Exam Coverage
Every AZ-500 and SC-100 objective, mapped to its unit by the appendix. Rate your own confidence on each — it's stored on this device. Nothing here is a generated question; it's the authored objective list, for tracking what's left before the exam.
AZ-500 — Azure Security Engineer (operate the control)
Identity, Access & Privileged Access
Manage Azure built-in role assignments
Manage custom roles, including Azure roles and Microsoft Entra roles
Plan and manage Azure resources in Microsoft Entra Privileged Identity Management (PIM), including settings and assignments
Implement multi-factor authentication (MFA) for access to Azure resources
Implement Conditional Access policies for cloud resources in Azure
Manage access to enterprise applications in Microsoft Entra ID, including OAuth permission grants
Manage Microsoft Entra app registrations
Configure app registration permission scopes
Manage app registration permission consent
Manage and use service principals
Manage managed identities
Secure Networking & Edge Protection
Plan and implement Network Security Groups (NSGs) and Application Security Groups (ASGs)
Manage virtual networks by using Azure Virtual Network Manager
Plan and implement user-defined routes (UDRs)
Plan and implement Virtual Network peering or VPN gateway
Plan and implement Virtual WAN, including secured virtual hub
Secure VPN connectivity, including point-to-site and site-to-site
Implement encryption over ExpressRoute
Configure firewall settings on Azure resources
Monitor network security by using Network Watcher
Plan and implement virtual network Service Endpoints
Plan and implement Private Endpoints
Plan and implement Private Link services
Plan and implement network integration for Azure App Service and Azure Functions
Plan and implement network security configurations for an App Service Environment (ASE)
Plan and implement network security configurations for an Azure SQL Managed Instance
Plan and implement Transport Layer Security (TLS) to applications, including Azure App Service and API Management
Plan, implement, and manage an Azure Firewall, including Azure Firewall Manager and firewall policies
Plan and implement an Azure Application Gateway
Plan and implement an Azure Front Door, including Content Delivery Network (CDN)
Plan and implement a Web Application Firewall (WAF)
Recommend when to use Azure DDoS Protection Standard
Data, Storage & Key Management
Configure access control for storage accounts
Manage storage account access keys
Select and configure an appropriate method for access to Azure Files
Select and configure an appropriate method for access to Azure Blob Storage
Select and configure appropriate methods for protecting against data security threats, including soft delete, backups, versioning, and immutable storage
Configure Bring your own key (BYOK)
Enable double encryption at the Azure Storage infrastructure level
Enable Microsoft Entra database authentication
Enable database auditing
Plan and implement dynamic masking
Implement Transparent Data Encryption (TDE)
Recommend when to use Azure SQL Database Always Encrypted
Configure Azure Key Vault network settings
Configure access to Key Vault, including vault access policies and Azure RBAC
Manage certificates, secrets, and keys in Key Vault
Configure key rotation
Perform backup and recovery of certificates, secrets, and keys
Unit 4 — Secure Compute, Containers & Endpoint Baselines
Plan and implement remote access to virtual machines, including Azure Bastion and just-in-time (JIT) VM access
Configure network isolation for Azure Kubernetes Service (AKS)
Secure and monitor AKS
Configure authentication for AKS
Configure security monitoring for Azure Container Instances (ACIs)
Configure security monitoring for Azure Container Apps (ACAs)
Manage access to Azure Container Registry (ACR)
Configure disk encryption, including Azure Disk Encryption (ADE), encryption at host, and confidential disk encryption
Unit 5 — Posture, Governance, Compliance & Multicloud
Create, assign, and interpret policies and initiatives in Azure Policy
Implement security controls to protect backups
Implement security controls for asset management
Identify and remediate security risks by using the Microsoft Defender for Cloud Secure Score and Inventory
Assess compliance against security frameworks by using Microsoft Defender for Cloud
Manage compliance standards in Microsoft Defender for Cloud
Add custom standards to Microsoft Defender for Cloud
Connect hybrid cloud and multi-cloud environments to Microsoft Defender for Cloud, including AWS and GCP
Implement and use Microsoft Defender External Attack Surface Management (EASM)
Enable cloud workload protection plans in Microsoft Defender for Cloud
Configure Microsoft Defender for Servers, Microsoft Defender for Databases, and Microsoft Defender for Storage
Implement and manage agentless scanning for virtual machines in Microsoft Defender for Servers
Implement and manage Microsoft Defender Vulnerability Management for Azure virtual machines
Connect to and configure settings in Microsoft Defender for Cloud DevOps Security, including GitHub, Azure DevOps, and GitLab
Security Operations: Sentinel SIEM, Defender XDR, SOAR & MITRE ATT&CK
Manage and respond to security alerts in Microsoft Defender for Cloud
Configure workflow automation by using Microsoft Defender for Cloud
Monitor network security events and performance data by configuring data collection rules (DCRs) in Azure Monitor
Configure data connectors in Microsoft Sentinel
Enable analytics rules in Microsoft Sentinel
Configure automation in Microsoft Sentinel
Application, API & M365 Data-Protection Architecture
Recommend security configurations for Azure API Management
SC-100 — Cybersecurity Architect (design & evaluate)
Identity, Access & Privileged Access
Design a solution for access to SaaS, PaaS, IaaS, hybrid/on-premises, and multicloud resources, including identity, networking, and application controls
Design a solution for Microsoft Entra ID, including hybrid and multi-cloud environments
Design a solution for external identities, including B2B and decentralized identity
Design a modern authentication and authorization strategy, including Conditional Access, continuous access evaluation, risk scoring, and protected actions
Validate the alignment of Conditional Access policies with a Zero Trust strategy
Specify requirements to harden Active Directory Domain Services (AD DS)
Design a solution for assigning and delegating privileged roles by using the enterprise access model
Evaluate the security and governance of Microsoft Entra ID, including PIM, entitlement management, and access reviews
Evaluate the security and governance of AD DS, including resilience to common attacks
Design a solution for securing the administration of cloud tenants, including SaaS and multicloud infrastructure
Design a solution for cloud infrastructure entitlement management
Evaluate an access review management solution
Design a solution for secure workstations for privileged access, including remote access
Design a solution for workload identities to authenticate and access Azure resources
Secure Networking & Edge Protection
Evaluate network designs to align with security requirements and best practices
Evaluate solutions that use Microsoft Entra Internet Access as a secure web gateway
Evaluate solutions that use Microsoft Entra Internet Access for Microsoft Services, including cross-tenant configurations
Evaluate solutions that use Microsoft Entra Private Access
Data, Storage & Key Management
Design a solution to manage secrets, keys, and certificates
Evaluate solutions for data discovery and classification
Specify priorities for mitigating threats to data
Evaluate solutions for encryption of data at rest and in transit, including Azure Key Vault and infrastructure encryption
Design a security solution for data in Azure workloads, including Azure SQL, Azure Synapse Analytics, and Azure Cosmos DB
Design a security solution for data in Azure Storage
Design a security solution that includes Microsoft Defender for Storage and Microsoft Defender for Databases
Unit 4 — Secure Compute, Containers & Endpoint Baselines
Specify security requirements for servers, including multiple platforms and operating systems
Specify security requirements for mobile devices and clients, including endpoint protection, hardening, and configuration
Specify security requirements for IoT devices and embedded systems
Evaluate solutions for securing OT and ICS by using Microsoft Defender for IoT
Specify security baselines for server and client endpoints
Evaluate Windows Local Administrator Password Solution (Windows LAPS)
Specify security baselines for SaaS, PaaS, and IaaS services
Specify security requirements for IoT workloads
Specify security requirements for containers
Specify security requirements for container orchestration
Evaluate solutions that include Azure AI services security
Unit 5 — Posture, Governance, Compliance & Multicloud
Evaluate security posture by using Microsoft Defender for Cloud, including the MCSB
Evaluate security posture by using Microsoft Secure Score
Design integrated security posture management solutions that include Microsoft Defender for Cloud in hybrid and multi-cloud environments
Select cloud workload protection solutions in Microsoft Defender for Cloud
Design a solution for integrating hybrid and multicloud environments by using Azure Arc
Design a solution for Microsoft Defender External Attack Surface Management (Defender EASM)
Specify requirements and priorities for a posture management process that uses Microsoft Security Exposure Management attack paths, attack surface reduction, security insights, and initiatives
Design Azure Policy solutions to address security and compliance requirements
Evaluate and validate alignment with regulatory standards and benchmarks by using Microsoft Defender for Cloud
Translate compliance requirements into security controls
Design a solution to address compliance requirements by using Microsoft Purview
Design a solution to address privacy requirements, including Microsoft Priva
Security Operations: Sentinel SIEM, Defender XDR, SOAR & MITRE ATT&CK
Design a solution for detection and response that includes XDR and SIEM
Design a solution for centralized logging and auditing, including Microsoft Purview Audit
Design monitoring to support hybrid and multicloud environments
Design a solution for security orchestration and automated response (SOAR), including Microsoft Sentinel and Microsoft Defender XDR
Design and evaluate security workflows, including incident response, threat hunting, and incident management
Design and evaluate threat detection coverage by using MITRE ATT&CK matrices, including Enterprise, Mobile, and ICS
Application, API & M365 Data-Protection Architecture
Evaluate security posture for productivity and collaboration workloads by using metrics, including Microsoft Secure Score
Evaluate solutions that include Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps
Evaluate device management solutions that include Microsoft Intune
Evaluate solutions for securing data in Microsoft 365 by using Microsoft Purview
Evaluate data security and compliance controls in Microsoft Copilot for Microsoft 365 services
Evaluate the security posture of existing application portfolios
Evaluate threats to business-critical applications by using threat modeling
Design and implement a full lifecycle strategy for application security
Design and implement standards and practices for securing the application development process
Map technologies to application security requirements
Design a solution for API management and security
Design solutions that secure applications by using Azure Web Application Firewall (WAF)
Specify security requirements for web workloads
Design a resiliency strategy for ransomware and other attacks based on Microsoft Security Best Practices
Design a security strategy to support business resiliency goals, including identifying and prioritizing threats to business-critical assets
Design solutions for business continuity and disaster recovery (BCDR), including secure backup and restore for hybrid and multicloud environments
Design solutions for mitigating ransomware attacks, including prioritization of BCDR and privileged access
Evaluate solutions for security updates
Design solutions that align with the Microsoft Cybersecurity Reference Architectures (MCRA) and Microsoft cloud security benchmark (MCSB)
Design solutions that align with best practices for cybersecurity capabilities and controls
Design solutions that align with best practices for protecting against insider, external, and supply chain attacks
Design solutions that align with best practices for Zero Trust security, including A Rapid Modernization Plan for Zero Trust (RaMP)
Design solutions that align with the Microsoft Cloud Adoption Framework for Azure (CAF) and the Azure Well-Architected Framework (WAF)
Design a new or evaluate an existing strategy for security and governance based on CAF and WAF
Recommend solutions for security and governance based on CAF and WAF
Design solutions for implementing and governing security by using Azure landing zones
Design a DevSecOps process that aligns with best practices in the Microsoft Cloud Adoption Framework for Azure (CAF)