- What This Cheat Sheet Covers
- The Four SC-900 Domains at a Glance
- Registration and Exam Logistics
- Passing Score and Scoring Mechanics
- Domain-by-Domain Must-Know Facts
- Question Style and Format Notes
- Who Earns SC-900 and Why
- Mapping a Final Review Week to the Domains
- Quick Reference: Terms You Must Not Confuse
- FAQ
- Microsoft Security Solutions is the largest domain at 35-40%, followed by Microsoft Entra at 25-30%.
- Passing score is 700 on a 1000-point scale - not a simple 70% correct threshold.
- Testing time is 45 minutes inside a standard 65-minute proctored appointment.
- Exam delivery runs through Pearson VUE, with Certiport listed for students and educators.
What This Cheat Sheet Covers
This page is a compressed, one-stop reference for Microsoft Certified: Security, Compliance, and Identity Fundamentals - the SC-900 exam. It is not a substitute for full preparation, but it works as a final review before test day or a quick-check while you're building your study plan. If you want the long-form version of everything summarized here, pair this page with the full SC-900 Study Guide 2026: How to Pass on Your First Attempt and the domain-by-domain breakdown in the SC-900 Exam Domains 2026: Complete Guide to All 4 Content Areas.
Every fact below is scoped specifically to Microsoft's SC-900 exam. If you've seen other "SC-900" content online referencing different fees, timelines, or governing bodies, be cautious - this page only reflects the Microsoft credential covering security, compliance, and identity fundamentals.
The Four SC-900 Domains at a Glance
SC-900 is organized into four content areas, each with a published weight range. Memorize these weights before anything else - they tell you where to spend your study hours.
| Domain | Weight | Focus |
|---|---|---|
| 1. Concepts of security, compliance, and identity | 10-15% | Shared responsibility model, Zero Trust, encryption basics, compliance concepts |
| 2. Microsoft Entra capabilities | 25-30% | Identity services, authentication, access management, identity governance |
| 3. Microsoft security solutions | 35-40% | Security tooling across Microsoft's ecosystem - the largest and highest-value domain |
| 4. Microsoft compliance solutions | 20-25% | Compliance Manager, information protection, governance, and risk tools |
Registration and Exam Logistics
These are the operational facts you need before scheduling anything:
- Delivery: Proctored, computer-based, via Pearson VUE; Certiport is also listed as an option for students and educators.
- Testing time: 45 minutes of actual testing time, inside a standard 65-minute appointment window (extra time covers check-in, agreements, and surveys).
- Question count: Not officially disclosed for SC-900 specifically. Microsoft's exams broadly tend to fall in the 40-60 question range, but treat that as a general pattern, not a guarantee.
- Format: Interactive item types are possible; the exact mix of question types is not published in detail.
- Fee: Microsoft has not published a currently verified official U.S. checkout price on this page's source data. Third-party references sometimes cite US$99, but treat that as unverified until you confirm current pricing at checkout. Regional taxes and discounts can also change the final total - see the SC-900 Certification Cost 2026: Complete Pricing Breakdown for a fuller discussion.
- Remote proctoring: Available where supported, though calculator access and adaptive-testing behavior are not verified.
- Learn access during the test: None. You cannot reference Microsoft Learn documentation while the exam is in progress.
Key Takeaway
Arrive with a confirmed, current fee and appointment length from your Pearson VUE or Certiport account - don't rely on older blog posts for exact dollar amounts.
Passing Score and Scoring Mechanics
The passing score for SC-900 is 700 out of a 1000-point scale. This is a scaled score, which means 700 does not automatically equal "70% of questions correct." Different items can carry different weight, and the scale accounts for difficulty variance across exam forms.
Microsoft has not disclosed the exact number of scored versus unscored items, and no public pass rate is available for this exam. If you're trying to gauge your odds going in, qualitative research is more useful than chasing a number that doesn't exist publicly - see the SC-900 Pass Rate 2026: What the Data Shows for a deeper look at what is and isn't knowable here. For a focused breakdown of the scaled scoring model itself, read SC-900 Passing Score 2026: Exactly What You Need to Pass.
Domain-by-Domain Must-Know Facts
Domain 1: Concepts of Security, Compliance, and Identity (10-15%)
The smallest domain, but it sets the vocabulary for the rest of the exam. Expect foundational questions rather than product-specific ones.
- Zero Trust principles: verify explicitly, least privilege, assume breach
- Shared responsibility model between cloud provider and customer
- Core concepts: encryption, hashing, governance, risk, and compliance basics
- Defense in depth as a layered security strategy
Domain 2: Microsoft Entra Capabilities (25-30%)
This is the identity backbone of the exam. Expect to distinguish between authentication and authorization, and to know how identity governance features fit together.
- Authentication methods and multifactor authentication concepts
- Conditional Access as a policy engine, not a single feature
- Identity governance: entitlement management, access reviews, privileged identity concepts
- External identities and business-to-business/business-to-consumer scenarios
Domain 3: Microsoft Security Solutions (35-40%)
The single largest domain - treat it as the anchor of your study plan, not an afterthought. Expect broad coverage across Microsoft's security product family at a conceptual level.
- Extended detection and response (XDR) concepts and how threat protection tools relate
- Cloud security posture and workload protection concepts
- Security information and event management (SIEM) fundamentals
- Unified security operations concepts across endpoints, identities, and cloud apps
Domain 4: Microsoft Compliance Solutions (20-25%)
Compliance concepts overlap with governance and risk - expect scenario questions asking you to match a business need to the right compliance capability.
- Compliance Manager and compliance score concepts
- Information protection and data lifecycle management basics
- Insider risk management and communication compliance concepts
- Data governance and records management fundamentals
Question Style and Format Notes
SC-900 is a Fundamentals-level exam, which means it leans toward conceptual understanding rather than deep hands-on configuration. Expect scenario-style prompts that ask you to identify the correct capability, tool, or concept for a described business situation, rather than asking you to recall exact menu paths or CLI syntax.
Interactive question formats are possible, though Microsoft has not published the exact breakdown of item types used on any given exam form. Because there's no in-exam access to Microsoft Learn documentation, you need to internalize terminology rather than plan to look anything up mid-test. If you're unsure how difficult this actually feels in practice, the How Hard Is the SC-900 Exam? Complete Difficulty Guide 2026 article walks through what trips candidates up most often.
Who Earns SC-900 and Why
There's no formal degree, prior certification, employment history, or required training hours to sit for SC-900. Microsoft does recommend general familiarity with Azure and Microsoft 365 concepts, but this is guidance, not a gatekeeping requirement. That accessibility is a big part of why SC-900 attracts such a wide range of candidates. For the full list of what is and isn't required, see SC-900 Requirements 2026: Eligibility, Prerequisites & How to Qualify.
Typical candidates include people early in security, compliance, or identity-adjacent roles, IT professionals branching into governance and risk work, and business stakeholders who need to speak the same language as security teams without necessarily configuring the tools themselves. If you're evaluating whether this fits your career direction, the SC-900 Jobs overview and the Is the SC-900 Certification Worth It? Complete ROI Analysis 2026 article both go deeper on positioning and outcomes than this cheat sheet can.
Mapping a Final Review Week to the Domains
Generic study techniques only matter if they're tied to how SC-900 is actually weighted. In your last review week before test day, allocate time proportionally rather than evenly across all four domains.
Microsoft Security Solutions (35-40%)
- Review XDR, SIEM, and cloud security posture concepts
- Drill scenario questions matching business need to security capability
Microsoft Entra Capabilities (25-30%)
- Rehearse authentication vs. authorization distinctions
- Review identity governance and Conditional Access scenarios
Microsoft Compliance Solutions (20-25%)
- Review Compliance Manager and information protection concepts
- Practice matching compliance tools to business scenarios
Core Concepts (10-15%)
- Confirm Zero Trust and shared responsibility model terminology
- Take a full-length practice run
Notice that even the smallest domain still gets a dedicated review day - skipping it entirely is a common way candidates lose easy points. For a longer discussion of pacing across multiple weeks rather than just the final stretch, the SC-900 Study Guide 2026: How to Pass on Your First Attempt lays out a fuller timeline.
Quick Reference: Terms You Must Not Confuse
| Term A | Term B | Key Distinction |
|---|---|---|
| Authentication | Authorization | Authentication proves identity; authorization determines what that identity can access |
| Compliance | Security | Compliance addresses meeting regulatory/policy obligations; security addresses protecting systems and data |
| Conditional Access | Multifactor Authentication | Conditional Access is a policy engine; MFA is one control it can enforce |
| Testing time | Appointment time | 45 minutes is testing time; 65 minutes is the full standard appointment |
Key Takeaway
When two SC-900 terms sound similar, the exam is usually testing whether you know which one is the broader concept and which one is a specific control or mechanism.
If you want to keep this kind of scenario practice going beyond a single review session, running timed sets on a full SC-900 practice test platform is one of the most efficient ways to stress-test your recall of exact terminology under time pressure. Rotating through realistic practice questions also helps surface which of the four domains still needs another pass before your actual appointment.
Frequently Asked Questions
This article covers exactly one credential: Microsoft Certified: Security, Compliance, and Identity Fundamentals. Some other acronyms overlap in name across unrelated fields - make sure any source you're reading is specifically about Microsoft's security, compliance, and identity fundamentals exam.
Testing time is 45 minutes, within a standard 65-minute total appointment that also covers check-in and administrative steps.
Microsoft security solutions, at 35-40%, is the largest domain and should get the most review time, followed by Microsoft Entra capabilities at 25-30%.
Not necessarily. The passing score is 700 on a 1000-point scaled score, which doesn't map directly to a simple percentage of correct answers.
No. As a Fundamentals-level credential, SC-900 does not expire and has no renewal assessment or continuing-education requirement.
Keep this page bookmarked as your last-minute reference, but pair it with deeper reading - starting with the SC-900 Exam Domains 2026: Complete Guide to All 4 Content Areas - so the concepts above have real context behind them on exam day.