Free SC-900 Exam Flashcards
Memorize 50 essential terms and definitions for the Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900). See the term, recall the definition, then flip to check yourself.
Shared responsibility model
Splits security duties between the cloud provider and customer. Provider always owns physical hosts, network, and datacenter; customer always owns data, devices, and identities. OS, network controls, and apps shift based on IaaS, PaaS, or SaaS.
Filter by Topic
Jump to Card
About These SC-900 Flashcards
These 50 flashcards are designed to help you memorize key terms and definitions for the Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.
Topics Covered
Frequently Asked Questions
What is the SC-900 passing score and exam length?
SC-900 requires a scaled score of 700 out of 1000 to pass. The exam contains 40-60 multiple-choice and multiple-select questions and you have 45 minutes to complete it. The fee is US$99 in the United States. The certification does not expire because it is a fundamentals-level credential.
What changed in the 2026 SC-900 update?
Microsoft added a fifth domain on AI security solutions weighted 12-18%. It covers Microsoft Security Copilot, Data Security Posture Management for AI (DSPM for AI), risky AI prompt detection in Microsoft 365 Copilot, and oversharing prevention. Together with Microsoft Entra, this AI domain accounts for roughly 35-45% of the modern SC-900 blueprint.
What are the five SC-900 exam domains and weights?
The 2026 SC-900 domains are: Describe SCI concepts (10-15%), Describe Microsoft Entra capabilities (25-30%), Describe Microsoft security solutions (25-30%), Describe Microsoft compliance solutions (25-30%), and Describe Microsoft AI security solutions (12-18%). Focus first on Entra and the security/compliance solution sets, then close out with the AI domain and SCI concepts.
Do I need IT or Azure experience to pass SC-900?
No. SC-900 is a fundamentals exam testing conceptual knowledge, not hands-on configuration. You should be able to describe what each service does and when to use it, but you do not need to deploy resources. Most candidates pass with 20-35 hours of study using Microsoft Learn modules, a practice assessment, and flashcards for vocabulary recall.
What is the SC-900 retake policy if I fail?
After a first failed attempt you can retake the exam after 24 hours. If you fail a second time you must wait 14 days before each subsequent attempt. Microsoft caps attempts at five within any rolling 12-month period. Each retake costs US$99 unless you have a voucher from a Microsoft Virtual Training Day.
Explore More Microsoft Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.