Microsoft Security, Compliance, and Identity Fundamentals (SC-900)¶
Exam Overview¶
The Security, Compliance, and Identity Fundamentals certification validates foundational knowledge on security, compliance, and identity concepts and related cloud-based Microsoft solutions. This exam is intended for those looking to familiarize themselves with the fundamentals of security, compliance, and identity across cloud-based and related Microsoft services.
Exam Details: - Exam Code: SC-900 - Duration: 60 minutes - Number of Questions: 40-60 questions - Passing Score: 700 out of 1000 - Question Types: Multiple choice, multiple select, drag and drop, hot area, case studies - Cost: $99 USD - Prerequisites: None (basic understanding of Microsoft 365 and Azure helpful)
Exam Domains¶
1. Describe the Concepts of Security, Compliance, and Identity (10-15%)¶
- Security and Compliance Concepts
- Shared responsibility model
- Defense in depth strategy
- Zero Trust model
- Encryption and hashing
- Common threats and attack vectors
- Identity Concepts
- Authentication vs authorization
- Identity as the primary security perimeter
- Role-based access control (RBAC)
- Identity providers and directory services
2. Describe the Capabilities of Microsoft Identity and Access Management Solutions (25-30%)¶
- Azure Active Directory (Azure AD)
- Azure AD editions and licensing
- User and group management
- External identities (B2B and B2C)
- Authentication Capabilities
- Multi-factor authentication (MFA)
- Self-service password reset (SSPR)
- Password protection and smart lockout
- Single sign-on (SSO)
- Access Management Capabilities
- Conditional access
- Azure AD roles and role-based access control
- Azure AD Privileged Identity Management (PIM)
- Identity Protection and Governance
- Azure AD Identity Protection
- Azure AD access reviews
- Azure AD entitlement management
- Azure AD terms of use
3. Describe the Capabilities of Microsoft Security Solutions (25-30%)¶
- Basic Security Capabilities in Azure
- Azure Security Center/Microsoft Defender for Cloud
- Azure Network Security Groups (NSGs)
- Azure Firewall and Web Application Firewall
- Azure DDoS Protection
- Azure Key Vault
- Security Management Capabilities
- Microsoft Defender for Cloud Apps
- Microsoft Defender for Endpoint
- Microsoft Defender for Identity
- Microsoft Defender for Office 365
- Microsoft 365 Defender portal
- Security Capabilities of Microsoft Sentinel
- SIEM and SOAR concepts
- Data connectors and analytics rules
- Incidents and investigations
- Hunting and threat intelligence
4. Describe the Capabilities of Microsoft Compliance Solutions (25-30%)¶
- Compliance Management Capabilities
- Microsoft Purview compliance portal
- Compliance Manager and compliance score
- Privacy management capabilities
- Information Protection and Governance
- Microsoft Purview Information Protection
- Data classification and sensitivity labels
- Data loss prevention (DLP)
- Records management and retention policies
- Insider Risk Capabilities
- Microsoft Purview Insider Risk Management
- Communication compliance
- Information barriers
- eDiscovery and Audit Capabilities
- eDiscovery solutions in Microsoft 365
- Audit logging and search capabilities
Study Tips¶
Recommended Study Timeline: 4-6 weeks¶
- Week 1: Security, compliance, and identity concepts
- Week 2: Azure AD and identity management
- Week 3: Microsoft security solutions
- Week 4: Compliance and information protection
- Week 5-6: Practice tests and review
Key Study Resources¶
- Microsoft Learn Learning Paths:
- SC-900 part 1: Describe the concepts of security, compliance, and identity
- SC-900 part 2: Describe the capabilities of Microsoft identity and access management solutions
- SC-900 part 3: Describe the capabilities of Microsoft security solutions
- SC-900 part 4: Describe the capabilities of Microsoft compliance solutions
Hands-on Practice¶
- Explore Azure AD admin center
- Configure MFA and conditional access policies
- Set up Microsoft Defender for Cloud
- Use Microsoft Purview compliance portal
- Create sensitivity labels and DLP policies
- Review security and compliance dashboards
Exam Strategy¶
- Understand the Zero Trust security model
- Know the difference between authentication and authorization
- Focus on capabilities rather than detailed configuration
- Understand compliance requirements and solutions
- Practice identifying appropriate tools for security scenarios
Common Gotchas¶
- Distinguish between different Microsoft Defender products
- Understand Azure AD vs on-premises Active Directory
- Know when to use different authentication methods
- Understand data classification and protection concepts
- Be familiar with compliance frameworks and regulations
Comprehensive Study Resources¶
π Complete Azure Study Resources Guide
For detailed information on courses, practice tests, hands-on labs, communities, and more, see our comprehensive Azure study resources guide which includes: - Official Microsoft Learn paths (FREE) - Top-rated video courses with specific instructors - Practice test platforms with pricing and comparisons - Hands-on lab environments and free tier details - Community forums and study groups - Essential tools and Azure CLI resources - Pro tips and budget-friendly study strategies
Quick Links (SC-900 Specific)¶
- SC-900 Official Exam Page - Registration and exam details
- Microsoft Learn - SC-900 Learning Path - FREE official study path
- Azure Documentation - Complete Azure documentation
- Azure Free Account - $200 free credit for hands-on practice
Key Services Quick Reference¶
Identity and Access Management¶
- Azure Active Directory: Cloud-based identity and access management
- Azure AD B2B/B2C: External identity solutions
- Azure AD PIM: Privileged identity management
- Conditional Access: Risk-based access policies
Security Solutions¶
- Microsoft Defender for Cloud: Cloud security posture management
- Microsoft Defender for Endpoint: Endpoint detection and response
- Microsoft Sentinel: Cloud-native SIEM/SOAR solution
- Azure Key Vault: Secrets and key management
Compliance Solutions¶
- Microsoft Purview: Unified data governance and compliance
- Compliance Manager: Compliance assessment and management
- Information Protection: Data classification and protection
- eDiscovery: Legal hold and content search
Security Frameworks and Standards¶
- NIST Cybersecurity Framework
- ISO 27001/27002
- SOC ½/3
- GDPR and other privacy regulations
- HIPAA, PCI DSS, FedRAMP
Remember: This exam covers the breadth of Microsoft's security, compliance, and identity solutions. Focus on understanding when to use different services and their key capabilities rather than detailed technical implementation.