Skip to content

Microsoft Security, Compliance, and Identity Fundamentals (SC-900)

Exam Overview

The Security, Compliance, and Identity Fundamentals certification validates foundational knowledge on security, compliance, and identity concepts and related cloud-based Microsoft solutions. This exam is intended for those looking to familiarize themselves with the fundamentals of security, compliance, and identity across cloud-based and related Microsoft services.

Exam Details: - Exam Code: SC-900 - Duration: 60 minutes - Number of Questions: 40-60 questions - Passing Score: 700 out of 1000 - Question Types: Multiple choice, multiple select, drag and drop, hot area, case studies - Cost: $99 USD - Prerequisites: None (basic understanding of Microsoft 365 and Azure helpful)

Exam Domains

1. Describe the Concepts of Security, Compliance, and Identity (10-15%)

  • Security and Compliance Concepts
  • Shared responsibility model
  • Defense in depth strategy
  • Zero Trust model
  • Encryption and hashing
  • Common threats and attack vectors
  • Identity Concepts
  • Authentication vs authorization
  • Identity as the primary security perimeter
  • Role-based access control (RBAC)
  • Identity providers and directory services

2. Describe the Capabilities of Microsoft Identity and Access Management Solutions (25-30%)

  • Azure Active Directory (Azure AD)
  • Azure AD editions and licensing
  • User and group management
  • External identities (B2B and B2C)
  • Authentication Capabilities
  • Multi-factor authentication (MFA)
  • Self-service password reset (SSPR)
  • Password protection and smart lockout
  • Single sign-on (SSO)
  • Access Management Capabilities
  • Conditional access
  • Azure AD roles and role-based access control
  • Azure AD Privileged Identity Management (PIM)
  • Identity Protection and Governance
  • Azure AD Identity Protection
  • Azure AD access reviews
  • Azure AD entitlement management
  • Azure AD terms of use

3. Describe the Capabilities of Microsoft Security Solutions (25-30%)

  • Basic Security Capabilities in Azure
  • Azure Security Center/Microsoft Defender for Cloud
  • Azure Network Security Groups (NSGs)
  • Azure Firewall and Web Application Firewall
  • Azure DDoS Protection
  • Azure Key Vault
  • Security Management Capabilities
  • Microsoft Defender for Cloud Apps
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Identity
  • Microsoft Defender for Office 365
  • Microsoft 365 Defender portal
  • Security Capabilities of Microsoft Sentinel
  • SIEM and SOAR concepts
  • Data connectors and analytics rules
  • Incidents and investigations
  • Hunting and threat intelligence

4. Describe the Capabilities of Microsoft Compliance Solutions (25-30%)

  • Compliance Management Capabilities
  • Microsoft Purview compliance portal
  • Compliance Manager and compliance score
  • Privacy management capabilities
  • Information Protection and Governance
  • Microsoft Purview Information Protection
  • Data classification and sensitivity labels
  • Data loss prevention (DLP)
  • Records management and retention policies
  • Insider Risk Capabilities
  • Microsoft Purview Insider Risk Management
  • Communication compliance
  • Information barriers
  • eDiscovery and Audit Capabilities
  • eDiscovery solutions in Microsoft 365
  • Audit logging and search capabilities

Study Tips

  1. Week 1: Security, compliance, and identity concepts
  2. Week 2: Azure AD and identity management
  3. Week 3: Microsoft security solutions
  4. Week 4: Compliance and information protection
  5. Week 5-6: Practice tests and review

Key Study Resources

  • Microsoft Learn Learning Paths:
  • SC-900 part 1: Describe the concepts of security, compliance, and identity
  • SC-900 part 2: Describe the capabilities of Microsoft identity and access management solutions
  • SC-900 part 3: Describe the capabilities of Microsoft security solutions
  • SC-900 part 4: Describe the capabilities of Microsoft compliance solutions

Hands-on Practice

  • Explore Azure AD admin center
  • Configure MFA and conditional access policies
  • Set up Microsoft Defender for Cloud
  • Use Microsoft Purview compliance portal
  • Create sensitivity labels and DLP policies
  • Review security and compliance dashboards

Exam Strategy

  • Understand the Zero Trust security model
  • Know the difference between authentication and authorization
  • Focus on capabilities rather than detailed configuration
  • Understand compliance requirements and solutions
  • Practice identifying appropriate tools for security scenarios

Common Gotchas

  • Distinguish between different Microsoft Defender products
  • Understand Azure AD vs on-premises Active Directory
  • Know when to use different authentication methods
  • Understand data classification and protection concepts
  • Be familiar with compliance frameworks and regulations

Comprehensive Study Resources

πŸ‘‰ Complete Azure Study Resources Guide

For detailed information on courses, practice tests, hands-on labs, communities, and more, see our comprehensive Azure study resources guide which includes: - Official Microsoft Learn paths (FREE) - Top-rated video courses with specific instructors - Practice test platforms with pricing and comparisons - Hands-on lab environments and free tier details - Community forums and study groups - Essential tools and Azure CLI resources - Pro tips and budget-friendly study strategies

Key Services Quick Reference

Identity and Access Management

  • Azure Active Directory: Cloud-based identity and access management
  • Azure AD B2B/B2C: External identity solutions
  • Azure AD PIM: Privileged identity management
  • Conditional Access: Risk-based access policies

Security Solutions

  • Microsoft Defender for Cloud: Cloud security posture management
  • Microsoft Defender for Endpoint: Endpoint detection and response
  • Microsoft Sentinel: Cloud-native SIEM/SOAR solution
  • Azure Key Vault: Secrets and key management

Compliance Solutions

  • Microsoft Purview: Unified data governance and compliance
  • Compliance Manager: Compliance assessment and management
  • Information Protection: Data classification and protection
  • eDiscovery: Legal hold and content search

Security Frameworks and Standards

  • NIST Cybersecurity Framework
  • ISO 27001/27002
  • SOC ½/3
  • GDPR and other privacy regulations
  • HIPAA, PCI DSS, FedRAMP

Remember: This exam covers the breadth of Microsoft's security, compliance, and identity solutions. Focus on understanding when to use different services and their key capabilities rather than detailed technical implementation.