Microsoft · Official Blueprint · Last reviewed May 2026
The official Microsoft SC-100 exam covers 9 domains. The vendor does not publish percentage weights for these domains — treat each as an equal part of the exam blueprint.
Covers the topics, concepts, and applied skills examined under the Design solutions that align with security best practices and priorities domain. Study the official exam objectives and practise questions in this area to build confidence and accuracy before your exam.
Practice Design solutions that align with security best practices and priorities questionsIncident response lifecycle, digital forensics, threat hunting, SIEM/SOAR tools, log analysis, and security automation.
Practice Design security operations, identity, and compliance capabilities questionsCovers the topics, concepts, and applied skills examined under the Design security solutions for infrastructure domain. Study the official exam objectives and practise questions in this area to build confidence and accuracy before your exam.
Practice Design security solutions for infrastructure questionsCovers the topics, concepts, and applied skills examined under the Design a Zero Trust strategy and architecture domain. Study the official exam objectives and practise questions in this area to build confidence and accuracy before your exam.
Practice Design a Zero Trust strategy and architecture questionsCovers the topics, concepts, and applied skills examined under the Design security solutions for applications and data domain. Study the official exam objectives and practise questions in this area to build confidence and accuracy before your exam.
Practice Design security solutions for applications and data questionsIncident response lifecycle, digital forensics, threat hunting, SIEM/SOAR tools, log analysis, and security automation.
Practice Evaluate GRC and security operations strategies questionsCovers the topics, concepts, and applied skills examined under the Design security for infrastructure domain. Study the official exam objectives and practise questions in this area to build confidence and accuracy before your exam.
Practice Design security for infrastructure questionsCovers the topics, concepts, and applied skills examined under the Design a strategy for data and applications domain. Study the official exam objectives and practise questions in this area to build confidence and accuracy before your exam.
Practice Design a strategy for data and applications questionsCovers the topics, concepts, and applied skills examined under the Recommend security best practices and priorities domain. Study the official exam objectives and practise questions in this area to build confidence and accuracy before your exam.
Practice Recommend security best practices and priorities questionsThe vendor does not currently publish percentage weights for these domains, so Courseiva does not rank them by weight.
Work through each domain systematically — cover fundamentals first, then applied and scenario-based topics.
Never skip a domain regardless of perceived importance. Full coverage is required to pass.
Use Courseiva domain analytics to track your accuracy per domain and route extra questions to your weak areas.
Courseiva tracks your accuracy per domain automatically and routes you toward your weakest areas — no manual configuration needed.