nerdexam
Microsoft

MS-900 · Question #420

Hotspot Question A company is evaluating Zero Trust security principles for Microsoft 365. You need to identify a Zero Trust security principle used in Microsoft 365. Select the answer that…

The correct answer is A Zero Trust security principle that uses segmented access for networks, users, devices, and applications is: least privileged access. The correct Zero Trust security principle for segmented access across networks, users, devices, and applications is 'assume breach', which focuses on minimizing the blast radius in anticipation of potential security incidents.

Submitted by klara.se· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

Hotspot Question A company is evaluating Zero Trust security principles for Microsoft 365. You need to identify a Zero Trust security principle used in Microsoft 365. Select the answer that correctly completes the sentence. Answer:

Exhibit

MS-900 question #420 exhibit

Answer Area

  • A Zero Trust security principle that uses segmented access for networks, users, devices, and applications isleast privileged access
    assume breachleast privileged accessverify explicitlyshared responsibility model

Explanation

The correct Zero Trust security principle for segmented access across networks, users, devices, and applications is 'assume breach', which focuses on minimizing the blast radius in anticipation of potential security incidents.

Approach. The correct interaction is to select 'assume breach' from the dropdown list. The Zero Trust principle 'assume breach' dictates that organizations should always act as if an attacker has already compromised their network. To mitigate the impact of such a breach, it's crucial to minimize the 'blast radius' by segmenting access across all facets-networks, users, devices, and applications. This proactive segmentation limits an attacker's lateral movement and the potential damage, directly aligning with the description 'segmented access for networks, users, devices, and applications'.

Common mistakes.

  • common_mistake. Selecting any other option would be incorrect. 'Least privileged access' is a Zero Trust principle focusing on granting only the necessary permissions for a user or entity to perform their tasks, not directly on the broader concept of segmented infrastructure. 'Verify explicitly' is another Zero Trust principle emphasizing strong authentication and authorization based on all available data points, rather than network segmentation. The 'shared responsibility model' is a cloud security concept defining the division of security responsibilities between a cloud provider and a customer, and it is not one of the core Zero Trust security principles.

Concept tested. The core concept being tested is an understanding of Microsoft's Zero Trust security principles and their practical application, specifically the 'Assume Breach' principle and its direct correlation to the practice of implementing segmented access.

Reference. https://learn.microsoft.com/en-us/security/zero-trust/understand/zero-trust-overview

Topics

#Zero Trust#least privileged access#network segmentation#security principles

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice