Microsoft Security, Compliance, and Identity Fundamentals (SC-900) Exam Blueprint

SC-900

40Questions
45 minDuration
700/1-1000Passing Score
$165Price
12Languages
Practice Microsoft Security, Compliance, and Identity Fundamentals on QuizForge

Exam Domains

1.0 Describe the concepts of security, compliance, and identity 10%
  • 1.1Describe security and compliance concepts
    Describe the shared responsibility model; Describe defense-in-depth; Describe the Zero Trust model; Describe encryption and hashing; Describe Governance, Risk, and Compliance (GRC) concepts
  • 1.2Define identity concepts
    Define identity as the primary security perimeter; Define authentication; Define authorization; Describe identity providers; Describe the concept of directory services and Active Directory; Describe the concept of federation
2.0 Describe the capabilities of Microsoft Entra 25%
  • 2.1Describe function and identity types of Microsoft Entra ID
  • 2.2Describe Microsoft Entra ID
  • 2.3Describe types of identities
  • 2.4Describe hybrid identity
  • 2.5Describe authentication capabilities of Microsoft Entra ID
    Describe the authentication methods; Describe multifactor authentication (MFA); Describe password protection and management capabilities
  • 2.6Describe access management capabilities of Microsoft Entra ID
    Describe Conditional Access; Describe Microsoft Entra roles and role-based access control (RBAC); Describe identity protection and governance capabilities of Microsoft Entra; Describe Microsoft Entra ID Governance; Describe access reviews; Describe the capabilities of Microsoft Entra Privileged Identity Management; Describe Microsoft Entra ID Protection
3.0 Describe the capabilities of Microsoft security solutions 35%
  • 3.1Describe core infrastructure security services in Azure
    Describe Azure distributed denial-of-service (DDoS) Protection; Describe Azure Firewall; Describe Web Application Firewall (WAF); Describe network segmentation with Azure virtual networks; Describe network security groups (NSGs); Describe Azure Bastion; Describe Azure Key Vault
  • 3.2Describe security management capabilities of Azure
    Describe Microsoft Defender for Cloud; Describe Cloud Security Posture Management (CSPM); Describe how security policies, standards, and recommendations improve the cloud security posture; Describe enhanced security features provided by cloud workload protection
  • 3.3Describe capabilities of Microsoft Sentinel
    Define the concepts of security information and event management (SIEM) and security orchestration automated response (SOAR); Describe threat detection and mitigation capabilities in Microsoft Sentinel; Describe threat protection with Microsoft Defender XDR; Describe Microsoft Defender XDR services; Describe Microsoft Defender for Office 365; Describe Microsoft Defender for Endpoint; Describe Microsoft Defender for Cloud Apps; Describe Microsoft Defender for Identity; Describe Microsoft Defender Vulnerability Management; Describe Microsoft Defender Threat Intelligence (Defender TI); Describe the Microsoft Defender portal
4.0 Describe the capabilities of Microsoft compliance solutions 20%
  • 4.1Describe Microsoft Service Trust Portal and privacy principles
    Describe the Service Trust Portal offerings; Describe the privacy principles of Microsoft
  • 4.2Describe Microsoft Priva
  • 4.3Describe compliance management capabilities of Microsoft Purview
    Describe the Microsoft Purview portal; Describe Compliance Manager; Describe the uses and benefits of compliance score
  • 4.4Describe information protection, data lifecycle management, and data governance capabilities of Microsoft Purview
    Describe the data classification capabilities; Describe the benefits of Content explorer and Activity explorer; Describe sensitivity labels and sensitivity label policies; Describe data loss prevention (DLP); Describe records management; Describe retention policies, retention labels, and retention label policies
  • 4.5Describe insider risk, eDiscovery, and audit capabilities in Microsoft Purview
    Describe insider risk management; Describe eDiscovery solutions in Microsoft Purview; Describe audit solutions in Microsoft Purview

Exam Details

Question TypesMultiple Choice, Multiple Response, Drag and Drop, Case Study, Build List, Hot Area, Repeated Answer Choices
FormatLinear
Online ProctoringAvailable
ID RequirementsOne valid, government-issued photo ID. Name on ID must match registration. For online: webcam required, room must be clear of people and materials.
RenewalRequired -- Microsoft certifications (Associate/Expert/Specialty) are renewed annually for free via a short renewal assessment on Microsoft Learn. Renewal assessment available 6 months before expiry. Fundamentals certifications do not expire.
Retake PolicyNo waiting period for first retake if score >= 500 on failed attempt. If score < 500: 14-day waiting period before retake. Maximum 5 attempts per exam per year (365 days). Free retake voucher sometimes included in official instructor-led training.
LanguagesEnglish, Simplified Chinese, Traditional Chinese, French, German, Japanese, Korean, Portuguese, Russian, Spanish, Arabic, Indonesian

Official Study Resources