Microsoft · SC-100
Validates expertise in designing and implementing cybersecurity solutions that protect organizational assets, business operations, and infrastructure following Zero Trust principles and security best practices.
Practice Questions
880
≈ 17 practice exams
Duration
120 minutes
Passing Score
700/1000
Difficulty
ExpertLast Updated
Sep 2026
SC-100 doesn't test whether you can click through a Defender for Cloud console — it tests whether you can architect the strategy behind it. The current blueprint splits the exam into four weighted domains: design solutions that align with security best practices and priorities (20-25%), design security operations, identity, and compliance capabilities (25-30%), design security solutions for infrastructure (25-30%), and design security solutions for applications and data (20-25%). Every domain leans on Microsoft's own frameworks — the Microsoft Cybersecurity Reference Architectures (MCRA), the Microsoft Cloud Security Benchmark (MCSB), Zero Trust RaMP, and the Cloud Adoption Framework — so questions ask you to pick the best architectural response to a business constraint, not recall a configuration blade. Case-study-style items present a fictional company's current environment, compliance obligations, and risk appetite, then ask which of several plausible Entra ID, Sentinel, Purview, or Defender XDR designs actually fits. This is why SC-100 has a reputation, well earned in Microsoft certification communities, as one of the toughest exams in the security track: it rewards architectural judgment built from real multi-domain experience, not memorized product feature lists. Our practice bank mirrors that scenario-based structure and the current domain weighting so you can build the evaluative reasoning the real exam demands, rather than just recognizing terminology.
SC-100 is delivered through Pearson VUE, either at a test center or via online proctoring, with roughly 120 minutes of seat time. Microsoft does not publish an exact question count, but the exam is commonly reported at around 40-60 questions spanning multiple-choice, multiple-response, drag-and-drop, and multi-question case studies built around a shared scenario. A scaled score of 700 out of 1000 is required to pass, and Microsoft's scoring model weights individual items by difficulty and domain rather than counting every question equally. The exam is available in English, Japanese, Simplified and Traditional Chinese, Korean, German, French, Spanish, Portuguese (Brazil), and Italian. Note that Microsoft has announced the English-language version will be refreshed on October 21, 2026, with localized versions following roughly eight weeks later — if you're testing near that date, check the official study guide for the updated objective list before you sit the exam, since a handful of task areas typically shift with each SC-100 revision.
This is an expert-level credential, and Microsoft enforces that with a real gate: before you can earn the Cybersecurity Architect Expert certification, you must already hold at least one of three associate certifications — Identity and Access Administrator Associate (SC-300), Security Operations Analyst Associate (SC-200), or Cloud and AI Security Engineer Associate (SC-500, which replaced the retired AZ-500 on August 31, 2026). That prerequisite isn't a formality; it exists because SC-100 assumes you already have hands-on depth in at least one security domain and are now being tested on how you connect that depth to enterprise-wide strategy across identity, operations, infrastructure, applications, and data. The SC-100 exam itself costs $165 USD (regional pricing varies), and the resulting Expert certification renews for free with an annual online assessment. If you already hold an SC-200, SC-300, or SC-500 associate credential and are ready to prove you can think at the architecture level, work through our SC-100 practice questions below to pressure-test your scenario reasoning before exam day.
The Microsoft Cybersecurity Architect Expert certification (SC-100) validates the ability to translate an organization's cybersecurity strategy into concrete, cross-domain capabilities. Credential holders design, guide the implementation of, and maintain security solutions built on Zero Trust principles across identity, devices, data, AI, applications, network, infrastructure, and DevOps, plus governance, risk, and compliance (GRC), security operations, and security posture management. Per Microsoft's official exam page (last confirmed current as of September 2026), the certification sits at the top of the Security, Compliance, and Identity portfolio, and Microsoft has announced the English-language version of the exam will be refreshed on October 21, 2026.
Unlike associate-level exams that test hands-on configuration, SC-100 tests architectural judgment: evaluating and comparing security solutions, aligning technical controls to business risk, and communicating that reasoning to organizational leadership. The exam leans heavily on Microsoft's own frameworks — the Microsoft Cybersecurity Reference Architectures (MCRA), the Microsoft Cloud Security Benchmark (MCSB), Zero Trust Rapid Modernization Plan (RaMP), and the Cloud Adoption Framework (CAF) — and expects broad familiarity with Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, and Defender XDR across hybrid and multicloud environments.
SC-100 is built for senior security professionals functioning as, or moving into, a cybersecurity architect role: Security Architects, Cloud Security Engineers, Security Operations Analysts, and Solution Architects with hands-on experience across identity and access, platform protection, security operations, data and AI security, and application security. Microsoft's own guidance states candidates should have expert-level skill in at least one of those domains plus practical experience designing solutions with Microsoft security technologies — this is explicitly not an entry point into security.
Most successful candidates already hold an associate-level Microsoft security certification and are transitioning from implementation-focused work (Security Operations Analyst, Identity Administrator, Cloud Security Engineer) into a strategic, architecture-defining role that involves collaborating with executives, translating compliance and business requirements into technical design, and owning organization-wide security posture decisions rather than a single product or control.
SC-100 is gated: to earn the Cybersecurity Architect Expert certification, Microsoft requires candidates to already hold at least one of three associate-level certifications, per the official certification prerequisites page — Microsoft Certified: Identity and Access Administrator Associate (SC-300), Microsoft Certified: Security Operations Analyst Associate (SC-200), or Microsoft Certified: Cloud and AI Security Engineer Associate (SC-500). SC-500 is the current path into the infrastructure/platform-security side of the prerequisite tree; it replaced AZ-500 (Azure Security Engineer Associate), which Microsoft retired on August 31, 2026, so AZ-500 no longer counts as a qualifying prerequisite for new candidates.
Beyond the mandatory associate credential, candidates should have real, multi-year experience implementing or administering solutions across identity and access, platform protection, security operations, and hybrid or multicloud infrastructure. Working familiarity with Microsoft Entra ID, Microsoft Defender XDR, Microsoft Sentinel, Microsoft Defender for Cloud, Microsoft Purview, and Azure Policy is assumed, along with Zero Trust concepts and regulatory/compliance frameworks. Candidates who only have exposure to one security domain typically find the cross-domain case studies significantly harder.
SC-100 is delivered through Pearson VUE at a test center or via online proctoring, with approximately 120 minutes of seat time. Microsoft does not publish an exact scored-item count, but the exam is widely reported at roughly 40-60 questions across multiple-choice, multiple-response, drag-and-drop, and case-study formats, where several questions share one detailed business scenario. A passing score of 700 out of 1000 is required, using Microsoft's scaled scoring model that weights items by difficulty and domain rather than a flat percentage-correct calculation.
The exam is available in English, Japanese, Simplified Chinese, Korean, German, French, Spanish, Portuguese (Brazil), Traditional Chinese, and Italian, per the official exam page. Microsoft has confirmed the English-language version will be updated on October 21, 2026, with localized versions following roughly eight weeks later; candidates testing near or after that date should recheck the official study guide for objective changes. Standard pricing is $165 USD, though Microsoft prices exams by the country or region in which they are proctored, so actual local cost can vary.
SC-100 positions holders for senior, strategy-owning roles: Cybersecurity Architect, Cloud Security Engineer/Lead, Solution Architect, and Security Operations Analyst tracks that lead toward architecture responsibility. U.S. salary data from ZipRecruiter and Indeed (2026) places cybersecurity architect pay in roughly the $121,500-$164,000 range between the 25th and 75th percentiles nationally, with top earners above $180,000; Microsoft-ecosystem-specific security architect roles frequently trend above the broader market given the premium on Entra ID, Sentinel, Defender, and Purview expertise at the architecture level rather than pure implementation.
As enterprises consolidate on Microsoft's security stack and regulatory pressure increases, demand continues to grow for professionals who can own end-to-end security strategy rather than a single control area. SC-100 differentiates candidates from associate-only holders by proving they can evaluate architecture trade-offs, justify designs to leadership, and reason about risk across an entire hybrid/multicloud estate. Because it requires an associate prerequisite (SC-200, SC-300, or SC-500) to even earn the credential, holding it also signals verified depth in at least one specific domain plus the strategic layer on top of it — a combination employers explicitly look for when hiring into architect-level and principal engineer roles.
5 sample questions with answers and explanations. The full bank has 880 questions, enough for 17 full-length practice exams.
Preview — answers shown1. Solution: Contoso recommends implementing Protected Folders to minimize the risk of ransomware encrypting local user files. Does this solution meet the goal?
Explanation
Protected Folders is a ransomware protection feature that prevents unauthorized applications from modifying files in specified folders, effectively protecting user files from ransomware encryption. This directly addresses the requirement to minimize ransomware file encryption risk.
2. Solution: Alpine Ski House implements network segmentation and configures data encryption at rest. Does this solution meet the goal of establishing a complete zero trust data protection strategy?
Explanation
While network segmentation and encryption at rest are important components, they do not constitute a complete zero trust data protection strategy. Zero trust data protection requires: data classification to identify sensitive information, encryption both at rest and in transit, access controls based on data classification and user identity, monitoring and auditing of data access, and protection that persists even when data leaves organizational control. Network segmentation without classification and access controls based on data sensitivity is insufficient. Encryption at rest alone doesn't protect data in transit or when accessed by users. Zero trust specifically requires that data remains protected based on its classification regardless of location or who accesses it, which requires sensitivity labels, usage restrictions, and information protection policies applied to the data itself.
3. Solution: Prism Corporation deploys its web application on Azure App Service with HTTP connections allowed alongside HTTPS. Does this solution meet the security requirement to protect data in transit?
Explanation
Allowing HTTP connections means sensitive data can be transmitted unencrypted, violating data protection requirements. All HTTP requests must be redirected to HTTPS, and TLS v1.2 minimum must be enforced to ensure all data in transit is encrypted. Accepting HTTP connections creates a vulnerability that attackers can exploit.
4. Solution: Fabrikam configures an Azure Policy with the Disabled effect to evaluate compliance in their Azure environment. Does this solution meet the goal of evaluating compliance without changing any resources?
Explanation
The Disabled effect in Azure Policy is specifically designed for compliance evaluation without resource modification. It allows policies to be tested and evaluated against resources without enforcing any changes, making it ideal for assessing compliance posture. The Disabled effect provides flexibility by allowing individual policy assignments to be disabled for testing while maintaining the policy definition for future use.
5. Solution: Northwind Traders configures Azure AD Multi-Factor Authentication (MFA) for all users and implements network segmentation. Does this solution meet the goal of implementing a complete zero trust architecture?
Explanation
While MFA and network segmentation are important components of zero trust, they alone do not constitute a complete zero trust architecture. Zero trust requires verification across multiple pillars: securing identities, endpoints, data, applications, infrastructure, and networks. A complete implementation requires conditional access policies that evaluate multiple signals (user risk, device compliance, location), device health monitoring and compliance enforcement, data classification and protection, application security and shadow IT detection, infrastructure hardening, and continuous monitoring for anomalies. MFA only addresses one layer of identity verification. Network segmentation without continuous risk assessment and device compliance monitoring is insufficient. Zero trust specifically mandates continuous verification and the assumption of breach across all layers.
As of the current exam blueprint (Microsoft Learn, updated September 2026): design solutions that align with security best practices and priorities (20-25%), design security operations, identity, and compliance capabilities (25-30%), design security solutions for infrastructure (25-30%), and design security solutions for applications and data (20-25%). Microsoft has announced the English-language exam will be refreshed on October 21, 2026, so check the official study guide for objective changes if you're testing after that date.
SC-100 has no exam-level prerequisite, but the Cybersecurity Architect Expert certification itself requires you to already hold at least one associate-level credential: Identity and Access Administrator Associate (SC-300), Security Operations Analyst Associate (SC-200), or Cloud and AI Security Engineer Associate (SC-500). SC-500 replaced AZ-500, which Microsoft retired on August 31, 2026, so AZ-500 is no longer a valid path for new candidates.
SC-100 is scenario- and case-study-based rather than configuration-based. Instead of asking which button enables a feature, it presents a business scenario with compliance constraints and existing infrastructure, then asks you to choose the best architectural design among several plausible Microsoft security solutions. That requires synthesizing knowledge across identity, infrastructure, applications, and operations simultaneously, which is why it has a strong reputation for difficulty in the Microsoft certification community even among experienced security engineers.
SC-100 runs approximately 120 minutes and is commonly reported to include around 40-60 questions (Microsoft does not publish an exact count), including case studies, multiple-choice, multiple-response, and drag-and-drop formats. A scaled score of 700 out of 1000 is required to pass, per Microsoft's official exam scoring guidance.
The standard price is $165 USD, though Microsoft prices exams by the country or region where you sit them, so your local cost may differ. The certification renews for free every year through a short online assessment on Microsoft Learn.
SC-100 targets senior roles like Cybersecurity Architect, Cloud Security Engineer/Lead, and Solution Architect. Industry salary data (ZipRecruiter, Indeed, 2026) places U.S. cybersecurity architect pay in roughly the $121,500-$164,000 range at the 25th-75th percentile, with Microsoft-specific security architect roles trending higher, reflecting the premium employers place on staff who can design strategy across Microsoft's full security stack rather than just implement individual controls.
Microsoft 365 Certified: Collaboration Communications Systems Engineer Associate (MS-721)
MS-721 · 306 questions
Microsoft Certified: Azure Virtual Desktop Specialty (AZ-140)
AZ-140 · 517 questions
Microsoft Certified: Windows Server Hybrid Administrator Associate (AZ-801)
AZ-801 · 1376 questions
Microsoft Certified: Cybersecurity Business Professional (SC-730)
SC-730 · 575 questions
Microsoft Certified: AI Agent Builder Associate (AB-620)
AB-620 · 595 questions
Designing and Implementing Microsoft DevOps Solutions (AZ-400)
AZ-400 · 622 questions
$17.99
One-time access to this exam