Microsoft Security, Compliance, and Identity Fundamentals Zero Trust Security Model Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Zero Trust Security Model flashcards as text
Which Zero Trust signal is evaluated when a user attempts to access a resource from an unfamiliar location?
Answer: User location and IP address
User location and IP address are key signals evaluated in Zero Trust to detect anomalous access patterns and enforce conditional access.
Just-in-time (JIT) access is a Zero Trust practice primarily used to manage which type of accounts?
Answer: Privileged administrator accounts
JIT access grants privileged administrator accounts elevated permissions only when needed and for a limited time, reducing standing access risk.
Which Microsoft Defender product aligns with the Zero Trust 'Endpoints' pillar?
Answer: Microsoft Defender for Endpoint
Microsoft Defender for Endpoint protects devices and provides health signals used to enforce Zero Trust endpoint compliance.
What is the purpose of microsegmentation in a Zero Trust network architecture?
Answer: Isolate workloads to prevent lateral movement
Microsegmentation divides the network into small zones so that even if an attacker gains access, they cannot move laterally to other segments.
Which of the following best describes 'verify explicitly' in Zero Trust?
Answer: Always authenticate and authorize using all available data points
Verify explicitly means always authenticate and authorize based on all available data points including identity, location, device, and behavior.
In Zero Trust, what role does threat intelligence play?
Answer: Informing real-time access decisions based on known attack patterns
Threat intelligence feeds real-time risk assessments, helping Zero Trust systems detect and respond to known malicious actors and techniques.
Which Conditional Access condition helps enforce Zero Trust by requiring users to use approved applications?
Answer: Approved client app requirement
The approved client app requirement in Conditional Access ensures that only Microsoft-approved applications can access cloud resources.