Guide

How to pass SC-500: Cloud and AI Security Engineer

A practical six-week route through identity, storage, network, compute, and AI security — plus posture management — for Microsoft's newest security engineering exam, the exam that replaced AZ-500.

· ~10 min read

Aura presents a four-step visual study cycle for SC-500: learn, connect, practise, and prove readiness.
Your study loop

The exam

What is SC-500, and is it for you?

SC-500 earns the Microsoft Certified: Cloud and AI Security Engineer Associate credential, spanning identity, network, application, data, and compute security across cloud and hybrid environments.

Format & domains

Exam format and skills domains

SC-500 mixes question styles: single-answer and multi-select items, ordering tasks around a configuration or investigation workflow, and case studies that group several questions around one security-engineering scenario.

The exam fee changes from country to country, so check Microsoft's certification page for the price where you live. The four skills domains and their weights, from the official May 2026 outline, are below.

SC-500 skills measured (May 2026 outline)
DomainWeight
Manage identity, access, and governance20–25%
Secure storage, databases, and networking25–30%
Secure compute20–25%
Manage and monitor security posture20–25%

Secure storage, databases, and networking is the largest single domain, covering Defender for Storage and Databases, Azure SQL auditing, private endpoints and Private Link, network security groups, and Azure Firewall. Secure compute is where the AI-security content lives — the clearest differentiator from AZ-500 — and deserves focused attention even though its weight matches the other two remaining domains.

Six-week study plan

A realistic six-week study plan

Use the six-week plan below as a starting point if you already administer Azure security day to day; extend it when Microsoft Sentinel, Entra Agent ID, or the AI-security controls are unfamiliar. It gives the largest domain — storage, databases, and networking — two full weeks, with the remaining three domains taking one week each.

  1. Manage identity, access, and governance

    The smallest domain, covered in full this week.

    • Entra ID: PIM, Conditional Access, MFA and passwordless, application identities, OAuth consent, managed identities.
    • Key Vault: deployment, access policies, firewall rules, Defender for Key Vault.
    • Governance: Azure Policy, Defender for Cloud compliance standards, resource locks, RBAC, IaC controls.
  2. Secure storage and databases

    The largest domain starts here.

    • Storage: firewall rules, Defender for Storage, access policies.
    • Databases: Azure SQL platform-level security, database auditing, Defender for Databases.
  3. Secure Azure network services

    Networking closes out the largest domain.

    • NSGs and ASGs; Virtual Network Manager access policies; Virtual WAN security; VPN connections.
    • Entra Private Access; private endpoints and Private Link for PaaS; Azure Firewall; effective rules via Network Watcher.
  4. Secure compute: AI, servers, and the application platform

    Give the headline addition over AZ-500 a deliberate deep dive before the more familiar compute topics.

    • AI security: Purview DSPM for Copilot and AI apps, real-time protection for Copilot Studio agents, Conditional Access and blast-radius analysis for Entra Agent ID, AI Gateway, Defender for AI Services, Foundry guardrails.
    • Servers and VMs: disk encryption, Azure Bastion, just-in-time access, Azure Arc, Defender for Servers, secure boot and vTPM.
    • Application platform: Defender for Containers, AKS, Container Apps, Functions, Logic Apps, App Service, WAF.
  5. Manage and monitor security posture

    Three tools, one domain.

    • Defender for Cloud CSPM, compliance frameworks, workload protection plans, multicloud AWS/GCP connectors.
    • Sentinel ingestion: workspaces, data connectors, syslog/CEF, Windows event collection, automation rules and playbooks.
    • Microsoft Security Copilot: workspaces, permissions, plugins, agents.
  6. Review and exam simulation

    Revisit the control-layering distinctions the exam leans on hardest, then prove you're ready.

    • Which Defender for Cloud plan covers which resource, and which network-access control fits which pattern.
    • Drill your weakest domain daily, then sit two full-length timed practice runs before you book.

Focus areas

The hardest SC-500 topics

SC-500 covers many security controls with similar names. Focus on these five areas and practise choosing the control that fits each threat.

The AI-security control set

  • Purview DSPM, Entra Agent ID Conditional Access, AI Gateway, Defender for AI Services, and Foundry guardrails all touch AI workloads but stop different threats.
  • Match the named risk to the one control that addresses it: data overexposure, agent identity misuse, model-endpoint abuse, or runtime prompt attacks.

Private network access patterns

  • Private endpoints, Private Link, Entra Private Access, and Virtual Network Manager all restrict access differently.
  • Pick the one that fits the pattern — a PaaS resource, a user outside Azure, or centralised policy across many networks — not the one you know best.

Which Defender for Cloud plan covers what

  • CSPM and the individual plans for Storage, Databases, Servers, Containers, and Key Vault overlap in the dashboard but protect different resource types.
  • Questions naming a specific resource and threat expect the specific plan, not a generic "enable Defender for Cloud" answer.

Governance layering: policy, RBAC, and locks

  • Azure Policy, RBAC, resource locks, and Key Vault access policies each stop a different kind of misconfiguration.
  • SC-500 tests which layer actually prevents the scenario: an accidental deletion, an overprivileged assignment, or a non-compliant resource being created.

Matching a Sentinel ingestion method to the source

  • Built-in connectors, syslog/CEF forwarding, data-collection-rule Windows Event collection, and custom log tables all get data in, but each suits a different source and licensing model.
  • Read a source description and name the correct ingestion path rather than defaulting to whichever is most familiar.

How to practise

Practise the way the exam works

SC-500 rewards matching a control or plan to a scenario, a skill built through practice more than reading.

Azure Mastery's adaptive study plan screen, showing the next recommended SC-500 topics to revise.
Azure Mastery rebuilds its study plan from your answer history, surfacing the weakest domains first.

New AI-security content, the same rigour

Azure Mastery writes a rationale for every option on every SC-500 question, so a wrong call on Purview DSPM versus Defender for AI Services teaches you the distinction, not just the score. Exam IQ gives you an on-device readiness score with a confidence range, and the study plan keeps circling back to your weak domain. Free to start, works offline.

Download Azure Mastery — free

Exam day

Tactics for exam day

A few habits protect the marks you've already earned.

  1. Sitting online? Run the system check the day before and clear your desk — proctors ask you to show the room first.
  2. Arrive early either way; a rushed start eats into your focus during the dense scenario questions.
  3. Budget roughly ninety seconds to two minutes per question, and flag anything you pause on with mark-for-review.
  4. Read every network or Defender-for-Cloud question twice — the trap is usually one scope, resource type, or plan name.
  5. Answer everything inside a case study before you advance; you generally cannot return to one once you leave it.
  6. Remember the pass mark is 700 out of 1000, scaled. An unfamiliar configuration isn't a disaster: make your call and keep moving.
New to the AI-security domain? Drill SC-500 scenario questions with a rationale for every option — free to start. Download free

Frequently asked

SC-500 FAQs

How hard is the SC-500 exam?

Broad rather than deep: identity, storage, database, network, compute, and AI security, plus posture management, so breadth of recall matters as much as depth on any one topic. Give the newer AI-security material — Entra Agent ID, Purview DSPM, Defender for AI Services, Foundry guardrails — dedicated hands-on revision.

How long should I study for SC-500?

The six-week plan above is a practical start if you already administer Azure security day to day. Extend it when Sentinel, Entra Agent ID, or the AI-security controls are unfamiliar, since several are recent additions. Use your domain-level results to decide when to add or repeat a week.

Do I need AZ-500 or SC-200 before SC-500?

Neither is a formal prerequisite. Microsoft expects practical experience administering Azure and hybrid environments and strong Entra ID familiarity — the background AZ-500 or day-to-day cloud security work already gives you. Partway through AZ-500 prep? That study carries over directly.

Is SC-500 the same as AZ-500?

SC-500 is the direct successor to AZ-500, which retired on 31 August 2026. Most of AZ-500's identity, storage, database, network, and compute content carries over unchanged. The new part is Secure compute for AI — Purview DSPM, Entra Agent ID, AI Gateway, Defender for AI Services, Foundry guardrails — which didn't exist on AZ-500.

What is the passing score for SC-500, and does it expire?

700 out of 1000, scaled rather than a raw percentage, so it doesn't map to a fixed number of correct answers. Like other Associate certifications, SC-500 expires annually, with a free renewal assessment on Microsoft Learn inside the six-month window before expiry.

How much does SC-500 cost and can I retake it if I fail?

Pricing varies by country — check Microsoft's certification page for your local fee. If you don't pass:

  • First retake: available 24 hours later.
  • Second and third retakes: each requires a 14-day wait.
  • Maximum five attempts per rolling 12 months, each a fresh booking.

Ready to start on SC-500?

SC-500's AI-security material is new to almost everyone — Azure Mastery gives every option a rationale and predicts your score on-device with Exam IQ before you book. Free to start.

Download Azure Mastery — free iPhone & iPad · Free to start · No account required