SC-100 Verified 2026 Edition

SC-100Practice Test

Master the Microsoft Cybersecurity Architect with the official PlanetCert Practice Test. Access real exam questions, professional-grade detailed explanations, and our advanced adaptive simulator. Pass your certification exam on the first attempt.

169 Total Questions
1 Included Version Get all versions for the price of one
English Edition
All-In-One Bundle
$79.99
$75.99
  • Interactive Simulator & AI
  • Detailed Explanations
  • Study, Timed & Flashcard Mode
  • Lifetime Access & Updates

Instant lifetime access • Secure checkout

Why Study with PlanetCert?

The Latest Questions

Practice questions and exam topics aligned with the current exam objectives.

Detailed Explanations

Go beyond the answer. Master the material with comprehensive learning and professional explanations for every concept.

AI

AI-Powered Insights

Personalized preparation guidance that adapts to your performance and identifies weak spots automatically.

Exam Information

Official specifications published by Microsoft

Exam Format

120 min
40-60
700
Expert

Registration

$165 USD
Pearson VUE or online proctoring
English, Japanese, Chinese (Simplified), Korean +6 more

Validity

1 year
Free online renewal assessment on Microsoft Learn; Pass the current version of the exam; Complete continuing education activities

SC-100 Exam Topics and Domains

SC-100 is organized into 4 weighted domains. Expect to work with Azure AD, Microsoft Purview, Microsoft Sentinel, Azure Policy, and more.

1

Design solutions that align with security best practices and priorities

22.5%

Design a resiliency strategy for ransomware and other attacks based on Microsoft Security Best Practices

Design security strategy for business resiliencyDesign BCDR solutionsMitigate ransomware attacksEvaluate security updates
  • Design a security strategy to support business resiliency goals
  • Design solutions for business continuity and disaster recovery
  • Design solutions for mitigating ransomware attacks
  • Evaluate solutions for security updates

Design solutions that align with the Microsoft Cybersecurity Reference Architectures (MCRA) and Microsoft cloud security benchmark (MCSB)

Align with cybersecurity capabilities and controlsProtect against various attack typesImplement Zero Trust
  • Design solutions that align with best practices for cybersecurity capabilities and controls
  • Design solutions that align with best practices for protecting against attacks
  • Design solutions that align with best practices for Zero Trust security

Design solutions that align with the Microsoft Cloud Adoption Framework for Azure and the Microsoft Azure Well-Architected Framework

Security and governance strategyAzure landing zonesDevSecOps processes
  • Design or evaluate strategy for security and governance based on CAF and WAF
  • Recommend solutions for security and governance
  • Design solutions for implementing and governing security using Azure landing zones
  • Design a DevSecOps process that aligns with best practices
2

Design security operations, identity, and compliance capabilities

27.5%

Design solutions for security operations

Detection and response solutionsCentralized logging and auditingHybrid and multicloud monitoringSOAR implementationSecurity workflowsMITRE ATT&CK coverage
  • Design a solution for detection and response including XDR and SIEM
  • Design a solution for centralized logging and auditing
  • Design monitoring to support hybrid and multicloud environments
  • Design a solution for SOAR
  • Design and evaluate security workflows
  • Design and evaluate threat detection coverage using MITRE ATT&CK

Design solutions for identity and access management

Access to cloud resourcesMicrosoft Entra ID solutionsExternal identitiesModern authenticationZero Trust alignmentAD DS hardeningSecrets management
  • Design a solution for access to cloud resources
  • Design a solution for Microsoft Entra ID
  • Design a solution for external identities
  • Design a modern authentication and authorization strategy
  • Validate alignment of Conditional Access policies with Zero Trust
  • Specify requirements to harden AD DS
  • Design a solution to manage secrets, keys, and certificates

Design solutions for securing privileged access

Enterprise access modelMicrosoft Entra ID governanceAD DS governanceCloud tenant administrationCloud infrastructure entitlementsAccess review managementPrivileged Access Workstation
  • Design a solution for assigning and delegating privileged roles
  • Evaluate security and governance of Microsoft Entra ID
  • Evaluate security and governance of AD DS
  • Design a solution for securing cloud tenant administration
  • Design a solution for cloud infrastructure entitlement management
  • Evaluate an access review management solution
  • Design a solution for Privileged Access Workstation

Design solutions for regulatory compliance

Compliance to security controlsMicrosoft Purview solutionsPrivacy requirementsAzure Policy solutionsRegulatory standards validation
  • Translate compliance requirements into security controls
  • Design a solution to address compliance requirements using Microsoft Purview
  • Design a solution to address privacy requirements
  • Design Azure Policy solutions for security and compliance
  • Evaluate and validate alignment with regulatory standards
3

Design security solutions for infrastructure

27.5%

Design solutions for security posture management in hybrid and multicloud environments

Defender for Cloud assessmentMicrosoft Secure ScoreIntegrated posture managementCloud workload protectionAzure Arc integrationExternal Attack Surface ManagementSecurity Exposure Management
  • Evaluate security posture using Microsoft Defender for Cloud
  • Evaluate security posture using Microsoft Secure Score
  • Design integrated security posture management solutions
  • Select cloud workload protection solutions
  • Design a solution for integrating environments using Azure Arc
  • Design a solution for Microsoft Defender EASM
  • Specify requirements for posture management process

Specify requirements for securing server and client endpoints

Server security requirementsMobile and client securityIoT and embedded systemsOT and ICS securitySecurity baselinesWindows LAPS
  • Specify security requirements for servers
  • Specify security requirements for mobile devices and clients
  • Specify security requirements for IoT devices
  • Evaluate solutions for securing OT and ICS
  • Specify security baselines for endpoints
  • Evaluate Windows LAPS solutions

Specify requirements for securing SaaS, PaaS, and IaaS services

Cloud service baselinesIoT workload securityWeb workload securityContainer securityContainer orchestrationAzure AI services security
  • Specify security baselines for cloud services
  • Specify security requirements for IoT workloads
  • Specify security requirements for web workloads
  • Specify security requirements for containers
  • Specify security requirements for container orchestration
  • Evaluate solutions that include Azure AI services security

Evaluate solutions for network security and Security Service Edge (SSE)

Network security designSecure web gatewayMicrosoft Services accessPrivate access solutions
  • Evaluate network designs to align with security requirements
  • Evaluate solutions using Microsoft Entra Internet Access as SWG
  • Evaluate solutions for Microsoft Services access
  • Evaluate solutions using Microsoft Entra Private Access
4

Design security solutions for applications and data

22.5%

Evaluate solutions for securing Microsoft 365

Productivity workload securityDefender for Office 365Cloud app securityDevice managementData protection in M365Copilot security
  • Evaluate security posture for productivity workloads
  • Evaluate solutions including Defender for Office 365 and Cloud Apps
  • Evaluate device management solutions
  • Evaluate solutions for securing data in Microsoft 365
  • Evaluate data security and compliance controls in Copilot

Design solutions for securing applications

Application portfolio assessmentThreat modelingApplication lifecycle securityDevelopment process securityTechnology mappingWorkload identityAPI management and securityWeb Application Firewall
  • Evaluate security posture of application portfolios
  • Evaluate threats using threat modeling
  • Design full lifecycle strategy for application security
  • Design standards for securing development process
  • Map technologies to application security requirements
  • Design solution for workload identity
  • Design solution for API management and security
  • Design solutions using Azure WAF

Design solutions for securing an organization's data

Data discovery and classificationData threat mitigationData encryptionAzure data workload securityAzure Storage securityDefender for data services
  • Evaluate solutions for data discovery and classification
  • Specify priorities for mitigating threats to data
  • Evaluate solutions for encryption
  • Design security solution for data in Azure workloads
  • Design security solution for data in Azure Storage
  • Design solution including Defender for Storage and Databases

How do I earn this certification?

Practice with Precision

The PlanetCert Simulator mirrors the real exam environment with authentic questions and timed pressure.

Launch Simulator

How to study for this exam?

The most effective way to prepare for SC-100 is by using the PlanetCert Simulator to practice questions and review detailed explanations.

What's changed on this exam?

Current Status
  • ACTIVE
  • Last content update: 2025-07-22
  • Announcement date: 2025-06-20
Updates
  • Microsoft Security Exposure Management GA New focus on attack paths and exposure analytics • Release date: 2025-04-01
  • Microsoft Defender EASM 2.0 External attack surface management now critical topic • Release date: 2025-03-15
  • Microsoft Sentinel Enhanced SOAR Advanced automation and AI-powered threat hunting • Release date: 2025-05-01

Who should take this exam?

This exam is typically taken by Security Architects and Cloud Security Architects.

One of the following certifications: SC-200, SC-300, AZ-500, or MS-500
  • Expert skills in at least one security domain
  • Experience with Microsoft security technologies
  • Understanding of hybrid and multi-cloud architectures
  • Knowledge of Zero Trust principles
  • Familiarity with compliance and governance frameworks

Your Complete Exam Solution

Best-In-Class Practice Tests

Authentic, regularly updated questions that mirror the real exam. Verified, current material — not recycled dumps.

Topical Breakdown

Study by domain, pinpoint weak areas, and focus your time where it matters most. Every topic mapped to the official syllabus.

Flashcard Mode

Rapid-fire review to reinforce key concepts. Flip through questions and answers at your own pace before exam day.

See How You Compare Against Yourself

✕
✕
✕

Other Exam Prep

  • Outdated question dumpsRecycled, often inaccurate material
  • No explanationsMemorize answers without understanding
  • Static PDF filesNo interactive practice or feedback
  • Subscription feesRecurring charges, access expires
✓
✓
✓

PlanetCert

  • Verified, current questionsUpdated weekly to match live exam objectives
  • Expert-written rationalesUnderstand every concept, not just the answer
  • Session tracking & exam progressTrack every attempt, see your growth over time
  • Lifetime access, one pricePay once — updates included forever
CERTIFIEDSC-100

Study Naturally, Study Responsibly

Join thousands of certified professionals who trusted PlanetCert to pass on the first attempt.

Try Free Demo
Secure Checkout Lifetime Access Money-back Guarantee