examOS.
Exam CatalogueStudy PlansRoadmapsBlogs
Login

ExamOS

Credits PolicyReferral PolicyQuality StandardsPricingPrivacy PolicyTerms of UseContact UsReport a Bug

Follow us

Disclaimer: ExamOS is an independent platform, not affiliated with any certification provider, and does not use or distribute exam dumps.

Share your feedback

Checking sign-in status...

examOS.Study Plan
Disclaimer: ExamOS is an independent platform, not affiliated with any certification provider, and does not use or distribute exam dumps.
← Back to Exam Details

Study Plan

Microsoft Cybersecurity Architect (SC-100) – Study Plan

A condensed 7-week plan for SC-100. Design Zero Trust, security operations, and compliance strategies across Microsoft 365, Azure, and hybrid environments.

MicrosoftSC-100Passing score: 700 / 1000Security architects with 3+ years experience in identity, platform protection, security operations, data security, application security, or hybrid/multicloud infrastructure. SC-200, SC-300, or AZ-500 recommended.18-Jul-202632 views
Start date: _______________Target exam date: _______________
7 WeeksDuration
~50 hrsTotal Study Time
4 DomainsExam Coverage

Stay consistent by setting a target date for this certification.

Set target

How to use this plan

  1. 1Read and explore. Start the week with Microsoft Learn modules and reference architectures. The Microsoft Cybersecurity Reference Architecture (MCRA) and Microsoft Cloud Security Benchmark (MCSB) are foundational documents for this exam. Familiarity with their capability maps matters.
  2. 2Build your judgment. For every security service you encounter, understand not just how it works but when it is the right choice, what it protects against, and what gaps remain.
  3. 3Practice with ExamOS. Use the quiz modes in the order specified in this Study Plan.
  4. 4Learn to evaluate, not just deploy. SC-100 questions will describe a security scenario and ask you to recommend a design. Train yourself to read the requirements, identify the binding constraint, and evaluate options against it.
Rookie ModeChallenger ModeLegend Mode

Week-by-Week Breakdown


W1

Week 1

Foundation and Self-Assessment

This week is about mapping your current knowledge against the exam domains, getting familiar with the Microsoft Cybersecurity Reference Architecture (MCRA), and reviewing the Microsoft Cloud Security Benchmark (MCSB). You are not expected to master anything yet. You are building a baseline.

Topics

  • SC-100 exam structure and domain mapping
  • MCRA: capability maps and architecture diagrams
  • MCSB: security controls baseline
  • Zero Trust principles across all pillars
  • CAF and WAF security alignment

Activities

  • Read the official SC-100 study guide and identify weak domains.
W2

Week 2

Security Best Practices and Priorities (20-25%)

This domain tests whether you can align security designs with established frameworks and business priorities. The MCRA, MCSB, Cloud Adoption Framework, and Well-Architected Framework all show up here. So does ransomware resilience, which is an increasingly common scenario.

Topics

  • Zero Trust strategy design
  • Ransomware resilience and BCDR
  • MCRA and MCSB alignment
  • CAF and WAF security pillar
  • Regulatory compliance mapping

Activities

  • Design a Zero Trust architecture for a mid-size enterprise with hybrid infrastructure and a remote workforce.
W3

Week 3

Security Operations, Identity, and Compliance (25-30%)

This is the largest domain and covers three distinct areas. Since you already have hands-on experience in at least one (from your prerequisite certification), focus on the architecture design perspective: how to recommend solutions, not how to configure them.

Topics

  • Entra ID architecture and Conditional Access
  • PIM, PAM, and tiered administration
  • Sentinel architecture and playbooks
  • KQL for investigation and threat hunting
  • Compliance Manager and insider risk

Activities

  • Design a Conditional Access policy framework for an organization with hybrid identity, external partners, and privileged admin roles.
W4

Week 4

Infrastructure Security (25-30%)

This domain covers security posture management, endpoint protection, network security, and the newer Security Service Edge (SSE) topic. It also covers SaaS, PaaS, and IaaS security requirements, which the exam tests at an architecture level.

Topics

  • Defender for Cloud: CSPM and posture
  • Defender for Endpoint and Cloud Apps
  • Network security: Firewall, DDoS, microsegmentation
  • Security Service Edge (SSE)
  • SaaS, PaaS, and IaaS security design

Activities

  • Design a security posture management strategy for a multicloud environment (Azure and AWS) using Defender for Cloud.
W5

Week 5

Application, Data, and AI Security (20-25%)

This domain covers M365 security, application security, data protection, and the increasingly important area of AI security. The official audience profile explicitly lists AI and DevOps as areas where you should have design skills.

Topics

  • M365 security: Defender for Office 365, information protection
  • Application security: STRIDE, API security, WAF
  • Data protection: Purview, sensitivity labels, DLP
  • AI security: Azure OpenAI, threat surface, responsible AI
  • Copilot for Security considerations

Activities

  • Design a data classification and protection strategy using Microsoft Purview with sensitivity labels and DLP policies.
W6

Week 6

Cross-Domain Scenarios and Weak Area Review

SC-100 case studies span multiple domains. This week practices end-to-end scenarios and fills gaps. The exam does not test domains in isolation, and neither will this week.

Topics

  • Cross-domain architecture scenarios
  • Case study technique and constraint identification
  • Threat modeling and architecture review
  • MCRA and WAF evaluation criteria
  • Targeted weak domain practice

Activities

  • Solve at least 5 full end-to-end architecture scenarios that span multiple domains (ExamOS case study mode).
W7

Week 7

Exam Simulation and Booking

Your final push. This week is full exam simulation mode: filling in remaining gaps and building the confidence to walk into the testing center ready.

Topics

  • Full syllabus review across all four domains
  • Time management (100 minutes for 40-60 questions)
  • Case study reasoning under time pressure
  • Security design trade-off articulation

Activities

  • Take at least 3 ExamOS Legend mode full quizzes (80% hard questions, 100-minute timer).
  • Simulate real exam conditions at least once: no phone, no breaks, 100 minutes, same time of day you plan to actually sit the exam.

Daily Study Routine

Suggested 2–3 Hour Day

TimeActivity
15 minLook over yesterday's wrong answers. For each one, identify the principle you missed.
45 minRead Microsoft Learn modules and reference architectures for this week's topic
30 minHands-on lab (Azure portal, Sentinel, Purview, Defender)
30 minTake an ExamOS quiz (Challenger or Legend mode, depending on the week)
15 minLog missed concepts and review them the next morning

Stay consistent by setting a target date for this certification.

Set target
  • Review the MCRA documentation and study the architecture diagrams for capabilities you are less familiar with.
  • Take the free official practice assessment to gauge your baseline.
  • Take the ExamOS Rookie mode quiz (30 questions). Note any domain below 60%.
  • Goal:A clear picture of where you stand and genuine familiarity with the MCRA capability maps.
    Rookie Mode
    Rookie Mode
  • Map a sample architecture to MCRA capabilities and identify gaps.
  • Design a ransomware resilience strategy including backup, recovery, and privileged access protection.
  • Take the ExamOS Challenger quiz. Repeat until you pass 2 times in a row.
  • Goal:Design security strategies that align with Microsoft reference architectures and map clearly to regulatory requirements.
    Challenger Mode
    Challenger Mode
  • Design a Microsoft Sentinel deployment architecture for a multi-subscription environment with data ingestion from Azure, M365, and third-party sources.
  • Design a privileged access strategy using PIM and tiered administration.
  • Design a compliance monitoring strategy that maps controls to a regulatory framework.
  • Take the ExamOS Challenger quiz. Repeat until you pass 2 times in a row.
  • Goal:Design security operations, identity, and compliance architectures that scale across an enterprise.
    Challenger Mode
    Challenger Mode
  • Design a network security architecture with Azure Firewall, NSG-based microsegmentation, and SSE integration.
  • Specify security requirements for a SaaS application, a PaaS web app, and an IaaS VM workload.
  • Take the ExamOS Challenger quiz. Repeat until you pass 2 times in a row.
  • Goal:Design infrastructure security solutions that cover posture management, endpoints, network, and multicloud environments.
    Challenger Mode
    Challenger Mode
  • Perform a threat model for a sample web application using STRIDE and map mitigations to Microsoft security services.
  • Design an AI security strategy for an organization deploying Azure OpenAI Service with sensitive data.
  • Take the ExamOS Challenger quiz. Repeat until you pass 2 times in a row.
  • Goal:Design security solutions for applications, data, and AI workloads across Microsoft 365 and Azure.
    Challenger Mode
    Challenger Mode
  • Review every incorrect answer from the past 5 weeks. Identify the security design principle you missed.
  • Map wrong answers to specific domains. Are misses concentrated in high-weight areas?
  • Take targeted Challenger quizzes on your two weakest domains until 3 consecutive passes above 75%.
  • Take the free official practice assessment again and compare to your Week 1 score.
  • Goal:Consistent above 75% on full-domain Challenger with no domain below 65%.
    Challenger Mode
    Challenger Mode
  • For every Legend question you miss, review the explanation and write one sentence explaining the security design principle behind the correct answer.
  • Use the exam sandbox on Microsoft Learn to familiarize yourself with the exam interface before test day.
  • Once you are consistently hitting 80% or above on Legend mode across two or more sessions, book your exam. You are ready.
  • Goal:Consistent above 80% on Legend mode across two or more sessions. Confidence to schedule the exam.
    Legend Mode
    Legend Mode

    Overview

    The SC-100 validates your ability to design and evaluate cybersecurity strategies that follow Zero Trust principles across Microsoft 365, Azure, hybrid, and multicloud environments. It tests architecture design judgment: you will recommend solutions, evaluate competing designs, and map security controls to business and regulatory requirements.

    If you already hold one of the prerequisite certifications (SC-200, SC-300, AZ-500 or SC-500), you have hands-on depth in at least one security domain. That knowledge is the foundation. This plan builds on it by shifting your thinking from "how do I configure this?" to "which security design is the right fit for this organization, and why?"

    The April 2026 update made minor adjustments that align to product changes. No domains were added or removed. The official skills measured now explicitly reference AI security solutions and Security Service Edge (SSE). Both are covered in this plan.

    Domain Weight
    Design solutions that align with security best practices and priorities 20-25%
    Design security operations, identity, and compliance capabilities 25-30%
    Design security solutions for infrastructure 25-30%
    Design security solutions for applications and data 20-25%

    The two middle domains (SecOps/identity/compliance and infrastructure) together represent 50-60% of the exam. The biggest trap is over-studying the domain that matches your prerequisite certification and under-studying the others.

    Recommended experience: Expert-level skills in at least one area: identity and access, platform protection, security operations, data and AI security, application security, or hybrid/multicloud infrastructure. One of SC-200, SC-300, or AZ-500 is a prerequisite for earning the Cybersecurity Architect Expert certification.

    A note on prerequisites: To earn the Cybersecurity Architect Expert certification, you must pass SC-100 AND one of the following: SC-200 (Security Operations Analyst), SC-300 (Identity and Access Administrator), or AZ-500 (Azure Security Engineer). You can sit SC-100 without holding one, but you need both to earn the Expert badge. Each prerequisite covers a different lens, so the one you hold will naturally shape which SC-100 domains feel familiar and which need more study. Note that AZ-500 retires on July 31, 2026, and is being replaced by SC-500 (Cloud and AI Security Engineer Associate).

    Frequently Asked Questions

    Do I need other certifications before SC-100?

    To earn the Cybersecurity Architect Expert certification, you must pass SC-100 AND one of the following: SC-200 (Security Operations Analyst), SC-300 (Identity and Access Administrator), or AZ-500 (Azure Security Engineer). You can sit SC-100 without holding one, but you need both to earn the Expert badge. Each prerequisite covers a different lens: SC-200 focuses on SecOps, SC-300 on identity, AZ-500 on infrastructure security. Note that AZ-500 retires on July 31, 2026, and is being replaced by SC-500 (Cloud and AI Security Engineer Associate), which expands the security role to include protection of cloud and AI models. If you have not yet started preparing for AZ-500, consider preparing for SC-500 instead.

    Why is this plan 7 weeks instead of 10?

    Because SC-100 candidates are expected to already hold one of the prerequisite certifications. You have hands-on depth in at least one security domain. This plan skips security fundamentals and focuses on architecture design judgment: how to recommend solutions across domains, evaluate competing designs, and justify security decisions based on business requirements and risk tolerance. Business continuity is integrated into the security best practices week rather than getting a standalone week. Cross-domain practice and Legend mode are condensed since you already know how security services work at a configuration level.

    How many practice questions should I aim for?

    Aim for at least 600 unique questions across all domains, ensuring you prioritize quality over quantity. ExamOS provides over 2,000 high quality practice questions covering all domains and designed to explain the rationale behind both correct and incorrect answers.

    When should I book the exam?

    Once you are consistently hitting 80% or above on Legend mode across two or more sessions, and you feel comfortable explaining security architecture decisions, you are ready. Trust your preparation.

    How long is the exam?

    You get 100 minutes of actual exam time (120 minutes total seat time) if the exam does not include interactive lab tasks. If labs are included, the duration is 120 minutes (140 minutes total seat time). Microsoft does not publish which exams contain labs in advance. When you launch the exam, the overview pages will tell you. Note that labs can be removed at any time due to Azure outages or bandwidth issues, so their availability on exam day is not guaranteed.

    I am a non-native English speaker. Can I get extra time?

    Yes, under certain conditions. Microsoft offers an additional 30 minutes if the exam is not available in your native language. The SC-100 is currently offered in English, Japanese, Chinese (Simplified), Korean, German, French, Spanish, Portuguese (Brazil), Chinese (Traditional), and Italian. If your native language is not among these, you can request the accommodation:

    1. Visit the English as a Second Language request form on the Microsoft Learn credentials page.
    2. Submit your request before scheduling your exam.
    3. Once approved, the extra time will be applied when you schedule and take the exam.

    If the exam is available in your native language, you can still take it in English, but the additional 30 minutes will not be granted. Request this accommodation before you schedule. It cannot be added after the exam is booked.

    Can I use Microsoft Learn during the exam?

    Yes. All associate and expert role-based exams, including SC-100, give you access to Microsoft Learn during the exam.

    A "Learn" button at the bottom of the exam screen (Pearson VUE) opens Microsoft Learn in a split-screen view. You can search for documentation using the search bar at the top right. This is not available on Fundamentals or GitHub exams.

    A few things to know:

    • You can only access Microsoft Learn. No other websites, no browser tabs, no search engines.
    • CTRL+F does not work reliably in the embedded view. Use the search bar.
    • Use it to confirm specific details like service limits, SKUs, or feature availability. Do not rely on it as a substitute for preparation. Candidates who know the material well use it to verify edge cases. Candidates who rely on it consistently run out of time.

    What changed in the April 2026 update?

    Minor adjustments that align to product changes. No domains were added or removed. The official skills measured now explicitly reference AI security solutions and Security Service Edge (SSE) as evaluated capabilities. Always review the official skills measured page on Microsoft Learn before your exam date.

    What is the most important domain to study?

    SecOps/identity/compliance (25-30%) and infrastructure (25-30%) together represent 50-60% of the exam. But every domain carries enough weight that skipping one is risky. The biggest trap is over-studying the domain that matches your prerequisite certification and under-studying the others. If you hold SC-200, you likely know SecOps well, but you still need to design identity, infrastructure, and data security at an architecture level.

    What is the difference between SC-100 and my prerequisite certification?

    Your prerequisite certification tests implementation and administration: how to configure, deploy, and operate security services. SC-100 tests architecture design judgment: how to recommend solutions, evaluate competing designs, and justify security decisions based on business requirements, risk tolerance, and regulatory constraints. The question style, scope, and expected judgment are fundamentally different.

    What are the most common ways people fail?

    • Studying only the domain that matches their prerequisite. If you hold SC-300, identity feels comfortable. But SC-100 tests all four domains at an architecture level. Neglecting infrastructure or application security is a common way to fail.
    • Not knowing the MCRA diagrams. The exam expects you to understand Microsoft's capability maps, not just individual services. Review the MCRA early.
    • Ignoring Security Service Edge (SSE). It is a newer topic explicitly listed in the official skills. Make sure you understand when and why to recommend it.
    • Confusing Azure Blueprints with Azure Policy. Blueprints have been retired and replaced by deployment stacks. Do not study Blueprint-specific content.
    • Treating SC-100 like a configuration exam. The exam asks "what should you recommend?" not "how do you configure this?"
    • Underestimating AI security. The official audience profile explicitly includes AI as an area where you should have design skills. Azure OpenAI, responsible AI governance, and AI threat surfaces are in scope.

    What are the three biggest preparation mistakes?

    1. Studying service features without studying reference architectures. SC-100 is anchored in MCRA, MCSB, CAF, and WAF. Knowing individual services is not enough if you cannot map them to these frameworks.
    2. Assuming your prerequisite certification covers most of SC-100. While your prerequisite gives you hands-on depth in one area, SC-100 tests cross-domain architecture design. The question style and expected judgment are different.
    3. Not practicing case studies under time pressure. Case studies with multiple linked questions consume the most time. Practice reading requirements before background, identifying constraints quickly, and making architectural decisions under time pressure.

    Is there a renewal option?

    Yes. SC-100 is valid for 1 year. You can renew it for free by passing an online assessment on Microsoft Learn. The renewal assessment is shorter and focuses on what has changed since you originally certified. Start the renewal process before your certification expires to avoid having to retake the full exam.


    Quick-Reference: What Is on the Exam

    For the full, always-current list, visit the official SC-100 study guide.

    Domain Key Skills
    Design solutions that align with security best practices and priorities (20-25%) Ransomware resiliency (BCDR, secure backup/restore for hybrid and multicloud, privileged access prioritization), MCRA and MCSB alignment (cybersecurity capabilities, insider/external/supply chain attack protection), CAF and WAF security alignment, AI solutions alignment to Microsoft security best practices, regulatory compliance mapping (HIPAA, PCI-DSS, GDPR)
    Design security operations, identity, and compliance capabilities (25-30%) Security operations (Sentinel, playbooks, KQL, Microsoft 365 Defender integration, threat intelligence), identity and access management (Entra ID, Conditional Access, identity governance, external identities), privileged access (PIM, PAM, tiered administration, securing privileged access roadmap), regulatory compliance (Compliance Manager, compliance score, insider risk management)
    Design security solutions for infrastructure (25-30%) Security posture management (Defender for Cloud CSPM, multicloud posture, secure score), server and client endpoints (Defender for Endpoint, Defender for Cloud Apps, attack surface reduction), SaaS/PaaS/IaaS security (specifying requirements per service model), network security (Azure Firewall, DDoS, NSGs, microsegmentation), Security Service Edge (SSE) (secure web gateway, CASB, ZTNA)
    Design security solutions for applications and data (20-25%) M365 security (Defender for Office 365, information protection, compliance), application security (secure development lifecycle, threat modeling with STRIDE, API security, WAF), data security (Purview classification, sensitivity labels, DLP, encryption, rights management), AI security (Azure OpenAI security, AI threat surface, responsible AI governance, Copilot for Security)