SC-100 · Expert

SC-100 Cheat Sheet 2026: Quick Reference for the Cybersecurity Architect Exam

All 4 domains as scannable tables, the MCRA/MCSB/CAF/WAF framework guide people mix up most, and the AZ-500/SC-200/SC-300 prerequisite reference.

Quick Facts

Certification: Cybersecurity Architect Expert
Passing score: 700 / 1000
Fee: $165 USD
Level: Expert
Required exams: SC-100 + 1 of 3 prerequisite certs
Skills measured as of: July 28, 2026

The domain weights, terminology, and reference links here come straight from Microsoft's official SC-100 exam page. We re-check them against our audited 500-question SC-100 practice bank so nothing drifts out of date.

Domain 1: Security Best Practices and Priorities (20-25%)

ConceptSub-areaQuick note
Ransomware/BCDR resiliencyBest practicesMicrosoft prioritizes secure backup + privileged-access reduction over detection tooling
Business continuity & disaster recovery (BCDR)Best practicesSecure backup/restore design for hybrid and multicloud environments
Microsoft Cybersecurity Reference Architecture (MCRA)FrameworksConceptual map of how security capabilities relate — not a scored checklist
Microsoft Cloud Security Benchmark (MCSB)FrameworksThe scored control baseline Defender for Cloud evaluates configurations against
Cloud Adoption Framework (CAF)FrameworksGoverns the broader cloud adoption/migration lifecycle, including landing zones
Well-Architected Framework (WAF)FrameworksEvaluates workload design quality; security is one of five pillars
Azure landing zonesGovernanceCAF's mechanism for baking governance into every new subscription by default
DevSecOps process designGovernanceSecurity integrated into the CI/CD pipeline, not bolted on after deployment
Secure AI adoption strategyEmergingNewer skills-measured item — governance for AI workload rollout specifically

Domain 2: Security Operations, Identity, and Compliance (25-30%)

ConceptSub-areaQuick note
SIEM/XDR design (Sentinel + Defender XDR)SecOpsCentralizes detection across identity, endpoint, and cloud signal
SOAR — automation rules & playbooksSecOpsAutomates response to high-confidence incidents without manual triage
MITRE ATT&CK coverage mappingSecOpsEvaluates detection coverage against Enterprise, Mobile, and ICS matrices
Microsoft Entra Agent ID & Conditional Access for agentsIdentityNewer skills-measured item — identity for autonomous AI agents specifically
Microsoft Entra B2B & decentralized identityIdentityExternal-identity federation without creating local accounts for partners
Continuous access evaluation & risk-based Conditional AccessIdentityModern authentication strategy beyond static sign-in rules
Enterprise access model + Privileged Identity Management (PIM)Privileged accessJust-in-time, time-bound, approval-gated role activation — never standing access
AD DS hardening requirementsPrivileged accessOn-premises Active Directory resilience to common attack patterns
Compliance via Microsoft Purview & Azure PolicyComplianceTranslating regulatory requirements into enforceable technical controls

Cross-referencing while you study?

Drill each domain above with MSCertQuiz's 500-question SC-100 bank — 40 questions free to start.

Start Free SC-100 Practice

Domain 3: Security Solutions for Infrastructure (25-30%)

ConceptSub-areaQuick note
Defender for Cloud posture across hybrid/multicloudPosture mgmtExtends to AWS/on-prem once onboarded via Azure Arc
Microsoft Secure ScorePosture mgmtA different scored signal than MCSB — tenant-wide, not just cloud config
Defender External Attack Surface Management (EASM)Posture mgmtDiscovers internet-facing assets the org may not know it owns
Microsoft Security Exposure ManagementPosture mgmtAttack-path analysis and attack-surface reduction, newer emphasis
Server & client endpoint baselinesEndpointsCovers multiple OS platforms, not just Windows
Defender for IoT (OT/ICS)EndpointsPassive, agentless monitoring for legacy industrial devices that can't run agents
Windows LAPS evaluationEndpointsRandomized local admin passwords as a specific endpoint control
SaaS/PaaS/IaaS security baselines, containersCloud servicesRequirements differ meaningfully by service model
Security Service Edge: Entra Internet Access vs. Entra Private AccessNetwork/SSEOutbound internet filtering (Internet Access) vs. inbound private-app access (Private Access) — commonly confused

Domain 4: Security Solutions for Applications and Data (20-25%)

ConceptSub-areaQuick note
Microsoft 365 posture (Secure Score for collaboration)M365 securityA distinct Secure Score view scoped to productivity workloads
Defender for Office 365 & Defender for Cloud AppsM365 securityEmail/collaboration threats vs. broader SaaS visibility — different tools
Copilot for M365 data security controlsM365 securityNewer skills-measured item — evaluating Purview controls specific to Copilot
Threat modeling & full-lifecycle app securityApp securityIdentifies attack vectors during design, before code is scanned
Workload identities for Azure resource accessApp securityNon-human identities authenticating to Azure — a distinct identity category
API management & security, Azure WAFApp securityTwo different control layers: API gateway policy vs. web traffic filtering
Data discovery & classification (Purview)Data securityPrerequisite step before you can prioritize which data to protect first
Encryption at rest/in transit, Azure Key VaultData securityKey management is a distinct design decision from the encryption itself
Security for data used in AI workloadsData securityA specifically called-out skills-measured item, not folded into general data security

Framework Quick Reference: MCRA vs. MCSB vs. CAF vs. WAF

These four get tested both directly and indirectly, and their names are easy to blur together under time pressure:

AcronymFull nameWhat it actually is
MCRAMicrosoft Cybersecurity Reference ArchitectureConceptual guidance for how security capabilities fit together across an org
MCSBMicrosoft Cloud Security BenchmarkScored control baseline you evaluate a cloud configuration against
CAFCloud Adoption FrameworkGoverns the strategy, planning, and adoption lifecycle for moving to Azure
WAFWell-Architected FrameworkEvaluates workload design quality across 5 pillars; security is one of them

SC-100 Prerequisite Path Reference

Per Microsoft's certification page (checked August 4, 2026), earning the Cybersecurity Architect Expert credential requires SC-100 plus one of these three, held either before or within one year after passing SC-100:

ExamCertificationStatus
AZ-500Azure Security Engineer AssociateRetires August 31, 2026 — still valid as an SC-100 prerequisite for 1 year if passed before then
SC-200Security Operations Analyst AssociateNo scheduled retirement as of this check
SC-300Identity and Access Administrator AssociateNo scheduled retirement as of this check

SC-100 Acronym Glossary

AcronymStands forWhat it means on the exam
BCDRBusiness Continuity and Disaster RecoverySecure backup/restore design, prioritized ahead of detection tooling for ransomware
GRCGovernance, Risk, and ComplianceThe umbrella category covering Domain 2's compliance-design skills
XDRExtended Detection and ResponseCross-signal threat detection — Defender XDR is Microsoft's implementation
SIEMSecurity Information and Event ManagementCentralized log analysis and correlation — Microsoft Sentinel
SOARSecurity Orchestration and Automated ResponseAutomation rules/playbooks that act on incidents without manual triage
PIMPrivileged Identity ManagementJust-in-time, approval-gated role activation inside Microsoft Entra ID
EASMExternal Attack Surface ManagementDiscovers internet-facing assets an org may not know it owns
SSESecurity Service EdgeUmbrella term covering Entra Internet Access and Entra Private Access
ICSIndustrial Control SystemsFactory-floor/OT systems monitored via Defender for IoT, not standard agents
WAF (control)Web Application FirewallNot to be confused with the Well-Architected Framework acronym above

SC-100 FAQ

What's the fastest way to tell MCRA, MCSB, CAF, and WAF apart on exam day?

MCRA is conceptual (how capabilities relate). MCSB is a scored checklist (evaluate a configuration against it). CAF governs the adoption lifecycle. WAF evaluates workload design quality, security being one pillar. If a question gives you a configuration to score, think MCSB — if it gives you an adoption/migration scenario, think CAF.

Which SC-100 prerequisite certification should I pick if I don't have any of the three yet?

Since AZ-500 retires August 31, 2026, starting it fresh now leaves little runway. SC-200 or SC-300 are the safer picks if you're choosing from scratch, unless your actual job role is specifically Azure security engineering and you can finish AZ-500 before the retirement date.

Is this cheat sheet different from the SC-100 study guide?

Yes. The study guide walks through an 8-week plan with narrative explanation and exam-day tactics. This page strips the narrative for tables and reference lists you can scan in the last hour before the exam.

Can I print this SC-100 cheat sheet?

Yes — every table here is plain HTML, so a browser print or "print to PDF" renders cleanly.

MSCertQuiz sells practice-exam access for SC-100 and other Microsoft certifications; this cheat sheet is written by the same team that builds those questions.

Continue Your Prep

Reviewed the cheat sheet? Now drill it.

Start with 40 free SC-100 questions covering every domain above.

Start Free SC-100 Practice