SC-900 Practice Test 16 Hard Questions

SC-900 Exam Practice Test 16 (Hard) - Zero Trust and Shared Responsibility Deep-Dive

SC-900 Exam Practice Tests

1 / 15

Which of the three guiding principles of Zero Trust involves basing access decisions on all available data points, such as user identity, location, and device health, rather than assumed trust?

2 / 15

Which of the three guiding principles of Zero Trust involves assuming that a breach has already occurred or could occur, and designing systems to minimize the blast radius of an incident?

3 / 15

Which of the three guiding principles of Zero Trust involves limiting user access with just-in-time and just-enough-access (JIT/JEA), and risk-based adaptive policies?

4 / 15

Which Zero Trust pillar focuses on verifying and securing identities, whether they represent people, services, or IoT devices, before granting access to resources?

5 / 15

Which Zero Trust pillar focuses on monitoring and enforcing device health and compliance before allowing access to organizational data and applications?

6 / 15

Which Zero Trust pillar focuses on discovering shadow IT, ensuring appropriate in-app permissions, and gating access based on real-time analytics?

7 / 15

Which Zero Trust pillar focuses on segmenting networks and using real-time threat protection, end-to-end encryption, and monitoring to limit lateral movement by an attacker?

8 / 15

Which Zero Trust pillar focuses on classifying, labeling, and encrypting data, and restricting access based on organizational policies?

9 / 15

Under the shared responsibility model, in an on-premises deployment, who is responsible for physical security of the data center?

10 / 15

Under the shared responsibility model for an IaaS deployment, who is typically responsible for patching the guest operating system running inside a virtual machine?

11 / 15

Which Zero Trust concept refers to continuously validating trust for every access request, rather than granting a one-time trust decision that persists indefinitely?

12 / 15

Which term describes an organization's overall approach and framework for how it identifies, assesses, and manages risk to its information assets?

13 / 15

Which term refers to the overall discipline of protecting an organization's systems, networks, and data from digital attacks?

14 / 15

Which term describes an individual's right to control how their personal information is collected, used, and shared?

15 / 15

Which term describes a formalized, independent examination of an organization's controls and processes to verify they meet a specific standard or regulation?

Your score is

The average score is 0%

0%