In a design review a colleague argues that requests arriving from inside the corporate network can skip verification, because the perimeter already vetted whoever sent them. How does a Zero Trust approach answer that?
Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
The options
Correct Every request is verified explicitly wherever it comes from, granted only the privilege it needs, and handled on the assumption that some part of the environment may already be compromised
Correct. Those are the three principles — verify explicitly, least privilege, assume breach — and together they remove network location as a reason to trust anything.
Not correct Zero Trust agrees: the internal network is the trusted zone, which is why the perimeter firewall is the primary control
Wrong, and it describes the model Zero Trust was created to replace. A single hard perimeter means anything that gets inside, or starts inside, can move freely.
Not correct Zero Trust means no user is granted access to anything without an administrator approving each request
Wrong. The zero refers to implicit trust, not to access. People are granted access continually — explicitly verified, scoped to what they need, and time-bound where the privilege is high.
Not correct Zero Trust is a product you enable in the portal
Wrong. It is a security model that shapes how you configure identity, devices, networks, applications and data across many services. Nothing switches it on.
Why
Zero Trust replaces the assumption that a location implies trust with three working rules: verify explicitly using every signal available, grant the least privilege necessary and only for as long as necessary, and assume breach so that segmentation, monitoring and encryption limit what a foothold is worth. Read a scenario for the phrase that gives trust away for free — 'it came from inside the network' — and that is the sentence Zero Trust deletes.
Where this comes from
- Cited
- Microsoft AZ-900 study guide skill area architecture-and-services.identity-access-security
Practise this
Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.
Practise Microsoft Certified: Azure Fundamentals (AZ-900)
More questions on this objective
- An image-resizing routine runs for about two seconds whenever a file lands in a storage container — perhaps two hundred times on a busy day, and not at all on a quiet one. The team wants to pay for the work done and maintain no servers. Which compute option fits? machine-checked
- A fifteen-year-old accounting application needs a kernel-level driver, a scheduled task that edits the registry, and a runtime version nobody supports any more. The business wants it running in Azure this quarter with as few code changes as possible. Where does it go? machine-checked
- A team runs nine small services, each with its own conflicting library versions. They want each one packaged with its dependencies, starting in seconds, several to a host, without a separate operating system per service. Which compute type are they describing? machine-checked
- Which TWO of these statements about Azure compute types are true? machine-checked
- A public website runs on four identical virtual machines behind a load balancer. Traffic triples while a television advert airs and falls back an hour later. The team wants instances added and removed automatically against CPU, all built from one image, with nobody clicking. Which option is designed for that? machine-checked
- Three virtual machines form a quorum-based cluster in a region that has no availability zones. You want them placed so that neither a single rack losing power nor a single batch of planned host maintenance can take all three at once. What do you configure? machine-checked