SC-100 Practice Question 3887
Exam: SC-100
Domain: Design solutions that align with security best practices and priorities
Difficulty: medium
In designing a Zero Trust network architecture, why does Microsoft advise against relying on network location (such as corporate office IP or VPN IP) as the primary authenticator for corporate access?
Answer Options
A
Perimeter compromise grants lateral trust; access must be verified per request
B
Corporate network cables are slower than public home Wi-Fi networks
C
VPN gateways cannot process TLS encryption protocols
D
Office IP addresses change every 15 minutes automatically
Correct Answer
A: Perimeter compromise grants lateral trust; access must be verified per request
Explanation
Attackers who compromise internal network perimeters or establish VPN implants gain unrestricted lateral trust; access must be authenticated and authorized dynamically per request regardless of network topology.