Microsoft Security, Compliance, and Identity Fundamentals Zero Trust Security Model Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Zero Trust Security Model flashcards as text
Which Zero Trust pillar is addressed when implementing Azure Private Link to restrict access to Azure services?
Answer: Networks
Azure Private Link restricts Azure service access to private network connections, directly supporting the Zero Trust Networks pillar.
Multi-factor authentication (MFA) is a core Zero Trust control that primarily strengthens which pillar?
Answer: Identities
MFA strengthens the Identities pillar by adding additional verification factors beyond passwords, reducing the risk of compromised credentials.
What does Zero Trust mean by 'never trust, always verify'?
Answer: No user or device is trusted automatically, even on the internal network
Zero Trust's 'never trust, always verify' means that trust is never implicit—every access request must be authenticated and authorized regardless of origin.
Which feature in Microsoft Entra ID provides risk-based Zero Trust enforcement by detecting suspicious sign-in behaviors?
Answer: Identity Protection
Microsoft Entra ID Protection uses machine learning to detect risky sign-ins and users, triggering step-up authentication or access blocks.
How does Zero Trust handle east-west traffic (traffic between internal servers)?
Answer: Inspects and controls it the same as north-south traffic
Zero Trust treats east-west (lateral) traffic with the same scrutiny as north-south traffic because threats can originate from inside the network.
Which Microsoft solution helps organizations visualize their Zero Trust posture and track improvement across all six pillars?
Answer: Microsoft Secure Score
Microsoft Secure Score tracks an organization's security posture and provides recommended actions aligned to Zero Trust principles across all pillars.
In Zero Trust architecture, what is the primary purpose of session controls?
Answer: Monitor and limit what users can do during an active session
Session controls in Zero Trust limit what authenticated users can do during a session, such as blocking downloads or requiring re-authentication for sensitive actions.