MS-900 · Question #420
Hotspot Question A company is evaluating Zero Trust security principles for Microsoft 365. You need to identify a Zero Trust security principle used in Microsoft 365. Select the answer that…
The correct answer is A Zero Trust security principle that uses segmented access for networks, users, devices, and applications is: least privileged access. The correct Zero Trust security principle for segmented access across networks, users, devices, and applications is 'assume breach', which focuses on minimizing the blast radius in anticipation of potential security incidents.
Question
Exhibit
Answer Area
- A Zero Trust security principle that uses segmented access for networks, users, devices, and applications isleast privileged accessassume breachleast privileged accessverify explicitlyshared responsibility model
Explanation
The correct Zero Trust security principle for segmented access across networks, users, devices, and applications is 'assume breach', which focuses on minimizing the blast radius in anticipation of potential security incidents.
Approach. The correct interaction is to select 'assume breach' from the dropdown list. The Zero Trust principle 'assume breach' dictates that organizations should always act as if an attacker has already compromised their network. To mitigate the impact of such a breach, it's crucial to minimize the 'blast radius' by segmenting access across all facets-networks, users, devices, and applications. This proactive segmentation limits an attacker's lateral movement and the potential damage, directly aligning with the description 'segmented access for networks, users, devices, and applications'.
Common mistakes.
- common_mistake. Selecting any other option would be incorrect. 'Least privileged access' is a Zero Trust principle focusing on granting only the necessary permissions for a user or entity to perform their tasks, not directly on the broader concept of segmented infrastructure. 'Verify explicitly' is another Zero Trust principle emphasizing strong authentication and authorization based on all available data points, rather than network segmentation. The 'shared responsibility model' is a cloud security concept defining the division of security responsibilities between a cloud provider and a customer, and it is not one of the core Zero Trust security principles.
Concept tested. The core concept being tested is an understanding of Microsoft's Zero Trust security principles and their practical application, specifically the 'Assume Breach' principle and its direct correlation to the practice of implementing segmented access.
Reference. https://learn.microsoft.com/en-us/security/zero-trust/understand/zero-trust-overview
Topics
Community Discussion
No community discussion yet for this question.
