SC-900 Microsoft Security, Compliance, and Identity Fundamentals Zero Trust Security Model 5 — Questions and Answers
Question 1: Which of the following is a Zero Trust Infrastructure pillar control?
- Labeling sensitive emails
- Assessing the configuration and behavior of cloud workloads (Correct answer)
- Blocking personal devices from Wi-Fi
- Restricting app marketplace purchases
Correct answer: Assessing the configuration and behavior of cloud workloads
The Infrastructure pillar focuses on assessing the security posture of servers, VMs, containers, and cloud workloads to detect and respond to threats.
Question 2: Why is encryption considered essential to Zero Trust data protection?
- It removes the need for access controls
- It ensures data remains protected even if it is accessed without authorization (Correct answer)
- It speeds up data transfer between services
- It replaces the need for backups
Correct answer: It ensures data remains protected even if it is accessed without authorization
Encryption ensures that even if data is accessed by unauthorized parties, it cannot be read, which is a key data protection control in Zero Trust.
Question 3: What is the relationship between Zero Trust and the shared responsibility model in cloud computing?
- They are the same model with different names
- Zero Trust provides the security strategy customers apply within their shared responsibility scope (Correct answer)
- The shared responsibility model replaces Zero Trust in cloud environments
- Zero Trust only applies to on-premises environments
Correct answer: Zero Trust provides the security strategy customers apply within their shared responsibility scope
Zero Trust is the security strategy organizations apply to fulfill their side of the shared responsibility model in cloud environments.
Question 4: Which action aligns with the Zero Trust principle of 'use least privilege access' for an HR employee?
- Grant full read/write access to all company databases
- Grant access only to the HR database required for their role (Correct answer)
- Provide global administrator rights for convenience
- Allow access to all systems when working remotely
Correct answer: Grant access only to the HR database required for their role
Granting an HR employee access only to the HR database they need aligns with least privilege by limiting permissions to role-specific resources.
Question 5: How does Zero Trust address shadow IT (unauthorized cloud apps used by employees)?
- Ignores shadow IT since it is outside the network perimeter
- Uses cloud app discovery and access controls to manage and restrict unsanctioned apps (Correct answer)
- Blocks all internet traffic to prevent shadow IT
- Approves all apps requested by employees automatically
Correct answer: Uses cloud app discovery and access controls to manage and restrict unsanctioned apps
Zero Trust addresses shadow IT through cloud app discovery tools like Microsoft Defender for Cloud Apps to identify and control unsanctioned application usage.
Question 6: What does continuous access evaluation (CAE) add to the Zero Trust model?
- It evaluates access only at sign-in time
- It revokes active sessions in near real-time when risk conditions change (Correct answer)
- It automatically creates new user accounts
- It replaces MFA requirements
Correct answer: It revokes active sessions in near real-time when risk conditions change
Continuous Access Evaluation allows Microsoft Entra ID to revoke access tokens in near real-time when events like account deletion or policy changes occur.
Question 7: Which of the following scenarios best illustrates the Zero Trust 'assume breach' principle?
- Trusting all traffic from headquarters IP addresses
- Deploying endpoint detection and response tools to monitor for threats inside the network (Correct answer)
- Removing firewalls once MFA is implemented
- Only monitoring external-facing web servers
Correct answer: Deploying endpoint detection and response tools to monitor for threats inside the network
Deploying EDR tools inside the network reflects 'assume breach' by monitoring for threats that may already be present within the environment.
Which of the following is a Zero Trust Infrastructure pillar control?