1. Home
  2. Microsoft
  3. SC-100 Exam Syllabus

Microsoft SC-100 Exam Syllabus

Microsoft SC-100 Exam

Microsoft Cybersecurity Architect

Total Questions: 172

What is Included in the Microsoft SC-100 Exam?

Authentic information about the syllabus and an effective study guide is essential to go through the Microsoft SC-100 exam in the first attempt. The study guide of Study4Exam provides you with comprehensive information about the syllabus of the Microsoft SC-100 exam. You should get this information at the start of your preparation because it helps you make an effective study plan. We have designed this Microsoft Cybersecurity Architect Expert certification exam preparation guide to give the exam overview, practice questions, practice test, prerequisites, and information about exam topics that help to go through the Microsoft Cybersecurity Architect exam. We recommend you to the preparation material mentioned in this study guide to cover the entire Microsoft SC-100 syllabus. Study4Exam offers 3 formats of Microsoft SC-100 exam preparation material. Each format provides new practice questions in PDF format, web-based and desktop practice exams to get passing marks in the first attempt.

Microsoft SC-100 Exam Overview :

Exam Name Microsoft Cybersecurity Architect
Exam Code SC-100
Exam Registration Price $165
Official Information https://docs.microsoft.com/en-us/learn/certifications/exams/sc-100
See Expected Questions Microsoft SC-100 Expected Questions in Actual Exam
Take Self-Assessment Use Microsoft SC-100 Practice Test to Assess your preparation - Save Time and Reduce Chances of Failure

Microsoft SC-100 Exam Topics :

Section Weight Objectives
Design a Zero Trust strategy and architecture 30–35% Build an overall security strategy and architecture
  •  identify the integration points in an architecture by using Microsoft Cybersecurity Reference Architecture (MCRA)
  •  translate business goals into security requirements
  •  translate security requirements into technical capabilities, including security services,security products, and security processes
  •  design security for a resiliency strategy
  •  integrate a hybrid or multi-tenant environment into a security strategy
  •  develop a technical and governance strategy for traffic filtering and segmentation
Design a security operations strategy
  •  design a logging and auditing strategy to support security operations
  •  develop security operations to support a hybrid or multi-cloud environment
  •  design a strategy for SIEM and SOAR
  •  evaluate security workflows
  •  evaluate a security operations strategy for incident management lifecycle
  •  evaluate a security operations strategy for sharing technical threat intelligence
Design an identity security strategy
Note: includes hybrid and multi-cloud
  •  design a strategy for access to cloud resources
  •  recommend an identity store (tenants, B2B, B2C, hybrid)
  •  recommend an authentication strategy
  •  recommend an authorization strategy
  •  design a strategy for conditional access
  •  design a strategy for role assignment and delegation
  •  design security strategy for privileged role access to infrastructure including identity-based firewall rules, Azure PIM
  •  design security strategy for privileged activities including PAM, entitlement management, cloud tenant administration
Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies 20–25% Design a regulatory compliance strategy
  •  interpret compliance requirements and translate into specific technical capabilities (new or existing)
  •  evaluate infrastructure compliance by using Microsoft Defender for Cloud
  •  interpret compliance scores and recommend actions to resolve issues or improve security
  •  design implementation of Azure Policy
  •  design for data residency requirements
  •  translate privacy requirements into requirements for security solutions
Evaluate security posture and recommend technical strategies to manage risk
  •  evaluate security posture by using benchmarks (including Azure security benchmarks, ISO 2701, etc.)
  •  evaluate security posture by using Microsoft Defender for Cloud
  •  evaluate security posture by using Secure Scores
  •  evaluate security posture of cloud workloads
  •  design security for an Azure Landing Zone
  •  interpret technical threat intelligence and recommend risk mitigations
  •  recommend security capabilities or controls to mitigate identified risks
Design security for infrastructure 20–25% Design a strategy for securing server and client endpoints
NOTE: includes hybrid and multi-cloud
  •  specify security baselines for server and client endpoints
  •  specify security requirements for servers, including multiple platforms and operating systems
  •  specify security requirements for mobile devices and clients, including endpoint protection, hardening, and configuration
  •  specify requirements to secure Active Directory Domain Services
  •  design a strategy to manage secrets, keys, and certificates
  •  design a strategy for secure remote access
Design a strategy for securing SaaS, PaaS, and IaaS services
  •  specify security baselines for SaaS, PaaS, and IaaS services
  •  specify security requirements for IoT workloads
  •  specify security requirements for data workloads, including SQL, Azure SQL Database, Azure Synapse, and Azure Cosmos DB
  •  specify security requirements for web workloads, including Azure App Service
  •  specify security requirements for storage workloads, including Azure Storage
  •  specify security requirements for containers
  •  specify security requirements for container orchestration
Design a strategy for data and applications 20–25% Specify security requirements for applications
  •  specify priorities for mitigating threats to applications
  •  specify a security standard for onboarding a new application
  •  specify a security strategy for applications and APIs
Design a strategy for securing data
  •  specify priorities for mitigating threats to data
  •  design a strategy to identify and protect sensitive data
  •  specify an encryption standard for data at rest and in motion

Updates in the Microsoft SC-100 Exam Syllabus:

Microsoft SC-100 exam questions and practice test are the best ways to get fully prepared. Study4exam's trusted preparation material consists of both practice questions and practice test. To pass the actual Cybersecurity Architect Expert SC-100 exam on the first attempt, you need to put in hard work on these Microsoft SC-100 questions that provide updated information about the entire exam syllabus. Besides studying actual questions, you should take the Microsoft SC-100 practice test for self-assessment and actual exam simulation. Revise actual exam questions and remove your mistakes with the Microsoft Cybersecurity Architect SC-100 exam practice test. Online and windows-based formats of the SC-100 exam practice test are available for self-assessment.