Exam Coverage
Every AZ-500 and SC-100 objective, mapped to its unit by the appendix. Rate your own confidence on each — it's stored on this device. Nothing here is a generated question; it's the authored objective list, for tracking what's left before the exam.
AZ-500 — Azure Security Engineer (operate the control)
Identity, Access & Privileged Access
-
Manage Azure built-in role assignments
-
Manage custom roles, including Azure roles and Microsoft Entra roles
-
Plan and manage Azure resources in Microsoft Entra Privileged Identity Management (PIM), including settings and assignments
-
Implement multi-factor authentication (MFA) for access to Azure resources
-
Implement Conditional Access policies for cloud resources in Azure
-
Manage access to enterprise applications in Microsoft Entra ID, including OAuth permission grants
-
Manage Microsoft Entra app registrations
-
Configure app registration permission scopes
-
Manage app registration permission consent
-
Manage and use service principals
-
Manage managed identities
Secure Networking & Edge Protection
-
Plan and implement Network Security Groups (NSGs) and Application Security Groups (ASGs)
-
Manage virtual networks by using Azure Virtual Network Manager
-
Plan and implement user-defined routes (UDRs)
-
Plan and implement Virtual Network peering or VPN gateway
-
Plan and implement Virtual WAN, including secured virtual hub
-
Secure VPN connectivity, including point-to-site and site-to-site
-
Implement encryption over ExpressRoute
-
Configure firewall settings on Azure resources
-
Monitor network security by using Network Watcher
-
Plan and implement virtual network Service Endpoints
-
Plan and implement Private Endpoints
-
Plan and implement Private Link services
-
Plan and implement network integration for Azure App Service and Azure Functions
-
Plan and implement network security configurations for an App Service Environment (ASE)
-
Plan and implement network security configurations for an Azure SQL Managed Instance
-
Plan and implement Transport Layer Security (TLS) to applications, including Azure App Service and API Management
-
Plan, implement, and manage an Azure Firewall, including Azure Firewall Manager and firewall policies
-
Plan and implement an Azure Application Gateway
-
Plan and implement an Azure Front Door, including Content Delivery Network (CDN)
-
Plan and implement a Web Application Firewall (WAF)
-
Recommend when to use Azure DDoS Protection Standard
Data, Storage & Key Management
-
Configure access control for storage accounts
-
Manage storage account access keys
-
Select and configure an appropriate method for access to Azure Files
-
Select and configure an appropriate method for access to Azure Blob Storage
-
Select and configure appropriate methods for protecting against data security threats, including soft delete, backups, versioning, and immutable storage
-
Configure Bring your own key (BYOK)
-
Enable double encryption at the Azure Storage infrastructure level
-
Enable Microsoft Entra database authentication
-
Enable database auditing
-
Plan and implement dynamic masking
-
Implement Transparent Data Encryption (TDE)
-
Recommend when to use Azure SQL Database Always Encrypted
-
Configure Azure Key Vault network settings
-
Configure access to Key Vault, including vault access policies and Azure RBAC
-
Manage certificates, secrets, and keys in Key Vault
-
Configure key rotation
-
Perform backup and recovery of certificates, secrets, and keys
Unit 4 — Secure Compute, Containers & Endpoint Baselines
-
Plan and implement remote access to virtual machines, including Azure Bastion and just-in-time (JIT) VM access
-
Configure network isolation for Azure Kubernetes Service (AKS)
-
Secure and monitor AKS
-
Configure authentication for AKS
-
Configure security monitoring for Azure Container Instances (ACIs)
-
Configure security monitoring for Azure Container Apps (ACAs)
-
Manage access to Azure Container Registry (ACR)
-
Configure disk encryption, including Azure Disk Encryption (ADE), encryption at host, and confidential disk encryption
Unit 5 — Posture, Governance, Compliance & Multicloud
-
Create, assign, and interpret policies and initiatives in Azure Policy
-
Implement security controls to protect backups
-
Implement security controls for asset management
-
Identify and remediate security risks by using the Microsoft Defender for Cloud Secure Score and Inventory
-
Assess compliance against security frameworks by using Microsoft Defender for Cloud
-
Manage compliance standards in Microsoft Defender for Cloud
-
Add custom standards to Microsoft Defender for Cloud
-
Connect hybrid cloud and multi-cloud environments to Microsoft Defender for Cloud, including AWS and GCP
-
Implement and use Microsoft Defender External Attack Surface Management (EASM)
-
Enable cloud workload protection plans in Microsoft Defender for Cloud
-
Configure Microsoft Defender for Servers, Microsoft Defender for Databases, and Microsoft Defender for Storage
-
Implement and manage agentless scanning for virtual machines in Microsoft Defender for Servers
-
Implement and manage Microsoft Defender Vulnerability Management for Azure virtual machines
-
Connect to and configure settings in Microsoft Defender for Cloud DevOps Security, including GitHub, Azure DevOps, and GitLab
Security Operations: Sentinel SIEM, Defender XDR, SOAR & MITRE ATT&CK
-
Manage and respond to security alerts in Microsoft Defender for Cloud
-
Configure workflow automation by using Microsoft Defender for Cloud
-
Monitor network security events and performance data by configuring data collection rules (DCRs) in Azure Monitor
-
Configure data connectors in Microsoft Sentinel
-
Enable analytics rules in Microsoft Sentinel
-
Configure automation in Microsoft Sentinel
Application, API & M365 Data-Protection Architecture
-
Recommend security configurations for Azure API Management
SC-100 — Cybersecurity Architect (design & evaluate)
Identity, Access & Privileged Access
-
Design a solution for access to SaaS, PaaS, IaaS, hybrid/on-premises, and multicloud resources, including identity, networking, and application controls
-
Design a solution for Microsoft Entra ID, including hybrid and multi-cloud environments
-
Design a solution for external identities, including B2B and decentralized identity
-
Design a modern authentication and authorization strategy, including Conditional Access, continuous access evaluation, risk scoring, and protected actions
-
Validate the alignment of Conditional Access policies with a Zero Trust strategy
-
Specify requirements to harden Active Directory Domain Services (AD DS)
-
Design a solution for assigning and delegating privileged roles by using the enterprise access model
-
Evaluate the security and governance of Microsoft Entra ID, including PIM, entitlement management, and access reviews
-
Evaluate the security and governance of AD DS, including resilience to common attacks
-
Design a solution for securing the administration of cloud tenants, including SaaS and multicloud infrastructure
-
Design a solution for cloud infrastructure entitlement management
-
Evaluate an access review management solution
-
Design a solution for secure workstations for privileged access, including remote access
-
Design a solution for workload identities to authenticate and access Azure resources
Secure Networking & Edge Protection
-
Evaluate network designs to align with security requirements and best practices
-
Evaluate solutions that use Microsoft Entra Internet Access as a secure web gateway
-
Evaluate solutions that use Microsoft Entra Internet Access for Microsoft Services, including cross-tenant configurations
-
Evaluate solutions that use Microsoft Entra Private Access
Data, Storage & Key Management
-
Design a solution to manage secrets, keys, and certificates
-
Evaluate solutions for data discovery and classification
-
Specify priorities for mitigating threats to data
-
Evaluate solutions for encryption of data at rest and in transit, including Azure Key Vault and infrastructure encryption
-
Design a security solution for data in Azure workloads, including Azure SQL, Azure Synapse Analytics, and Azure Cosmos DB
-
Design a security solution for data in Azure Storage
-
Design a security solution that includes Microsoft Defender for Storage and Microsoft Defender for Databases
Unit 4 — Secure Compute, Containers & Endpoint Baselines
-
Specify security requirements for servers, including multiple platforms and operating systems
-
Specify security requirements for mobile devices and clients, including endpoint protection, hardening, and configuration
-
Specify security requirements for IoT devices and embedded systems
-
Evaluate solutions for securing OT and ICS by using Microsoft Defender for IoT
-
Specify security baselines for server and client endpoints
-
Evaluate Windows Local Administrator Password Solution (Windows LAPS)
-
Specify security baselines for SaaS, PaaS, and IaaS services
-
Specify security requirements for IoT workloads
-
Specify security requirements for containers
-
Specify security requirements for container orchestration
-
Evaluate solutions that include Azure AI services security
Unit 5 — Posture, Governance, Compliance & Multicloud
-
Evaluate security posture by using Microsoft Defender for Cloud, including the MCSB
-
Evaluate security posture by using Microsoft Secure Score
-
Design integrated security posture management solutions that include Microsoft Defender for Cloud in hybrid and multi-cloud environments
-
Select cloud workload protection solutions in Microsoft Defender for Cloud
-
Design a solution for integrating hybrid and multicloud environments by using Azure Arc
-
Design a solution for Microsoft Defender External Attack Surface Management (Defender EASM)
-
Specify requirements and priorities for a posture management process that uses Microsoft Security Exposure Management attack paths, attack surface reduction, security insights, and initiatives
-
Design Azure Policy solutions to address security and compliance requirements
-
Evaluate and validate alignment with regulatory standards and benchmarks by using Microsoft Defender for Cloud
-
Translate compliance requirements into security controls
-
Design a solution to address compliance requirements by using Microsoft Purview
-
Design a solution to address privacy requirements, including Microsoft Priva
Security Operations: Sentinel SIEM, Defender XDR, SOAR & MITRE ATT&CK
-
Design a solution for detection and response that includes XDR and SIEM
-
Design a solution for centralized logging and auditing, including Microsoft Purview Audit
-
Design monitoring to support hybrid and multicloud environments
-
Design a solution for security orchestration and automated response (SOAR), including Microsoft Sentinel and Microsoft Defender XDR
-
Design and evaluate security workflows, including incident response, threat hunting, and incident management
-
Design and evaluate threat detection coverage by using MITRE ATT&CK matrices, including Enterprise, Mobile, and ICS
Application, API & M365 Data-Protection Architecture
-
Evaluate security posture for productivity and collaboration workloads by using metrics, including Microsoft Secure Score
-
Evaluate solutions that include Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps
-
Evaluate device management solutions that include Microsoft Intune
-
Evaluate solutions for securing data in Microsoft 365 by using Microsoft Purview
-
Evaluate data security and compliance controls in Microsoft Copilot for Microsoft 365 services
-
Evaluate the security posture of existing application portfolios
-
Evaluate threats to business-critical applications by using threat modeling
-
Design and implement a full lifecycle strategy for application security
-
Design and implement standards and practices for securing the application development process
-
Map technologies to application security requirements
-
Design a solution for API management and security
-
Design solutions that secure applications by using Azure Web Application Firewall (WAF)
-
Specify security requirements for web workloads
-
Design a resiliency strategy for ransomware and other attacks based on Microsoft Security Best Practices
-
Design a security strategy to support business resiliency goals, including identifying and prioritizing threats to business-critical assets
-
Design solutions for business continuity and disaster recovery (BCDR), including secure backup and restore for hybrid and multicloud environments
-
Design solutions for mitigating ransomware attacks, including prioritization of BCDR and privileged access
-
Evaluate solutions for security updates
-
Design solutions that align with the Microsoft Cybersecurity Reference Architectures (MCRA) and Microsoft cloud security benchmark (MCSB)
-
Design solutions that align with best practices for cybersecurity capabilities and controls
-
Design solutions that align with best practices for protecting against insider, external, and supply chain attacks
-
Design solutions that align with best practices for Zero Trust security, including A Rapid Modernization Plan for Zero Trust (RaMP)
-
Design solutions that align with the Microsoft Cloud Adoption Framework for Azure (CAF) and the Azure Well-Architected Framework (WAF)
-
Design a new or evaluate an existing strategy for security and governance based on CAF and WAF
-
Recommend solutions for security and governance based on CAF and WAF
-
Design solutions for implementing and governing security by using Azure landing zones
-
Design a DevSecOps process that aligns with best practices in the Microsoft Cloud Adoption Framework for Azure (CAF)