nerdexam
Microsoft

MS-900 · Question #405

A company uses Microsoft cloud services. The company needs to protect against security breaches. You need to follow Microsoft's approach to security. Which approach should you use?

The correct answer is E. Will breach security. Microsoft's Zero Trust security philosophy is built on the 'assume breach' principle, meaning organizations should always operate as if a breach has already occurred or will occur.

Submitted by neha2k· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

A company uses Microsoft cloud services. The company needs to protect against security breaches. You need to follow Microsoft's approach to security. Which approach should you use?

Options

  • AWill never breach security of specific applications
  • BWill never breach the perimeter network
  • CWill never breach security
  • DWill only breach the perimeter network
  • EWill breach security

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    2% (1)
  • D
    14% (6)
  • E
    74% (31)

Why each option

Microsoft's Zero Trust security philosophy is built on the 'assume breach' principle, meaning organizations should always operate as if a breach has already occurred or will occur.

AWill never breach security of specific applications

Claiming security will never be breached for specific applications is unrealistic and contradicts Microsoft's Zero Trust 'assume breach' philosophy, which acknowledges that no application is inherently immune.

BWill never breach the perimeter network

Assuming the perimeter network will never be breached is the old 'castle-and-moat' security model that Microsoft's Zero Trust framework explicitly moves away from.

CWill never breach security

Assuming security will never be breached at any level is a false and dangerous assumption that Zero Trust directly opposes by mandating continuous verification and breach readiness.

DWill only breach the perimeter network

Limiting breach assumptions only to the perimeter network is a partial and outdated approach that ignores internal threats and lateral movement, which Zero Trust's assume breach principle addresses holistically.

EWill breach securityCorrect

Microsoft's security approach follows the 'Assume Breach' principle, one of the three core tenets of Zero Trust (alongside 'Verify Explicitly' and 'Use Least Privilege Access'). By assuming breach, organizations design security controls, monitoring, and response strategies as if attackers are already inside the network, minimizing blast radius and improving detection and response capabilities.

Concept tested: Microsoft Zero Trust assume breach security principle

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/zero-trust

Topics

#Zero Trust#assume breach#security posture#perimeter security

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice