GregLab | Exam Prep

Design security operations, identity, and compliance capabilities

Security Operations Architecture

Core

Unify XDR, SIEM, audit, multicloud monitoring, automation, incident management, hunting, and MITRE coverage into an operating model with trustworthy evidence and controlled response.

Aligned to SC-100 skills measured as of October 21, 2026; candidates testing earlier should review the transition note in the lane overview.

Why this matters

A collection of alerts is not a security-operations design. Architects decide which platform correlates which evidence, how cases and ownership flow, what can be automated safely, and how detection gaps are measured against relevant adversary behavior.

Must Know

  • Microsoft Defender XDR correlates signals across supported protection domains, while Microsoft Sentinel provides SIEM analytics, broad data ingestion, hunting, and SOAR across the wider estate.
  • Centralized logging requires source ownership, collection rules, normalization, retention, access control, cost governance, integrity, and time synchronization before analytics can be trusted.
  • Microsoft Purview Audit supplies user and administrative activity evidence for supported services; it does not replace operational diagnostics or threat telemetry.
  • Automation rules and playbooks should separate deterministic enrichment or containment from actions that require analyst approval, business context, or legal authorization.
  • MITRE ATT&CK mapping evaluates behavioral coverage and gaps, but a mapped detection still needs correct data, tested analytics, triage guidance, and response authority.
  • Hybrid and multicloud monitoring needs common severity, entity, incident, retention, and escalation conventions without erasing provider-specific context.

Compare and Distinguish

  • XDR offers deep native correlation and response across Defender domains; Sentinel extends SIEM and SOAR to diverse Microsoft and non-Microsoft sources.
  • An incident process governs ownership and decisions, while a playbook automates selected steps within that process.

Scenario examples

  • Scenario: Endpoint, identity, email, and cloud alerts create duplicate cases. Think: use Defender XDR correlation for its domains and Sentinel as the broader SIEM/SOAR plane with a defined incident authority.
  • Scenario: A playbook can disable an account but executive identities require approval. Think: automate enrichment and low-risk containment, then gate disruptive actions by identity tier and incident severity.

Exam traps

  • Sending every log to one workspace does not create usable detection coverage or governed retention.
  • A high ATT&CK mapping percentage can hide missing telemetry, untested rules, and response steps with no owner.

Key takeaways

  • A detection is incomplete until its telemetry, triage path, and response authority work.
  • Defender XDR and Sentinel need one incident ownership model at their integration boundary.
  • Validate ATT&CK coverage through controlled tests, not rule tags or connector counts.
How it works
  • Connectors and collection pipelines deliver telemetry; analytics create alerts; correlation forms incidents; workflows enrich, investigate, contain, recover, and capture lessons.
  • Coverage engineering maps priority threats to required sources, analytics, validation tests, triage decisions, and response actions.
Objects and administrative surfaces
  • Defender portal incidents, Sentinel workspaces, data connectors, analytics rules, automation rules, playbooks, hunting queries, watchlists, workbooks, and content hub solutions.
  • Purview Audit searches, retention settings, evidence access, incident records, threat-intelligence context, and MITRE coverage views.
When to use it
  • Use a unified operations architecture when multiple control planes must produce one governed response and learning process.
Security and governance implications
  • Define incident commander authority, evidence access, automation approval, retention ownership, and post-incident control improvement.
Troubleshooting signals
  • If incidents lack entities, verify source schemas, parsing, normalization, and analytics mappings before adding more alerts.
  • If automated containment causes outages, revisit confidence thresholds, asset criticality, approval gates, and rollback procedures.
More detail
  • Architect XDR and SIEM integration without duplicating incident ownership.
  • Define a logging and audit strategy suited to investigations and compliance.
  • Use MITRE matrices to prioritize tested detection and response gaps.

Ready for the quiz?

  • Which system should own the incident when Defender and non-Microsoft sources contribute evidence?
  • What must be true before a containment playbook runs without approval?
  • How would you prove a MITRE technique is operationally covered?

Related objectives

  • D2.1.S1 — Design a solution for detection and response that includes extended detection and response (XDR) and security information and event management (SIEM)
  • D2.1.S2 — Design a solution for centralized logging and auditing, including Microsoft Purview Audit
  • D2.1.S3 — Design monitoring to support hybrid and multicloud environments
  • D2.1.S4 — Design a solution for security orchestration, automation, and response (SOAR), including Microsoft Sentinel and Microsoft Defender XDR
  • D2.1.S5 — Design and evaluate security workflows, including incident response, threat hunting, and incident management
  • D2.1.S6 — Design and evaluate threat detection coverage by using MITRE ATT&CK matrices, including Enterprise, Mobile, and industrial control systems (ICS)

Learn more

Free Microsoft Certified: Cybersecurity Architect Expert prep

Build focused SC-100 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

SC-100 at a glance

Level
Expert
Duration
No SC-100-specific assessment duration published on the reviewed official pages
Questions
No fixed live question count published
Formats
No guaranteed question-type mix; the proctored exam may include interactive components
Scoring
Scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not publish a fixed live question count or guarantee a question-type mix for SC-100. This lane contains multiple-choice and multiple-response exam-style practice aligned to the October 21, 2026 blueprint. Practice percentages do not reproduce Microsoft's scaled scoring, and difficulty labels describe this site's Expert-level cybersecurity architecture complexity rather than a Microsoft-published question rating.

Reference

SC-100 topics and reference map

Study links

SC-100 resources