GregLab | Exam Prep

Design solutions that align with security best practices and priorities

CAF, WAF, Landing Zones, and Secure AI Adoption

Core

Embed security into cloud and AI adoption by joining business strategy, workload-quality guidance, governed landing zones, and DevSecOps feedback loops.

Aligned to SC-100 skills measured as of October 21, 2026; candidates testing earlier should review the transition note in the lane overview.

Why this matters

Cloud architecture fails when enterprise guardrails and workload engineering are designed independently. CAF coordinates adoption and governance, WAF guides workload trade-offs, landing zones establish the platform foundation, and DevSecOps keeps the design enforceable as code changes.

Must Know

  • A secure AI adoption strategy defines approved use cases, risk tiers, data boundaries, identity patterns, responsible-AI requirements, inventory, evaluation, monitoring, and incident ownership.
  • CAF addresses the organizational journey and operating model, while the Azure Well-Architected Framework evaluates workload design across its pillars, including security.
  • A platform landing zone supplies shared identity, connectivity, management, security, and governance; application landing zones host workloads within those guardrails.
  • Policy-driven subscription vending and infrastructure as code make guardrails repeatable, versioned, testable, and visible to workload teams.
  • DevSecOps integrates threat modeling, dependency and secret scanning, infrastructure validation, deployment gates, runtime feedback, and accountable remediation into delivery.

Compare and Distinguish

  • CAF tells the enterprise how to adopt and operate cloud capabilities; WAF helps a workload team assess design quality and trade-offs.
  • A central platform team owns reusable guardrails, while workload teams remain accountable for application-specific controls inside those boundaries.

Scenario examples

  • Scenario: Business units create subscriptions with inconsistent networking and logs. Think: standardize platform and application landing zones with policy-backed vending and explicit workload responsibilities.
  • Scenario: Teams are independently piloting agents against sensitive data. Think: establish risk tiers, approved platforms, identity and data guardrails, evaluation gates, inventory, and monitoring before scaling.

Exam traps

  • A landing zone does not transfer every workload-security duty to the platform team.
  • A responsible-AI policy without technical admission controls, inventory, evaluation, and monitoring does not secure adoption.

Key takeaways

  • CAF sets the operating model; WAF tests the workload's design trade-offs.
  • A landing zone makes shared guardrails consumable without absorbing workload ownership.
  • Production AI approval needs retained control evidence, not a successful demonstration alone.
How it works
  • Management groups and policy initiatives establish inheritance, while landing-zone automation creates compliant workload environments on demand.
  • DevSecOps converts design requirements into pipeline evidence and feeds production findings back into backlog and architecture decisions.
Objects and administrative surfaces
  • Management-group hierarchy, platform subscriptions, application subscriptions, policy initiatives, identity and connectivity services, and subscription vending workflows.
  • AI use-case register, model and agent inventory, risk approvals, evaluation suites, grounding-data controls, and runtime incident signals.
When to use it
  • Use this combined architecture when adoption must scale without giving every workload team unrestricted platform design authority.
Security and governance implications
  • Define platform, workload, data, model, and security-operations responsibilities before delegating AI or cloud deployment.
Troubleshooting signals
  • If teams bypass guardrails, inspect onboarding speed, exception paths, policy effects, and whether platform services meet workload needs.
  • If AI pilots cannot demonstrate safety, verify data lineage, identity scope, evaluation criteria, human oversight, and operational telemetry.
More detail
  • Design secure AI adoption as a portfolio governance problem.
  • Separate CAF operating-model choices from WAF workload assessments.
  • Embed security tests and remediation ownership throughout delivery.

Ready for the quiz?

  • Which controls belong in the platform landing zone rather than each workload?
  • What makes an AI pilot eligible to cross into production?
  • How should runtime incidents change DevSecOps gates?

Related objectives

  • D1.3.S1 — Design a strategy for secure AI adoption
  • D1.3.S2 — Design a new or evaluate an existing strategy for security and governance based on the Microsoft Cloud Adoption Framework for Azure (CAF) and the Azure Well-Architected Framework (WAF)
  • D1.3.S3 — Recommend solutions for security and governance based on the Microsoft Cloud Adoption Framework for Azure (CAF) and the Azure Well-Architected Framework
  • D1.3.S4 — Design solutions for implementing and governing security by using Azure landing zones
  • D1.3.S5 — Design a DevSecOps process that aligns with best practices in the Microsoft Cloud Adoption Framework for Azure (CAF)

Learn more

Free Microsoft Certified: Cybersecurity Architect Expert prep

Build focused SC-100 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

SC-100 at a glance

Level
Expert
Duration
No SC-100-specific assessment duration published on the reviewed official pages
Questions
No fixed live question count published
Formats
No guaranteed question-type mix; the proctored exam may include interactive components
Scoring
Scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not publish a fixed live question count or guarantee a question-type mix for SC-100. This lane contains multiple-choice and multiple-response exam-style practice aligned to the October 21, 2026 blueprint. Practice percentages do not reproduce Microsoft's scaled scoring, and difficulty labels describe this site's Expert-level cybersecurity architecture complexity rather than a Microsoft-published question rating.

Reference

SC-100 topics and reference map

Study links

SC-100 resources