Frequently Asked Questions
Do I need other certifications before SC-100?
To earn the Cybersecurity Architect Expert certification, you must pass SC-100 AND one of the following: SC-200 (Security Operations Analyst), SC-300 (Identity and Access Administrator), or AZ-500 (Azure Security Engineer). You can sit SC-100 without holding one, but you need both to earn the Expert badge. Each prerequisite covers a different lens: SC-200 focuses on SecOps, SC-300 on identity, AZ-500 on infrastructure security. Note that AZ-500 retires on July 31, 2026, and is being replaced by SC-500 (Cloud and AI Security Engineer Associate), which expands the security role to include protection of cloud and AI models. If you have not yet started preparing for AZ-500, consider preparing for SC-500 instead.
Why is this plan 7 weeks instead of 10?
Because SC-100 candidates are expected to already hold one of the prerequisite certifications. You have hands-on depth in at least one security domain. This plan skips security fundamentals and focuses on architecture design judgment: how to recommend solutions across domains, evaluate competing designs, and justify security decisions based on business requirements and risk tolerance. Business continuity is integrated into the security best practices week rather than getting a standalone week. Cross-domain practice and Legend mode are condensed since you already know how security services work at a configuration level.
How many practice questions should I aim for?
Aim for at least 600 unique questions across all domains, ensuring you prioritize quality over quantity. ExamOS provides over 2,000 high quality practice questions covering all domains and designed to explain the rationale behind both correct and incorrect answers.
When should I book the exam?
Once you are consistently hitting 80% or above on Legend mode across two or more sessions, and you feel comfortable explaining security architecture decisions, you are ready. Trust your preparation.
How long is the exam?
You get 100 minutes of actual exam time (120 minutes total seat time) if the exam does not include interactive lab tasks. If labs are included, the duration is 120 minutes (140 minutes total seat time). Microsoft does not publish which exams contain labs in advance. When you launch the exam, the overview pages will tell you. Note that labs can be removed at any time due to Azure outages or bandwidth issues, so their availability on exam day is not guaranteed.
I am a non-native English speaker. Can I get extra time?
Yes, under certain conditions. Microsoft offers an additional 30 minutes if the exam is not available in your native language. The SC-100 is currently offered in English, Japanese, Chinese (Simplified), Korean, German, French, Spanish, Portuguese (Brazil), Chinese (Traditional), and Italian. If your native language is not among these, you can request the accommodation:
- Visit the English as a Second Language request form on the Microsoft Learn credentials page.
- Submit your request before scheduling your exam.
- Once approved, the extra time will be applied when you schedule and take the exam.
If the exam is available in your native language, you can still take it in English, but the additional 30 minutes will not be granted. Request this accommodation before you schedule. It cannot be added after the exam is booked.
Can I use Microsoft Learn during the exam?
Yes. All associate and expert role-based exams, including SC-100, give you access to Microsoft Learn during the exam.
A "Learn" button at the bottom of the exam screen (Pearson VUE) opens Microsoft Learn in a split-screen view. You can search for documentation using the search bar at the top right. This is not available on Fundamentals or GitHub exams.
A few things to know:
- You can only access Microsoft Learn. No other websites, no browser tabs, no search engines.
- CTRL+F does not work reliably in the embedded view. Use the search bar.
- Use it to confirm specific details like service limits, SKUs, or feature availability. Do not rely on it as a substitute for preparation. Candidates who know the material well use it to verify edge cases. Candidates who rely on it consistently run out of time.
What changed in the April 2026 update?
Minor adjustments that align to product changes. No domains were added or removed. The official skills measured now explicitly reference AI security solutions and Security Service Edge (SSE) as evaluated capabilities. Always review the official skills measured page on Microsoft Learn before your exam date.
What is the most important domain to study?
SecOps/identity/compliance (25-30%) and infrastructure (25-30%) together represent 50-60% of the exam. But every domain carries enough weight that skipping one is risky. The biggest trap is over-studying the domain that matches your prerequisite certification and under-studying the others. If you hold SC-200, you likely know SecOps well, but you still need to design identity, infrastructure, and data security at an architecture level.
What is the difference between SC-100 and my prerequisite certification?
Your prerequisite certification tests implementation and administration: how to configure, deploy, and operate security services. SC-100 tests architecture design judgment: how to recommend solutions, evaluate competing designs, and justify security decisions based on business requirements, risk tolerance, and regulatory constraints. The question style, scope, and expected judgment are fundamentally different.
What are the most common ways people fail?
- Studying only the domain that matches their prerequisite. If you hold SC-300, identity feels comfortable. But SC-100 tests all four domains at an architecture level. Neglecting infrastructure or application security is a common way to fail.
- Not knowing the MCRA diagrams. The exam expects you to understand Microsoft's capability maps, not just individual services. Review the MCRA early.
- Ignoring Security Service Edge (SSE). It is a newer topic explicitly listed in the official skills. Make sure you understand when and why to recommend it.
- Confusing Azure Blueprints with Azure Policy. Blueprints have been retired and replaced by deployment stacks. Do not study Blueprint-specific content.
- Treating SC-100 like a configuration exam. The exam asks "what should you recommend?" not "how do you configure this?"
- Underestimating AI security. The official audience profile explicitly includes AI as an area where you should have design skills. Azure OpenAI, responsible AI governance, and AI threat surfaces are in scope.
What are the three biggest preparation mistakes?
- Studying service features without studying reference architectures. SC-100 is anchored in MCRA, MCSB, CAF, and WAF. Knowing individual services is not enough if you cannot map them to these frameworks.
- Assuming your prerequisite certification covers most of SC-100. While your prerequisite gives you hands-on depth in one area, SC-100 tests cross-domain architecture design. The question style and expected judgment are different.
- Not practicing case studies under time pressure. Case studies with multiple linked questions consume the most time. Practice reading requirements before background, identifying constraints quickly, and making architectural decisions under time pressure.
Is there a renewal option?
Yes. SC-100 is valid for 1 year. You can renew it for free by passing an online assessment on Microsoft Learn. The renewal assessment is shorter and focuses on what has changed since you originally certified. Start the renewal process before your certification expires to avoid having to retake the full exam.
Quick-Reference: What Is on the Exam
For the full, always-current list, visit the official SC-100 study guide.
| Domain |
Key Skills |
| Design solutions that align with security best practices and priorities (20-25%) |
Ransomware resiliency (BCDR, secure backup/restore for hybrid and multicloud, privileged access prioritization), MCRA and MCSB alignment (cybersecurity capabilities, insider/external/supply chain attack protection), CAF and WAF security alignment, AI solutions alignment to Microsoft security best practices, regulatory compliance mapping (HIPAA, PCI-DSS, GDPR) |
| Design security operations, identity, and compliance capabilities (25-30%) |
Security operations (Sentinel, playbooks, KQL, Microsoft 365 Defender integration, threat intelligence), identity and access management (Entra ID, Conditional Access, identity governance, external identities), privileged access (PIM, PAM, tiered administration, securing privileged access roadmap), regulatory compliance (Compliance Manager, compliance score, insider risk management) |
| Design security solutions for infrastructure (25-30%) |
Security posture management (Defender for Cloud CSPM, multicloud posture, secure score), server and client endpoints (Defender for Endpoint, Defender for Cloud Apps, attack surface reduction), SaaS/PaaS/IaaS security (specifying requirements per service model), network security (Azure Firewall, DDoS, NSGs, microsegmentation), Security Service Edge (SSE) (secure web gateway, CASB, ZTNA) |
| Design security solutions for applications and data (20-25%) |
M365 security (Defender for Office 365, information protection, compliance), application security (secure development lifecycle, threat modeling with STRIDE, API security, WAF), data security (Purview classification, sensitivity labels, DLP, encryption, rights management), AI security (Azure OpenAI security, AI threat surface, responsible AI governance, Copilot for Security) |