GregLab | Exam Prep

Design security solutions for applications and data

Application Security Architecture

Core

Transform portfolio risk and threat models into secure lifecycle standards, identity patterns, API controls, and correctly placed web application firewalls.

Aligned to SC-100 skills measured as of October 21, 2026; candidates testing earlier should review the transition note in the lane overview.

Why this matters

Application risk accumulates across design, dependencies, code, delivery, runtime identity, APIs, and edge exposure. Architects set a lifecycle and platform pattern that makes the secure choice repeatable without pretending that one scanner or gateway fixes every layer.

Must Know

  • Portfolio posture assessment inventories applications, owners, technologies, data, identities, exposure, dependencies, support state, findings, and business criticality before prioritizing modernization.
  • Threat modeling identifies assets, trust boundaries, data flows, threats, mitigations, and verification early enough to change the design of business-critical applications.
  • A full lifecycle strategy links requirements, architecture, development standards, dependency governance, testing, release gates, production protection, vulnerability response, and retirement.
  • Technology selection should follow explicit requirements for authentication, authorization, network placement, data protection, logging, availability, and operational ownership.
  • Managed identities remove stored Azure credentials from supported workloads and should receive least-privilege resource authorization at the narrowest practical scope.
  • API Management can centralize authentication, authorization policies, rate limits, transformations, versioning, and observability, while backend services still enforce domain authorization.
  • Azure Front Door WAF protects global edge applications; Application Gateway WAF protects regional layer-seven traffic in a virtual network; neither replaces secure code and origin hardening.

Compare and Distinguish

  • Threat modeling predicts abuse paths from architecture; security testing finds defects in an implementation; both inform different lifecycle decisions.
  • API Management governs API publication and gateway policy, while WAF filters web attack patterns at an HTTP ingress point.

Scenario examples

  • Scenario: A regional private application needs layer-seven inspection before internal backends. Think: use Application Gateway WAF in the virtual network and retain application authentication and secure coding.
  • Scenario: Hundreds of APIs need consistent OAuth validation and rate limits but resource authorization differs. Think: enforce common gateway policies in API Management and keep business authorization in each backend.

Exam traps

  • A WAF can reduce common exploit exposure but cannot repair broken object-level authorization in application logic.
  • Giving one shared managed identity broad access to every backend recreates a large credential blast radius without a password.

Key takeaways

  • Portfolio ranking needs exposure and identity paths alongside findings and business value.
  • Threat-model decisions become useful when delivery tests and runtime detections trace back to them.
  • A gateway centralizes reusable policy; the backend still owns resource authorization.
How it works
  • Threat models and standards become backlog and pipeline controls, while production telemetry verifies assumptions and drives remediation.
  • Gateways validate and shape requests before backends enforce resource-specific authorization and perform business operations.
Objects and administrative surfaces
  • Application inventory, data-flow diagrams, threat registers, SDL standards, repositories, pipeline gates, dependency inventories, vulnerabilities, and runtime findings.
  • Managed identities, Azure RBAC, API Management gateways and policies, Front Door and Application Gateway WAF policies, origins, diagnostics, and certificates.
When to use it
  • Use portfolio patterns when many applications share risk requirements but differ in data, exposure, and runtime technology.
Security and governance implications
  • Define approved patterns, deviation review, severity-based release gates, vulnerability ownership, and end-of-life criteria.
Troubleshooting signals
  • If a WAF produces false positives, tune exclusions narrowly at the affected rule and parameter while preserving managed-rule coverage.
  • If managed identity access fails, trace token audience, identity assignment, RBAC scope, resource firewall, and propagation time.
More detail
  • Evaluate current portfolios and business-critical threats.
  • Design secure development standards and lifecycle governance.
  • Select workload identity, API Management, and Azure WAF patterns from explicit requirements.

Ready for the quiz?

  • Which artifacts make a threat model actionable in delivery?
  • When does Front Door WAF fit better than Application Gateway WAF?
  • What authorization must remain behind API Management?

Related objectives

  • D4.2.S1 — Evaluate the security posture of existing application portfolios
  • D4.2.S2 — Evaluate threats to business-critical applications by using threat modeling
  • D4.2.S3 — Design and implement a full lifecycle strategy for application security
  • D4.2.S4 — Design and implement standards and practices for securing the application development process
  • D4.2.S5 — Map technologies to application security requirements
  • D4.2.S6 — Design a solution for workload identities to authenticate and access Azure resources
  • D4.2.S7 — Design a solution for API management and security
  • D4.2.S8 — Design solutions that secure applications by using Azure Web Application Firewall (WAF)

Learn more

Free Microsoft Certified: Cybersecurity Architect Expert prep

Build focused SC-100 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

SC-100 at a glance

Level
Expert
Duration
No SC-100-specific assessment duration published on the reviewed official pages
Questions
No fixed live question count published
Formats
No guaranteed question-type mix; the proctored exam may include interactive components
Scoring
Scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not publish a fixed live question count or guarantee a question-type mix for SC-100. This lane contains multiple-choice and multiple-response exam-style practice aligned to the October 21, 2026 blueprint. Practice percentages do not reproduce Microsoft's scaled scoring, and difficulty labels describe this site's Expert-level cybersecurity architecture complexity rather than a Microsoft-published question rating.

Reference

SC-100 topics and reference map

Study links

SC-100 resources