Microsoft SC-500

Microsoft SC-500 (Cloud and AI Security Engineer Associate) replaces the retired AZ-500 (Azure Security Engineer Associate, retired August 31, 2026). Four domains: manage identity, access, and governance; secure storage, databases, and networking; secure compute (now including an AI-security sub-domain covering Copilot, Microsoft Foundry agents, and Entra Agent ID); and manage and monitor security posture. Roughly 40-60 questions, 100 minutes, passing score 700 on a scaled 100-1000 scale.

Exam fee at last check: $165, per the vendor. The official objectives are at learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/sc-500. Verified 2026-09-26.

Free for a limited time. What I want from the site right now is to see what predicts passing, and that is worth more to me than a price.

Answer the first question

Timed mock · Where you stand

How the Microsoft SC-500 exam is weighted
  1. Manage Identity, Access, and Governance20-25%
  2. Secure Storage, Databases, and Networking25-30%
  3. Secure Compute20-25%
  4. Manage and Monitor Security Posture20-25%

Source: Vendor exam objectives. Checked 2026-09-26. Bar length is relative to the heaviest domain; the figure beside each name is the published weight.

What's on the exam

Manage Identity, Access, and Governance 20-25%

Entra ID identity security, Key Vault, and governance controls enforcing regulatory compliance.

  • Privileged Identity Management (PIM) for just-in-time, approval-gated role activation
  • Conditional Access for context-aware sign-in policy
  • Managed identities for Azure resources (no embedded credentials)
  • Access reviews to find and revoke stale, overprivileged role assignments
  • Azure Policy with deny effects to block non-compliant deployments
  • Azure Backup soft delete and multi-user authorization

Primary sources: Microsoft Entra ID Governance documentation

Secure Storage, Databases, and Networking 25-30%

The largest domain. Storage account and database security, plus the full range of Azure network security controls.

  • Storage firewall rules + private endpoints to eliminate public network access
  • Microsoft Defender for Databases threat detection
  • Network Security Groups (NSGs) for subnet/NIC-level traffic filtering
  • Azure Virtual Network Manager for centralized multi-VNet, multi-subscription policy
  • Microsoft Entra Private Access for Zero Trust, identity-aware private application access
  • Azure Firewall + Firewall Manager for hub-and-spoke traffic inspection

Primary sources: Azure Storage documentation, Azure Virtual Network documentation

Secure Compute 20-25%

VM, container, and application-platform security, plus an AI-security sub-domain with no AZ-500 equivalent.

  • Just-in-time (JIT) VM access to lock down management ports by default
  • Microsoft Defender for Servers via Azure Arc for hybrid/multicloud machines
  • Microsoft Purview DSPM for AI: identifying data overexposure risk in Copilot-accessible content
  • Microsoft Entra Agent ID for scoped AI agent identity + Defender XDR blast-radius analysis
  • Microsoft Defender for Containers for AKS runtime threat detection
  • Secure Boot, vTPM, and integrity monitoring for VM boot-chain attestation

Primary sources: Microsoft Defender for Cloud documentation, Microsoft Purview documentation, Microsoft Entra documentation

Manage and Monitor Security Posture 20-25%

Defender for Cloud posture scoring, multicloud connectors, Sentinel SIEM/SOAR, and AI-assisted investigation via Security Copilot.

  • Secure Score via Defender CSPM
  • Multicloud connectors (AWS, GCP) for unified posture management
  • Sentinel data collection rules, including Windows Event Forwarding at scale
  • Sentinel automation rules and playbooks for automated incident response
  • Microsoft Security Copilot for natural-language incident investigation
  • Microsoft Defender External Attack Surface Management (EASM) for unmanaged asset discovery

Primary sources: Microsoft Defender for Cloud documentation, Microsoft Sentinel documentation

Exam-day strategy

AZ-500 retired August 31, 2026; make sure any other study material you use targets SC-500's actual current blueprint, not legacy AZ-500 content.

The AI-security sub-domain under Secure Compute is new and has no AZ-500 equivalent: know Purview DSPM for AI, Entra Agent ID, and Security Copilot specifically.

Watch for distractors naming a real but wrong Azure service for the exact same general category (e.g., Defender for Servers vs Defender for Containers vs Defender for Databases).

On network questions, identify the exact scope: subnet/NIC-level (NSG) vs multi-VNet centralized (Virtual Network Manager) vs perimeter/hub (Azure Firewall).

Pace at roughly 2 minutes per question across the ~100-minute, 40-60 question exam.

Additional resources

Explore Related Cybersecurity Resources

DecipherU is independent of Microsoft. SC-500 (Cloud and AI Security Engineer Associate) is a trademark of Microsoft. DecipherU is not endorsed by, sponsored by, or affiliated with any certifying body.