nerdexam
Microsoft

MS-900 · Question #381

Drag and Drop Question A company uses Microsoft 365. The company is evaluating which Zero Trust security policies to implement. Which Zero Trust security principle should you recommend? To answer, dra

The correct answer is Verify explicitly; Least privileged access; Assume breach. The three core Zero Trust principles are 'Verify explicitly' (always authenticate and authorize based on all available data points), 'Least privileged access' (limit user access with just-in-time and just-enough-access), and 'Assume breach' (minimize blast radius, segment access,

Submitted by haruto_sh· Mar 5, 2026Describe security, compliance, identity, and management capabilities of Microsoft 365 - specifically the concepts and principles of Zero Trust security (MS-900 / SC-900)

Question

Drag and Drop Question A company uses Microsoft 365. The company is evaluating which Zero Trust security policies to implement. Which Zero Trust security principle should you recommend? To answer, drag the appropriate principles to the correct requirements. Each principle may be used once. more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point. Answer:

Exhibit

MS-900 question #381 exhibit

Answer Area

Drag items

Verify explicitlyLeast privileged accessAssume breachThreat protection

Correct arrangement

  • Verify explicitly
  • Least privileged access
  • Assume breach

Explanation

The three core Zero Trust principles are 'Verify explicitly' (always authenticate and authorize based on all available data points), 'Least privileged access' (limit user access with just-in-time and just-enough-access), and 'Assume breach' (minimize blast radius, segment access, and assume the network is already compromised). These are the foundational pillars defined by Microsoft's Zero Trust framework and map directly to specific security requirements such as identity verification, access control, and breach containment strategies. 'Threat protection' is not one of the three official Zero Trust principles - it is a security capability or solution category rather than a guiding Zero Trust principle.

Topics

#Zero Trust#Microsoft 365 Security#Identity and Access Management#Security Principles

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice