Exam Coverage

Every AZ-500 and SC-100 objective, mapped to its unit by the appendix. Rate your own confidence on each — it's stored on this device. Nothing here is a generated question; it's the authored objective list, for tracking what's left before the exam.

AZ-500
SC-100

AZ-500 — Azure Security Engineer (operate the control)

Identity, Access & Privileged Access

  • Manage Azure built-in role assignments

  • Manage custom roles, including Azure roles and Microsoft Entra roles

  • Plan and manage Azure resources in Microsoft Entra Privileged Identity Management (PIM), including settings and assignments

  • Implement multi-factor authentication (MFA) for access to Azure resources

  • Implement Conditional Access policies for cloud resources in Azure

  • Manage access to enterprise applications in Microsoft Entra ID, including OAuth permission grants

  • Manage Microsoft Entra app registrations

  • Configure app registration permission scopes

  • Manage app registration permission consent

  • Manage and use service principals

  • Manage managed identities

Secure Networking & Edge Protection

  • Plan and implement Network Security Groups (NSGs) and Application Security Groups (ASGs)

  • Manage virtual networks by using Azure Virtual Network Manager

  • Plan and implement user-defined routes (UDRs)

  • Plan and implement Virtual Network peering or VPN gateway

  • Plan and implement Virtual WAN, including secured virtual hub

  • Secure VPN connectivity, including point-to-site and site-to-site

  • Implement encryption over ExpressRoute

  • Configure firewall settings on Azure resources

  • Monitor network security by using Network Watcher

  • Plan and implement virtual network Service Endpoints

  • Plan and implement Private Endpoints

  • Plan and implement Private Link services

  • Plan and implement network integration for Azure App Service and Azure Functions

  • Plan and implement network security configurations for an App Service Environment (ASE)

  • Plan and implement network security configurations for an Azure SQL Managed Instance

  • Plan and implement Transport Layer Security (TLS) to applications, including Azure App Service and API Management

  • Plan, implement, and manage an Azure Firewall, including Azure Firewall Manager and firewall policies

  • Plan and implement an Azure Application Gateway

  • Plan and implement an Azure Front Door, including Content Delivery Network (CDN)

  • Plan and implement a Web Application Firewall (WAF)

  • Recommend when to use Azure DDoS Protection Standard

Data, Storage & Key Management

  • Configure access control for storage accounts

  • Manage storage account access keys

  • Select and configure an appropriate method for access to Azure Files

  • Select and configure an appropriate method for access to Azure Blob Storage

  • Select and configure appropriate methods for protecting against data security threats, including soft delete, backups, versioning, and immutable storage

  • Configure Bring your own key (BYOK)

  • Enable double encryption at the Azure Storage infrastructure level

  • Enable Microsoft Entra database authentication

  • Enable database auditing

  • Plan and implement dynamic masking

  • Implement Transparent Data Encryption (TDE)

  • Recommend when to use Azure SQL Database Always Encrypted

  • Configure Azure Key Vault network settings

  • Configure access to Key Vault, including vault access policies and Azure RBAC

  • Manage certificates, secrets, and keys in Key Vault

  • Configure key rotation

  • Perform backup and recovery of certificates, secrets, and keys

Unit 4 — Secure Compute, Containers & Endpoint Baselines

  • Plan and implement remote access to virtual machines, including Azure Bastion and just-in-time (JIT) VM access

  • Configure network isolation for Azure Kubernetes Service (AKS)

  • Secure and monitor AKS

  • Configure authentication for AKS

  • Configure security monitoring for Azure Container Instances (ACIs)

  • Configure security monitoring for Azure Container Apps (ACAs)

  • Manage access to Azure Container Registry (ACR)

  • Configure disk encryption, including Azure Disk Encryption (ADE), encryption at host, and confidential disk encryption

Unit 5 — Posture, Governance, Compliance & Multicloud

  • Create, assign, and interpret policies and initiatives in Azure Policy

  • Implement security controls to protect backups

  • Implement security controls for asset management

  • Identify and remediate security risks by using the Microsoft Defender for Cloud Secure Score and Inventory

  • Assess compliance against security frameworks by using Microsoft Defender for Cloud

  • Manage compliance standards in Microsoft Defender for Cloud

  • Add custom standards to Microsoft Defender for Cloud

  • Connect hybrid cloud and multi-cloud environments to Microsoft Defender for Cloud, including AWS and GCP

  • Implement and use Microsoft Defender External Attack Surface Management (EASM)

  • Enable cloud workload protection plans in Microsoft Defender for Cloud

  • Configure Microsoft Defender for Servers, Microsoft Defender for Databases, and Microsoft Defender for Storage

  • Implement and manage agentless scanning for virtual machines in Microsoft Defender for Servers

  • Implement and manage Microsoft Defender Vulnerability Management for Azure virtual machines

  • Connect to and configure settings in Microsoft Defender for Cloud DevOps Security, including GitHub, Azure DevOps, and GitLab

Security Operations: Sentinel SIEM, Defender XDR, SOAR & MITRE ATT&CK

  • Manage and respond to security alerts in Microsoft Defender for Cloud

  • Configure workflow automation by using Microsoft Defender for Cloud

  • Monitor network security events and performance data by configuring data collection rules (DCRs) in Azure Monitor

  • Configure data connectors in Microsoft Sentinel

  • Enable analytics rules in Microsoft Sentinel

  • Configure automation in Microsoft Sentinel

Application, API & M365 Data-Protection Architecture

  • Recommend security configurations for Azure API Management

SC-100 — Cybersecurity Architect (design & evaluate)

Identity, Access & Privileged Access

  • Design a solution for access to SaaS, PaaS, IaaS, hybrid/on-premises, and multicloud resources, including identity, networking, and application controls

  • Design a solution for Microsoft Entra ID, including hybrid and multi-cloud environments

  • Design a solution for external identities, including B2B and decentralized identity

  • Design a modern authentication and authorization strategy, including Conditional Access, continuous access evaluation, risk scoring, and protected actions

  • Validate the alignment of Conditional Access policies with a Zero Trust strategy

  • Specify requirements to harden Active Directory Domain Services (AD DS)

  • Design a solution for assigning and delegating privileged roles by using the enterprise access model

  • Evaluate the security and governance of Microsoft Entra ID, including PIM, entitlement management, and access reviews

  • Evaluate the security and governance of AD DS, including resilience to common attacks

  • Design a solution for securing the administration of cloud tenants, including SaaS and multicloud infrastructure

  • Design a solution for cloud infrastructure entitlement management

  • Evaluate an access review management solution

  • Design a solution for secure workstations for privileged access, including remote access

  • Design a solution for workload identities to authenticate and access Azure resources

Secure Networking & Edge Protection

  • Evaluate network designs to align with security requirements and best practices

  • Evaluate solutions that use Microsoft Entra Internet Access as a secure web gateway

  • Evaluate solutions that use Microsoft Entra Internet Access for Microsoft Services, including cross-tenant configurations

  • Evaluate solutions that use Microsoft Entra Private Access

Data, Storage & Key Management

  • Design a solution to manage secrets, keys, and certificates

  • Evaluate solutions for data discovery and classification

  • Specify priorities for mitigating threats to data

  • Evaluate solutions for encryption of data at rest and in transit, including Azure Key Vault and infrastructure encryption

  • Design a security solution for data in Azure workloads, including Azure SQL, Azure Synapse Analytics, and Azure Cosmos DB

  • Design a security solution for data in Azure Storage

  • Design a security solution that includes Microsoft Defender for Storage and Microsoft Defender for Databases

Unit 4 — Secure Compute, Containers & Endpoint Baselines

  • Specify security requirements for servers, including multiple platforms and operating systems

  • Specify security requirements for mobile devices and clients, including endpoint protection, hardening, and configuration

  • Specify security requirements for IoT devices and embedded systems

  • Evaluate solutions for securing OT and ICS by using Microsoft Defender for IoT

  • Specify security baselines for server and client endpoints

  • Evaluate Windows Local Administrator Password Solution (Windows LAPS)

  • Specify security baselines for SaaS, PaaS, and IaaS services

  • Specify security requirements for IoT workloads

  • Specify security requirements for containers

  • Specify security requirements for container orchestration

  • Evaluate solutions that include Azure AI services security

Unit 5 — Posture, Governance, Compliance & Multicloud

  • Evaluate security posture by using Microsoft Defender for Cloud, including the MCSB

  • Evaluate security posture by using Microsoft Secure Score

  • Design integrated security posture management solutions that include Microsoft Defender for Cloud in hybrid and multi-cloud environments

  • Select cloud workload protection solutions in Microsoft Defender for Cloud

  • Design a solution for integrating hybrid and multicloud environments by using Azure Arc

  • Design a solution for Microsoft Defender External Attack Surface Management (Defender EASM)

  • Specify requirements and priorities for a posture management process that uses Microsoft Security Exposure Management attack paths, attack surface reduction, security insights, and initiatives

  • Design Azure Policy solutions to address security and compliance requirements

  • Evaluate and validate alignment with regulatory standards and benchmarks by using Microsoft Defender for Cloud

  • Translate compliance requirements into security controls

  • Design a solution to address compliance requirements by using Microsoft Purview

  • Design a solution to address privacy requirements, including Microsoft Priva

Security Operations: Sentinel SIEM, Defender XDR, SOAR & MITRE ATT&CK

  • Design a solution for detection and response that includes XDR and SIEM

  • Design a solution for centralized logging and auditing, including Microsoft Purview Audit

  • Design monitoring to support hybrid and multicloud environments

  • Design a solution for security orchestration and automated response (SOAR), including Microsoft Sentinel and Microsoft Defender XDR

  • Design and evaluate security workflows, including incident response, threat hunting, and incident management

  • Design and evaluate threat detection coverage by using MITRE ATT&CK matrices, including Enterprise, Mobile, and ICS

Application, API & M365 Data-Protection Architecture

  • Evaluate security posture for productivity and collaboration workloads by using metrics, including Microsoft Secure Score

  • Evaluate solutions that include Microsoft Defender for Office 365 and Microsoft Defender for Cloud Apps

  • Evaluate device management solutions that include Microsoft Intune

  • Evaluate solutions for securing data in Microsoft 365 by using Microsoft Purview

  • Evaluate data security and compliance controls in Microsoft Copilot for Microsoft 365 services

  • Evaluate the security posture of existing application portfolios

  • Evaluate threats to business-critical applications by using threat modeling

  • Design and implement a full lifecycle strategy for application security

  • Design and implement standards and practices for securing the application development process

  • Map technologies to application security requirements

  • Design a solution for API management and security

  • Design solutions that secure applications by using Azure Web Application Firewall (WAF)

  • Specify security requirements for web workloads

  • Design a resiliency strategy for ransomware and other attacks based on Microsoft Security Best Practices

  • Design a security strategy to support business resiliency goals, including identifying and prioritizing threats to business-critical assets

  • Design solutions for business continuity and disaster recovery (BCDR), including secure backup and restore for hybrid and multicloud environments

  • Design solutions for mitigating ransomware attacks, including prioritization of BCDR and privileged access

  • Evaluate solutions for security updates

  • Design solutions that align with the Microsoft Cybersecurity Reference Architectures (MCRA) and Microsoft cloud security benchmark (MCSB)

  • Design solutions that align with best practices for cybersecurity capabilities and controls

  • Design solutions that align with best practices for protecting against insider, external, and supply chain attacks

  • Design solutions that align with best practices for Zero Trust security, including A Rapid Modernization Plan for Zero Trust (RaMP)

  • Design solutions that align with the Microsoft Cloud Adoption Framework for Azure (CAF) and the Azure Well-Architected Framework (WAF)

  • Design a new or evaluate an existing strategy for security and governance based on CAF and WAF

  • Recommend solutions for security and governance based on CAF and WAF

  • Design solutions for implementing and governing security by using Azure landing zones

  • Design a DevSecOps process that aligns with best practices in the Microsoft Cloud Adoption Framework for Azure (CAF)