Memory hook: Prove identity, limit access, detect threats, govern data.
Reviewed 10 October 2026. Read this once, then answer the last-pass checks without looking.
Scope/version: Targets Microsoft’s published October 21, 2026 update. If sitting earlier, compare your current booking outline. Fundamentals describe capabilities; implementation depth is available in the SC-300 and SC-500 paths.
Must remember by domain
| Domain | Rapid revision |
|---|---|
| Concepts | Authentication proves identity; authorization permits an action. Federation trusts another identity provider. Encryption is reversible with an appropriate key; hashing produces a digest and is not decryption. Defense in depth layers controls; Zero Trust verifies explicitly, uses least privilege and assumes breach. GRC connects governance, risk and compliance. |
| Entra identities | Entra ID is cloud identity; AD DS supplies traditional directory/domain services; hybrid identity connects supported environments. Users, devices, apps and workloads have different lifecycles. MFA combines independent factors; passwordless methods can use keys. Secure enrollment/recovery as well as login. |
| Entra access/governance | Conditional Access evaluates context and grant/session controls. Entra roles administer the directory; Azure RBAC administers resource scopes. Identity Protection assesses risk; PIM supports temporary privileged activation; access reviews verify ongoing need; entitlement management packages governed access. |
| Infrastructure | NSGs filter subnet/NIC traffic; Azure Firewall centrally filters supported network/application traffic; WAF targets HTTP attacks; DDoS Protection addresses network denial of service. Bastion provides managed VM administration without exposing every VM management port. Key Vault manages secrets, keys and certificates. |
| Security operations | Defender for Cloud combines CSPM and enabled workload protection. Defender XDR correlates Endpoint, Identity, Office 365 and Cloud Apps signals. Sentinel supplies broader SIEM/SOAR. SIEM collects/analyzes events; SOAR automates workflows; XDR correlates integrated security products. |
| Data protection/lifecycle | Classification identifies data; sensitivity labels mark/apply supported protection; DLP restricts inappropriate data movement. Retention policies/labels determine keeping/deletion; records management strengthens lifecycle control. Label publishing policy differs from the label applied to an item. |
| Investigation/trust | Content explorer inspects classified content; Activity explorer shows supported protection activity. Insider Risk evaluates indicators with privacy controls. eDiscovery finds/preserves/reviews evidence; audit records actions. Compliance Manager tracks assessments; Service Trust Portal provides Microsoft assurance resources. |
Exam traps
Shared responsibility still leaves customer data/access duties in SaaS. Encryption is not permission; a sensitivity label is not a retention policy. Risk signals are not automatic proof of compromise. Provider compliance reports and compliance scores do not automatically establish your organization's compliance. Fundamentals questions primarily ask capability and purpose, not deployment syntax.
Last-pass self-check
1. Temporary elevated admin rights?
Privileged Identity Management.
2. Periodically confirm a guest still needs access?
Access reviews, with decisions applied.
3. Preserve mail for an investigation?
Use the appropriate eDiscovery/retention preservation capability, not a sensitivity label alone.
4. Find Microsoft independent assurance reports?
Service Trust Portal.
5. Which tool connects third-party event evidence to automated response?
Sentinel SIEM/SOAR with configured connectors, detections and authorized playbooks.
Sources
- Official exam scope and version
- entra · fundamentals · whatis
- entra · identity · conditional-access · overview
- entra · id-governance · identity-governance-overview
- azure · defender-for-cloud · defender-for-cloud-introduction
- azure · firewall · overview
- web-application-firewall · overview
- azure · key-vault · general · overview
- defender-xdr · microsoft-365-defender
Every topic at a glance
Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.
01 · Security Principles and Controls
Memory hook: Protect the right property with the right kind of control.
Must remember
Confidentiality prevents unauthorized disclosure; integrity protects against unauthorized alteration; availability keeps a service usable. Authenticity establishes that something is genuine. Non-repudiation supplies evidence of origin or action, subject to trustworthy keys, identities and records.
Authentication establishes an identity, authorization decides permitted actions and accounting records activity. Identify which stage failed: a valid login with excessive database privileges is an authorization problem.
| Classification | Examples |
|---|---|
| Technical | Firewall, encryption, access-control software. |
| Managerial | Policy, risk assessment, oversight. |
| Operational | Human-run procedures, training, guard processes. |
| Physical | Locks, barriers, cameras, environmental protection. |
| Preventive / detective / corrective | Block / discover / repair. |
| Deterrent / directive / compensating | Discourage / instruct / supply an alternative protection. |
One control can have several classifications. A camera detects; a visible camera may also deter. A compensating control addresses the original control's intent when the normal implementation is not feasible; it does not simply mean a cheaper control.
Zero trust evaluates access using identity, device state, resource sensitivity and context rather than trusting network location. A policy engine decides, a policy administrator arranges the session and an enforcement point permits or blocks it. Least privilege and segmentation reduce blast radius; continuous evaluation handles changing conditions.
Honeypots, honeynets, honeyfiles and honeytokens are deception tools. Access to a decoy can be a high-value detection signal, but a decoy needs containment and monitoring.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Prevent disclosure | Access control and encryption appropriate to the data path. |
| Find unauthorized changes | Integrity checks, signatures and audit evidence. |
| Legacy system cannot implement a mandated control | Evaluate an approved compensating control against the same risk. |
Traps
- Encryption alone does not make a service available.
- Zero trust is an architecture and decision process, not one appliance.
02 · Entra Identity, Authentication and Governance
Memory hook: Prove who, decide what, review why access continues.
Must remember
Entra ID provides cloud identity and access management. AD DS provides traditional domain services; hybrid identity connects supported on-premises and cloud identity processes. Federation trusts another identity provider for authentication. People, devices, applications and workloads can all have identities with different lifecycles.
Authentication proves identity; authorization decides actions. MFA combines independent proof factors; passwordless methods can use keys or device-bound credentials. Password Protection and self-service reset address different parts of credential management. No method removes the need to secure enrollment and recovery.
Conditional Access evaluates configured signals and applies access/session controls. Entra roles manage directory tasks; Azure RBAC manages Azure resource access. Identity Protection identifies user/sign-in risk; it does not mean every detection is confirmed compromise.
Identity Governance manages access lifecycle. Access reviews check continuing need; entitlement management organizes requestable access; PIM supports temporary controlled privileged activation. Least privilege and timely offboarding reduce standing exposure.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Require stronger sign-in under a condition | Conditional Access. |
| Temporary administrator elevation | PIM. |
| Periodic confirmation of access | Access reviews. |
Traps
- Authentication is not authorization.
- Entra ID is not simply a cloud VM running AD DS.
03 · Azure Infrastructure and Cloud Posture
Memory hook: Filter traffic, protect secrets, find exposure.
Must remember
Virtual networks/subnets segment network placement; NSGs filter permitted traffic at supported subnet/interface boundaries. Azure Firewall provides managed centralized network filtering; WAF addresses supported web-layer attacks; DDoS Protection addresses supported denial-of-service exposure. They work at different layers and are not interchangeable.
Azure Bastion provides managed remote access to supported VMs without exposing their RDP/SSH ports directly to the internet. Key Vault stores/manages supported secrets, keys and certificates with access control. A vault does not automatically rotate every application secret or eliminate the need to grant the application permission.
Defender for Cloud combines cloud security posture management and supported workload-protection plans. CSPM assesses configurations and recommendations; workload protection detects/protects specific workloads under enabled plans. Security standards and policies help assess alignment, but a score or recommendation list is not proof that every risk is resolved.
Shared responsibility changes with IaaS/PaaS/SaaS. The provider handles more infrastructure in managed services, while customer data, access and configuration responsibilities remain. Select controls from the threat and resource type, then validate effective behavior.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Protect a web app from common HTTP attacks | WAF at an appropriate supported ingress. |
| Central network filtering | Azure Firewall. |
| Find cloud misconfigurations | Defender for Cloud posture assessment. |
Traps
- WAF does not replace every network firewall function.
- A high posture score does not guarantee no compromise.
04 · Defender XDR, Sentinel and Threat Operations
Memory hook: XDR connects product signals; SIEM connects the wider evidence.
Must remember
Defender XDR correlates supported security signals into incidents. Defender for Endpoint addresses endpoint protection/detection; Defender for Office 365 covers supported email/collaboration threats; Defender for Identity analyzes supported identity infrastructure; Defender for Cloud Apps addresses SaaS/cloud-app visibility and controls. Vulnerability Management prioritizes weaknesses; threat intelligence supplies adversary/indicator context.
Microsoft Sentinel is a SIEM/SOAR platform: collect and correlate telemetry, detect suspicious patterns, investigate incidents and orchestrate response. Data connectors ingest evidence; analytics rules detect conditions; automation/playbooks support response. A connector alone does not mean every required detection is enabled or tuned.
The Defender portal brings supported investigation experiences together. An alert is a signal; an incident groups related evidence and response work. Analysts validate, scope, contain and investigate rather than treating every alert as proven malicious activity. Automated response needs suitable permissions and safeguards.
SIEM emphasizes centralized event analysis; SOAR emphasizes orchestration/automation; XDR emphasizes correlated detection/response across integrated security products. The categories overlap in modern platforms, but the exam still asks which capability solves a stated need.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Correlate supported endpoint/email/identity attacks | Defender XDR. |
| Ingest broad cross-platform logs and automate response | Sentinel SIEM/SOAR. |
| Find risky SaaS use | Defender for Cloud Apps. |
Traps
- Defender for Cloud and Defender for Cloud Apps are different products.
- An alert count does not directly measure confirmed incidents.
05 · Purview, Retention, Discovery and Trust
Memory hook: Classify, protect, retain, investigate and prove.
Must remember
Microsoft Purview brings supported data governance, protection and compliance capabilities together. Classification identifies sensitive information; sensitivity labels mark and apply supported protection; DLP detects/restricts inappropriate data movement. A label policy publishes label availability/default behavior, while an item’s label expresses its classification/handling.
Retention policies and labels manage how long content is retained or deleted. Records management applies stronger lifecycle controls for designated records. Retention and sensitivity labels have different jobs: keeping content is not the same as encrypting or restricting access to it. Legal preservation needs can override ordinary disposal workflows.
Content explorer helps inspect classified content within permissions; Activity explorer shows supported protection-related activity. Insider Risk Management correlates supported indicators under privacy/access controls. eDiscovery supports finding, preserving and reviewing information for investigations/legal processes; audit records supported activity. These functions require appropriate configuration, roles and data scope.
Compliance Manager organizes assessments and improvement actions; compliance score is a progress/risk-management signal, not a legal certification. Service Trust Portal provides Microsoft assurance/compliance resources. Privacy principles and shared responsibility guide evaluation, but an organization must still determine its own obligations and actual control operation.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Prevent sensitive data leaving through supported channels | DLP. |
| Keep records for a required period | Retention/records controls. |
| Find and preserve relevant investigation content | eDiscovery with authorized scope. |
Traps
- Sensitivity and retention labels are not interchangeable.
- Compliance score is not proof of legal compliance.