Microsoft · SC-900
Validates foundational knowledge on security, compliance, and identity concepts across cloud-based and related Microsoft services.
Practice Questions
230
≈ 4 practice exams
Duration
45 minutes
Passing Score
700/1000
Difficulty
FoundationalLast Updated
Sep 2026
Microsoft revises the English-language SC-900 exam on October 21, 2026, the first refresh since July 28, 2026. This practice bank is built against the skills measured effective October 21, so you are training on the same objective list Microsoft is currently testing, not a version that quietly went stale months ago. The published change log confirms the four domain weights hold steady across the cutover: Security, Compliance, and Identity Concepts 10-15 percent, Microsoft Entra 25-30 percent, Microsoft Security Solutions 35-40 percent, and Microsoft Compliance Solutions 20-25 percent, so how you allocate study time doesn't change. What does shift is language inside two functional groups: the Microsoft Entra ID identity-types objective now explicitly names workload identities alongside user and hybrid identities, and the Defender XDR threat-protection objective's wording was refreshed. Neither addition moves point weight, but if you're studying from a course or book written even a few months ago, workload identities may not be called out at all. These explanations were checked against the live October 21 skills-measured page and change log, not a cached copy from earlier in the year.
Ask r/MicrosoftCertification whether to take SC-900 before or after AZ-900 (Azure Fundamentals) and you'll get a consistent answer: take AZ-900 first if you don't already know what a resource group, subscription, or Microsoft Entra tenant is. AZ-900 teaches you what the underlying Azure and Microsoft 365 'things' are; SC-900 teaches you how Microsoft secures those things, and the security concepts click faster once the platform vocabulary is already familiar. SC-900 has no enforced prerequisite, though, and experienced IT professionals who already administer Azure or Microsoft 365 day to day can skip straight to it, since the exam only asks you to describe capabilities, never configure them. This is why total study time varies so widely in candidate reports, from under a week for people who already live in the Microsoft admin centers to two or three weeks for genuine beginners working through the free SC-900T00 learning path from scratch. Because both groups sit the identical 45-minute, 700-out-of-1000-scaled exam, this bank mixes definitional recall questions with scenario questions that force you to pick between similarly named services, such as Defender for Cloud Apps versus Defender for Identity, which is where beginners and rusty veterans alike tend to lose points.
SC-900 does not expire, and Microsoft's own credential browser classifies it under the Security Engineer role and Azure product tags at the Beginner level. A recurring theme on Reddit and Microsoft's own Q&A forums is candidates asking some version of 'I passed SC-900, why am I not getting interviews' — the certification proves you can describe Microsoft's security, identity, and compliance stack, not that you can operate it, and hiring managers for hands-on security roles know the difference. Where SC-900 earns its keep is as a fast, $99 signal for IT admins, compliance officers, business analysts, and students who need Microsoft-specific vocabulary before their role or their next certification requires it. Pass it, and the direct next step is one of three role-based exams depending on your target: SC-200 for security operations, SC-300 for identity and access administration, or SC-400 for information protection and compliance administration; none of them waive their own prerequisites just because you hold SC-900. If your goal is a job title change rather than a knowledge refresher, budget for at least one of those follow-on exams and, ideally, hands-on time in Entra ID or Purview before you start interviewing.
Microsoft's SC-900 credential page lists its most recent update as July 28, 2026, with a further revision scheduled for October 21, 2026. Microsoft's published change log for that cutover shows the four domain weights stay fixed (10-15 / 25-30 / 35-40 / 20-25 percent) while two functional groups get wording refreshes: the Microsoft Entra ID identity-types objective now explicitly names workload identities, and the Microsoft Defender XDR threat-protection objective's language was updated. Candidates studying from courseware written before mid-2026 should specifically re-check those two areas rather than assume nothing changed.
Beyond the update itself, SC-900 remains a single 45-minute, Pearson VUE- or Certiport-proctored exam that tests whether you can describe, not configure, Microsoft's security, identity, and compliance stack across Entra ID, Microsoft Sentinel, the Defender XDR suite, and Microsoft Purview. It carries Microsoft's own 'Security Engineer' role tag and 'Azure' product tag on its official credential page despite being a Fundamentals-level exam with no hands-on lab component, which surprises some candidates who expect configuration-style questions similar to role-based exams.
SC-900 has no enforced prerequisite, but who should sit it first is more nuanced than Microsoft's own audience profile (business stakeholders, IT professionals, students) suggests. Community discussion on r/MicrosoftCertification converges on a specific sequencing rule: take AZ-900 (Azure Fundamentals) first if you don't already know what a resource group, subscription, or Microsoft Entra tenant is, because SC-900 assumes that platform vocabulary rather than teaching it. The most-echoed framing is that AZ-900 teaches you what the 'things' are and SC-900 teaches you how Microsoft secures those things.
Experienced IT professionals who already administer Azure or Microsoft 365, and therefore already know the platform layer, can skip that detour and go straight to SC-900, often finishing prep in under a week. True beginners without Microsoft cloud exposure report needing two to four weeks working through the free SC-900T00 learning path from scratch. Both groups sit the identical exam, so this is a study-time planning distinction, not a difficulty distinction — the exam itself doesn't get easier or harder based on who's taking it.
Microsoft imposes no formal prerequisite and no required prior certification for SC-900. The realistic prerequisite is conceptual: familiarity with Microsoft Azure and Microsoft 365 at roughly the level AZ-900 (Azure Fundamentals) teaches, since SC-900 questions reference services like Azure virtual networks, the Microsoft 365 admin center, and Entra tenants without re-explaining what they are first.
Before scheduling, take Microsoft's free official Practice Assessment (assessment ID 11 on the SC-900 certification page) and run through the Exam Sandbox (aka.ms/examdemo) to see the interactive question format live, since SC-900 can include drag-and-drop or matching-style items alongside standard multiple choice. Candidates who skip the sandbox and expect a plain multiple-choice test occasionally report losing time to unfamiliar UI on exam day rather than to the content itself.
SC-900 is delivered as a single 45-minute, proctored assessment through Pearson VUE for general candidates or Certiport for students and educators, taken either at a physical testing center or online with webcam proctoring. A scaled score of 700 out of 1000 is required to pass, and the format mixes standard multiple-choice and multi-select items with Microsoft's interactive question types, which the free Exam Sandbox previews so you aren't seeing them cold on test day.
The exam is offered in 13 languages, and Microsoft updates non-English versions roughly eight weeks after the English release, so candidates taking a lagging localized version can request an additional 30 minutes. A failed first attempt can be retaken after a 24-hour wait, with longer waits on subsequent retakes per Microsoft's standard retake policy, and Microsoft explicitly recommends registering with a personal Microsoft Account rather than a work or school account so your certification record isn't tied to, and lost with, your current employer's tenant.
SC-900 sits on Microsoft's official credential browser under the Security Engineer role and Azure product tags, at the Beginner level, and it does not expire. Community threads are candid that the badge alone rarely converts into interviews for hands-on security roles: a common complaint on Reddit and Microsoft's own Q&A forums is candidates asking why passing SC-900 didn't generate callbacks, and the honest answer is that the exam only asks you to describe capabilities, never operate them. Its real value is as a fast, $99 filter: IT administrators, compliance officers, business analysts, and students use it to prove Microsoft-specific vocabulary before a role, an internal transfer, or a follow-on certification requires it, and hiring managers who know Microsoft's certification ladder read it as 'has started,' not 'is qualified.'
The practical path forward is one of three role-based exams: SC-200 (Security Operations Analyst) for candidates heading toward SOC/Sentinel work, SC-300 (Identity and Access Administrator) for Entra-focused identity roles, or SC-400 (Information Protection and Compliance Administrator) for Purview-heavy compliance roles, each with its own study investment and none waiving prerequisites for holding SC-900. Entry-level roles that value foundational Microsoft security literacy alone, such as junior compliance analyst or IT support with a security lean, report salaries in the $72,000-$92,000 range, but candidates aiming higher should treat SC-900 as the first several weeks of a multi-exam plan rather than the destination, and pair it with hands-on time in the Entra admin center or Purview portal before interviewing.
5 sample questions with answers and explanations. The full bank has 230 questions, enough for 4 full-length practice exams.
Preview — answers shown1. Which of the three core principles of the Zero Trust model addresses the need to provide users with only the permissions they need to perform their job, and no more, especially for privileged roles?
Explanation
The three guiding principles of Zero Trust are Verify Explicitly, Use Least-Privileged Access, and Assume Breach. Why this is correct: The principle of 'Use least-privileged access' is fundamental to Zero Trust. It dictates that users should only have the minimum levels of access—or permissions—they need to perform their duties. This is often combined with just-in-time (JIT) and just-enough-access (JEA) policies to drastically limit the potential damage an attacker could do if they compromise an account. Why others are incorrect: 'Verify explicitly' is about always authenticating and authorizing based on all available data points. 'Assume breach' means you should design your security as if an attacker is already inside. 'Defense-in-depth' is a related security concept but not one of the three core Zero Trust principles.
2. The SOC team at 'BioGen Innovations' wants to ingest log data from their on-premises Cisco firewall into Microsoft Sentinel for analysis. What component must be configured in Sentinel to establish the connection and begin collecting these third-party logs?
Explanation
Data connectors are the essential first step for getting data into Microsoft Sentinel. Why this is correct: Microsoft Sentinel is only useful if it has data to analyze. Data connectors are the pre-built integrations that provide the connection and data ingestion pipeline from various sources into your Sentinel Log Analytics workspace. Sentinel has a large gallery of connectors for Microsoft services, as well as for third-party solutions like Cisco, Palo Alto, and Check Point firewalls. Why others are incorrect: Workbooks visualize data, Playbooks respond to data, and Analytics Rules analyze data. None of these can function until a Data Connector has first ingested the data.
3. SecureBank implements time-based one-time passwords for their high-security transactions. Employees receive new 6-digit codes every 30 seconds on their devices. Which authentication method are they using?
Explanation
OATH hardware tokens generate time-based one-time passwords that change at regular intervals, typically every 30 seconds. This provides strong authentication because even if a code is intercepted, it becomes useless after the time window expires. Windows Hello uses biometrics, SMS codes aren't time-based in the same way, and static passwords don't change.
4. StartupAccel needs someone to manage user accounts and group memberships in their Microsoft Entra tenant, but they want to follow the principle of least privilege. What is the least privileged role that can create and manage both users and groups?
Explanation
User Administrator is the least privileged role that can manage both users and groups in Microsoft Entra ID. While Global Administrator can also perform these tasks, it has far more permissions than necessary, violating the principle of least privilege. Groups Administrator only manages groups, and Authentication Administrator focuses on authentication methods, not user/group management.
5. In the Microsoft Purview portal, what is the primary function of the 'Data Map'?
Explanation
The Data Map is the foundational platform-as-a-service component of the Microsoft Purview governance solution. Why this is correct: The Microsoft Purview Data Map is the intelligent heart of the Purview governance portal. It automates the scanning and classification of data across your entire data estate, including multi-cloud and on-premises sources. It populates a unified map with metadata and captures data lineage, which provides the foundation for effective data governance and discovery. Why others are incorrect: Auditing, labeling, and retention are all applications and solutions that are built on top of the data discovered and organized by the Data Map. The Data Map itself is the underlying foundation.
Microsoft revises the English-language SC-900 exam on October 21, 2026, following a prior update on July 28, 2026. Microsoft's published change log shows the revision keeps all four domain weights the same and only refreshes wording in two functional groups: Entra ID identity types (adding workload identities) and Defender XDR threat protection. This bank is built against the skills measured as of that revision.
If you're new to Microsoft cloud, take AZ-900 (Azure Fundamentals) first. Community consensus on r/MicrosoftCertification is that AZ-900 teaches you what the platform 'things' are (resource groups, subscriptions, tenants) and SC-900 teaches you how Microsoft secures them, so the security concepts land faster once you know the platform vocabulary. Experienced Azure or Microsoft 365 admins can skip AZ-900 and go straight to SC-900.
It's still one of the easier Microsoft exams, but true beginners report needing two to four weeks with the free SC-900T00 learning path, versus under a week for people who already administer Azure or Microsoft 365. The exam tests whether you can describe a capability, not configure it, which lowers the ceiling on difficulty regardless of background.
Rarely on its own. A recurring pattern on Reddit and Microsoft's Q&A forums is candidates asking why SC-900 didn't generate interviews — it's a Fundamentals-level, describe-only exam, and hiring managers for hands-on security roles read it as a starting signal, not a qualification. It's most effective paired with a role-based follow-on (SC-200, SC-300, or SC-400) or real hands-on lab time.
The 'describe function and identity types of Microsoft Entra ID' objective now explicitly names workload identities alongside user and hybrid identities. Microsoft's change log labels this a minor change with no shift in the Microsoft Entra domain's 25-30% weight.
SC-900 is priced at $99 USD in the United States. Microsoft prices exams by the country or region where you're proctored, so check the exact figure on the Pearson VUE scheduling page for your location before booking.
SC-900 is a Fundamentals-level exam that only asks you to describe Microsoft's security, identity, and compliance concepts. SC-200 (Security Operations Analyst), SC-300 (Identity and Access Administrator), and SC-400 (Information Protection and Compliance Administrator) are role-based Associate exams that test hands-on configuration in Sentinel/Defender, Entra ID, and Purview respectively — none of them waive prerequisites for holding SC-900.
You have 45 minutes. Microsoft doesn't publish a fixed question count, but candidate reports consistently put it around 40 to 60 items, mixing standard multiple-choice/multi-select with newer interactive formats like drag-and-drop.
No. Like all Microsoft Fundamentals certifications, SC-900 does not expire and has no renewal requirement once earned.
Microsoft Security Solutions (35-40%) and Microsoft Entra (25-30%) together make up 60 to 70 percent of your score, so prioritize Defender XDR service differentiation and Entra ID's authentication, Conditional Access, and PIM capabilities before touching the smaller Concepts (10-15%) and Compliance (20-25%) domains.
Microsoft Certified: Power Platform Functional Consultant Associate (PL-200)
PL-200 · 1120 questions
Microsoft Certified: Power Platform Fundamentals (PL-900)
PL-900 · 223 questions
Microsoft Certified: Power Platform Solution Architect Expert (PL-600)
PL-600 · 1080 questions
Microsoft Certified: Security Operations Analyst Associate (SC-200)
SC-200 · 599 questions
Microsoft Certified: Windows Server Hybrid Administrator Associate (AZ-802)
AZ-802 · 600 questions
Microsoft 365 Certified: Administrator Expert (MS-102)
MS-102 · 965 questions
$17.99
One-time access to this exam