Why Study with PlanetCert?
The Latest Questions
Practice questions and exam topics aligned with the current exam objectives.
Detailed Explanations
Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI-Powered Insights
Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.
Exam Information
Official specifications published by Microsoft
Exam Format
Registration
Validity
SC-100 Exam Topics and Domains
SC-100 is organized into 4 weighted domains. Expect to work with Azure AD, Microsoft Purview, Microsoft Sentinel, Azure Policy, and more.
Design solutions that align with security best practices and priorities
Design a resiliency strategy for ransomware and other attacks based on Microsoft Security Best Practices
- Design a security strategy to support business resiliency goals
- Design solutions for business continuity and disaster recovery
- Design solutions for mitigating ransomware attacks
- Evaluate solutions for security updates
Design solutions that align with the Microsoft Cybersecurity Reference Architectures (MCRA) and Microsoft cloud security benchmark (MCSB)
- Design solutions that align with best practices for cybersecurity capabilities and controls
- Design solutions that align with best practices for protecting against attacks
- Design solutions that align with best practices for Zero Trust security
Design solutions that align with the Microsoft Cloud Adoption Framework for Azure and the Microsoft Azure Well-Architected Framework
- Design or evaluate strategy for security and governance based on CAF and WAF
- Recommend solutions for security and governance
- Design solutions for implementing and governing security using Azure landing zones
- Design a DevSecOps process that aligns with best practices
Design security operations, identity, and compliance capabilities
Design solutions for security operations
- Design a solution for detection and response including XDR and SIEM
- Design a solution for centralized logging and auditing
- Design monitoring to support hybrid and multicloud environments
- Design a solution for SOAR
- Design and evaluate security workflows
- Design and evaluate threat detection coverage using MITRE ATT&CK
Design solutions for identity and access management
- Design a solution for access to cloud resources
- Design a solution for Microsoft Entra ID
- Design a solution for external identities
- Design a modern authentication and authorization strategy
- Validate alignment of Conditional Access policies with Zero Trust
- Specify requirements to harden AD DS
- Design a solution to manage secrets, keys, and certificates
Design solutions for securing privileged access
- Design a solution for assigning and delegating privileged roles
- Evaluate security and governance of Microsoft Entra ID
- Evaluate security and governance of AD DS
- Design a solution for securing cloud tenant administration
- Design a solution for cloud infrastructure entitlement management
- Evaluate an access review management solution
- Design a solution for Privileged Access Workstation
Design solutions for regulatory compliance
- Translate compliance requirements into security controls
- Design a solution to address compliance requirements using Microsoft Purview
- Design a solution to address privacy requirements
- Design Azure Policy solutions for security and compliance
- Evaluate and validate alignment with regulatory standards
Design security solutions for infrastructure
Design solutions for security posture management in hybrid and multicloud environments
- Evaluate security posture using Microsoft Defender for Cloud
- Evaluate security posture using Microsoft Secure Score
- Design integrated security posture management solutions
- Select cloud workload protection solutions
- Design a solution for integrating environments using Azure Arc
- Design a solution for Microsoft Defender EASM
- Specify requirements for posture management process
Specify requirements for securing server and client endpoints
- Specify security requirements for servers
- Specify security requirements for mobile devices and clients
- Specify security requirements for IoT devices
- Evaluate solutions for securing OT and ICS
- Specify security baselines for endpoints
- Evaluate Windows LAPS solutions
Specify requirements for securing SaaS, PaaS, and IaaS services
- Specify security baselines for cloud services
- Specify security requirements for IoT workloads
- Specify security requirements for web workloads
- Specify security requirements for containers
- Specify security requirements for container orchestration
- Evaluate solutions that include Azure AI services security
Evaluate solutions for network security and Security Service Edge (SSE)
- Evaluate network designs to align with security requirements
- Evaluate solutions using Microsoft Entra Internet Access as SWG
- Evaluate solutions for Microsoft Services access
- Evaluate solutions using Microsoft Entra Private Access
Design security solutions for applications and data
Evaluate solutions for securing Microsoft 365
- Evaluate security posture for productivity workloads
- Evaluate solutions including Defender for Office 365 and Cloud Apps
- Evaluate device management solutions
- Evaluate solutions for securing data in Microsoft 365
- Evaluate data security and compliance controls in Copilot
Design solutions for securing applications
- Evaluate security posture of application portfolios
- Evaluate threats using threat modeling
- Design full lifecycle strategy for application security
- Design standards for securing development process
- Map technologies to application security requirements
- Design solution for workload identity
- Design solution for API management and security
- Design solutions using Azure WAF
Design solutions for securing an organization's data
- Evaluate solutions for data discovery and classification
- Specify priorities for mitigating threats to data
- Evaluate solutions for encryption
- Design security solution for data in Azure workloads
- Design security solution for data in Azure Storage
- Design solution including Defender for Storage and Databases
How do I earn this certification?
Practice with Precision
The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.
How to study for this exam?
The most effective way to prepare for SC-100 is by using the PlanetCert Simulator to practice questions and review detailed explanations.
What's changed on this exam?
- ACTIVE
- Last content update: 2025-07-22
- Announcement date: 2025-06-20
- Microsoft Security Exposure Management GA New focus on attack paths and exposure analytics • Release date: 2025-04-01
- Microsoft Defender EASM 2.0 External attack surface management now critical topic • Release date: 2025-03-15
- Microsoft Sentinel Enhanced SOAR Advanced automation and AI-powered threat hunting • Release date: 2025-05-01
Who should take this exam?
This exam is typically taken by Security Architects and Cloud Security Architects.
- Expert skills in at least one security domain
- Experience with Microsoft security technologies
- Understanding of hybrid and multi-cloud architectures
- Knowledge of Zero Trust principles
- Familiarity with compliance and governance frameworks