 5: Which of the following best describes 'verify explicitly' in Zero Trust?
- Trust users after first authentication
- Always authenticate and authorize using all available data points (Correct answer)
- Use only username and password for verification
- Verify only external users
Correct answer: Always authenticate and authorize using all available data points
Verify explicitly means always authenticate and authorize based on all available data points including identity, location, device, and behavior.
Question 6: In Zero Trust, what role does threat intelligence play?
- Replacing firewalls with AI systems
- Informing real-time access decisions based on known attack patterns (Correct answer)
- Storing user credentials securely
- Managing software licenses
Correct answer: Informing real-time access decisions based on known attack patterns
Threat intelligence feeds real-time risk assessments, helping Zero Trust systems detect and respond to known malicious actors and techniques.
Question 7: Which Conditional Access condition helps enforce Zero Trust by requiring users to use approved applications?
- Sign-in risk policy
- Approved client app requirement (Correct answer)
- Terms of use policy
- Named location policy
Correct answer: Approved client app requirement
The approved client app requirement in Conditional Access ensures that only Microsoft-approved applications can access cloud resources.
Which Zero Trust signal is evaluated when a user attempts to access a resource from an unfamiliar location?