GregLab | Exam Prep

Describe the concepts of security, compliance, and identity

Security and Compliance Foundations

Core

Understand responsibility boundaries, layered protection, Zero Trust, cryptography, and GRC.

Aligned to the SC-900 skills measured as of July 28, 2026; product behavior verified September 10, 2026.

Why this matters

Security decisions start with knowing who owns each control, how protections reinforce one another, and how governance turns business obligations into managed risk and compliance activities.

Must Know

  • The shared responsibility model divides security and operational duties between a cloud provider and the customer; the boundary changes across on-premises, IaaS, PaaS, and SaaS.
  • Defense-in-depth uses multiple protective layers so one failed control does not expose the entire environment.
  • Zero Trust applies three principles: verify explicitly, use least-privilege access, and assume breach.
  • Encryption transforms readable data into ciphertext that authorized parties can decrypt with the appropriate key; hashing produces a fixed-size digest used to detect change and is not intended to be reversed.
  • Governance sets direction and accountability, risk management identifies and treats uncertainty, and compliance addresses applicable requirements and evidence.

Compare and Distinguish

  • Provider responsibility vs customer responsibility: consuming a managed service transfers some platform work, not accountability for customer data, identities, access, and configuration.
  • Defense-in-depth vs Zero Trust: defense-in-depth organizes overlapping layers; Zero Trust guides every access decision without implicit trust.
  • Encryption vs hashing: encryption protects confidentiality and can be reversed with a key; hashing supports integrity checks and is designed as a one-way operation.
  • Governance vs risk vs compliance: direction and oversight versus uncertainty management versus adherence to requirements.

Scenario examples

  • A SaaS provider operates the application while the customer still controls its users, access decisions, and data handling.
  • An organization combines identity controls, network controls, endpoint protection, application controls, and data protection so a single failure is not decisive.
  • A service compares a stored digest with a newly calculated digest to detect whether a file changed.

Exam traps

  • Cloud use does not make the provider responsible for every security decision.
  • Zero Trust is a strategy, not one Microsoft product and not a demand to block every request.
  • Hashing is not encryption without a decryption key.
  • Compliance with one standard does not eliminate risk or establish universal compliance.

Key takeaways

  • Responsibility changes with the service model, but customer accountability remains.
  • Layer controls and evaluate access explicitly with least privilege.
  • Use encryption for confidentiality and hashing for integrity evidence.
  • Keep governance, risk, and compliance related but distinct.

Ready for the quiz?

  • Which duties remain with a SaaS customer?
  • How do defense-in-depth and Zero Trust differ?
  • Why is a hash not encrypted data?

Related objectives

  • D1.1.S1 — Describe the shared responsibility model
  • D1.1.S2 — Describe defense-in-depth
  • D1.1.S3 — Describe the Zero Trust model
  • D1.1.S4 — Describe encryption and hashing
  • D1.1.S5 — Describe Governance, Risk, and Compliance (GRC) concepts

Learn more

Free Microsoft Certified: Security, Compliance, and Identity Fundamentals prep

Build focused SC-900 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Exam snapshot

SC-900 at a glance

Level
Beginner / Fundamentals
Duration
45 minutes
Questions
No fixed live question count published
Formats
No guaranteed question-type mix
Scoring
Scaled score; 700 minimum passing score

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not publish a fixed live question count or guarantee a question-type mix for SC-900. This lane plans only multiple-choice and multiple-response exam-style practice; no supplemental matching, ordering, or case-study exercises are planned. Practice percentages do not reproduce Microsoft's scaled scoring, and difficulty labels describe this site's Fundamentals-level scenario complexity rather than a Microsoft-published question rating.

Reference

SC-900 topics and reference map

Study links

SC-900 resources