Microsoft Security, Compliance, and Identity Fundamentals Zero Trust Security Model Flashcards
7 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Microsoft Security, Compliance, and Identity Fundamentals Zero Trust Security Model flashcards as text
Which of the following is a Zero Trust Infrastructure pillar control?
Answer: Assessing the configuration and behavior of cloud workloads
The Infrastructure pillar focuses on assessing the security posture of servers, VMs, containers, and cloud workloads to detect and respond to threats.
Why is encryption considered essential to Zero Trust data protection?
Answer: It ensures data remains protected even if it is accessed without authorization
Encryption ensures that even if data is accessed by unauthorized parties, it cannot be read, which is a key data protection control in Zero Trust.
What is the relationship between Zero Trust and the shared responsibility model in cloud computing?
Answer: Zero Trust provides the security strategy customers apply within their shared responsibility scope
Zero Trust is the security strategy organizations apply to fulfill their side of the shared responsibility model in cloud environments.
Which action aligns with the Zero Trust principle of 'use least privilege access' for an HR employee?
Answer: Grant access only to the HR database required for their role
Granting an HR employee access only to the HR database they need aligns with least privilege by limiting permissions to role-specific resources.
How does Zero Trust address shadow IT (unauthorized cloud apps used by employees)?
Answer: Uses cloud app discovery and access controls to manage and restrict unsanctioned apps
Zero Trust addresses shadow IT through cloud app discovery tools like Microsoft Defender for Cloud Apps to identify and control unsanctioned application usage.
What does continuous access evaluation (CAE) add to the Zero Trust model?
Answer: It revokes active sessions in near real-time when risk conditions change
Continuous Access Evaluation allows Microsoft Entra ID to revoke access tokens in near real-time when events like account deletion or policy changes occur.
Which of the following scenarios best illustrates the Zero Trust 'assume breach' principle?
Answer: Deploying endpoint detection and response tools to monitor for threats inside the network
Deploying EDR tools inside the network reflects 'assume breach' by monitoring for threats that may already be present within the environment.