MS-900 · Question #381
Drag and Drop Question A company uses Microsoft 365. The company is evaluating which Zero Trust security policies to implement. Which Zero Trust security principle should you recommend? To answer, dra
The correct answer is Verify explicitly; Least privileged access; Assume breach. The three core Zero Trust principles are 'Verify explicitly' (always authenticate and authorize based on all available data points), 'Least privileged access' (limit user access with just-in-time and just-enough-access), and 'Assume breach' (minimize blast radius, segment access,
Question
Exhibit
Answer Area
Drag items
Correct arrangement
- Verify explicitly
- Least privileged access
- Assume breach
Explanation
The three core Zero Trust principles are 'Verify explicitly' (always authenticate and authorize based on all available data points), 'Least privileged access' (limit user access with just-in-time and just-enough-access), and 'Assume breach' (minimize blast radius, segment access, and assume the network is already compromised). These are the foundational pillars defined by Microsoft's Zero Trust framework and map directly to specific security requirements such as identity verification, access control, and breach containment strategies. 'Threat protection' is not one of the three official Zero Trust principles - it is a security capability or solution category rather than a guiding Zero Trust principle.
Topics
Community Discussion
No community discussion yet for this question.
