ciply.io

SC-500 Exam Guide: What the Cloud and AI Security Engineer Exam Covers, Format, and How to Pass

Published August 9, 2026 · Facts last verified against the official sources on August 9, 2026

SC-500 is Microsoft's associate-level exam for engineers who secure Azure, hybrid and AI workloads. Passing it earns Microsoft's Cloud and AI Security Engineer Associate certification. You get 120 minutes, the exam is currently offered in English only, and you pass at 700. Four skill areas share the marks almost evenly.

What SC-500 covers

The study guide lists four skill areas. The names below are written exactly as Microsoft publishes them:

Skill area Weight In plain terms
Manage identity, access, and governance 20–25% Entra ID, Key Vault, Azure Policy, RBAC
Secure storage, databases, and networking 25–30% storage accounts, Azure SQL, the network edge
Secure compute 20–25% AI workloads, servers and VMs, app platform services
Manage and monitor security posture 20–25% Defender for Cloud, Microsoft Sentinel, Security Copilot

The first thing to notice is how flat that is. One area is worth 25–30%; the other three are worth 20–25% each. There is no small area to skip and no dominant area to over-invest in. We say this as a planning observation rather than as Microsoft's advice: on an exam shaped like this, an untouched skill area costs you roughly a fifth of the paper.

The second thing is where the AI content actually lives, and it is not where most people guess. Microsoft did not give AI its own skill area. Instead the AI material sits inside "Secure compute", as the first of that area's three groups — and it is the largest group there. Counting the sub-bullets on the live page, "Secure compute" carries 29, and 11 of them are AI. That group covers data overexposure in SharePoint, risk identification through Microsoft Purview DSPM, runtime protection for Microsoft Copilot Studio agents, and a cluster of Microsoft Entra Agent ID work: conditional access for agent identities, access management for them, and blast-radius analysis in Microsoft Defender XDR. It then moves to Microsoft Foundry — AI Gateway in Azure API Management, agent guardrails — plus Defender for AI Service, Defender for Cloud's Data and AI security dashboard, and agent management from the Microsoft 365 admin center.

More AI turns up in the fourth area as Microsoft Security Copilot: its workspaces, its permissions and roles, its plugins, and the Microsoft and Security Store agents it runs. So the AI content is split across two skill areas and never labelled as one block. Read the outline by group name, not by area name, or you will miss half of it.

Area one is identity, secrets and governance. The Entra ID group covers Privileged Identity Management, conditional access policies, and the authentication methods themselves, passwordless and multifactor authentication (MFA) among them. It adds application identity — enterprise applications and app registrations — then OAuth permission grants with consent settings, and managed identities for Azure resources. Azure Key Vault gets a group of its own: deployment, settings, access configuration, firewall settings, and the handling of keys, secrets and certificates. Two Defender items close it, secret scanning through Defender Cloud Security Posture Management (Defender CSPM) and Defender for Key Vault. The governance group is the compliance half: Azure Policy with built-in and custom policy definitions, regulatory compliance evaluation in Microsoft Defender for Cloud, security standards and recommendations, resource locks, built-in and custom role assignments across both Azure and Microsoft Entra, remediation of overprivileged access through Azure role-based access control (RBAC), backup protection using Azure Backup security features, and security controls delivered as infrastructure as code.

Area two is the data and network estate, and it is the heaviest at 25–30%. Storage accounts come first: their security configuration, Azure Storage firewall rules, Defender for Storage threat protection, and access management including access policies. Databases follow, and they are narrower than people expect — platform-level security in Azure SQL, auditing for Azure SQL Managed Instance as well as Azure SQL Database, and Defender for Databases across the Azure database services. Then comes the largest single group in the whole outline, nine sub-bullets of Azure network security: network security groups (NSGs) with application security groups (ASGs), network access policies through Azure Virtual Network Manager, security for an Azure Virtual WAN, virtual private network (VPN) connections, Microsoft Entra Private Access, private endpoints in front of platform as a service (PaaS) resources, Azure Private Link services, Azure Firewall, and effective-rule evaluation using Azure Network Watcher diagnostics.

Area three is compute, and past the AI group it splits in two. Servers and virtual machines bring disk encryption, Azure Bastion, just-in-time (JIT) VM access, hybrid and multicloud reach through Azure Arc, onboarding and configuration for Defender for Servers — vulnerability scanning, endpoint detection and response (EDR), agentless scanning — plus the VM security features Microsoft names: integrity monitoring, security type, secure boot and the virtual Trusted Platform Module (vTPM). Configuration enforcement through Azure Machine Configuration closes that group. Application platform services bring Defender for Containers, then security controls for Azure Kubernetes Service (AKS), Azure Container Registry, Azure Container Instances, Azure Container Apps, Azure Functions, Azure Logic Apps and Azure App Service, closing on Azure Web Application Firewall and back-end API protection policies in API Management.

Area four is posture and operations. Defender for Cloud carries the posture half: risk identification with Defender CSPM, compliance evaluation against security frameworks, workload protection plans, connectors for hybrid and multicloud estates — Google Cloud Platform (GCP) and Amazon Web Services (AWS) are named explicitly — the settings Microsoft Defender Vulnerability Management applies to Azure VMs, and asset discovery through Microsoft Defender External Attack Surface Management (EASM). Microsoft Sentinel then takes ten sub-bullets, the second-largest group anywhere in the outline: workspace creation and connection, role assignment, content hub solutions, Microsoft data connectors for Azure resources, syslog and Common Event Format (CEF) collection, Windows Security event collection through data collection rules and Windows Event Forwarding (WEF), custom log tables, automation rules and playbooks, data retention, and querying Microsoft Purview Audit inside Defender XDR. Security Copilot supplies the last four.

Two notes printed beside the outline change how you should read all of it. Microsoft describes the sub-bullets as illustrations of how each skill gets assessed, and warns that related topics can also appear. So treat the list as the shape of the exam rather than its full contents. Microsoft also says most questions cover features that are generally available. Preview features can be asked about too, but only where they are already in common use. That second note matters more here than on a settled exam, because much of the AI material is young.

One thing this study guide does not give you

Microsoft study guides normally carry a "Skills measured as of" date, and normally a change log too, comparing the current outline against the previous one. SC-500's carries neither. We checked on 9 August 2026, against the study guides for eight other Microsoft exams. All eight publish an as-of date, and seven of them publish a change log. SC-500 was the only one with no date on its outline at all. Its page stamps itself as last updated on 13 May 2026, and that is the only date signal you get.

That is worth knowing rather than worrying about. It means you cannot compare this outline against an older version to see what moved. So if you started studying some months ago, re-read the skills measured section in full. Do not go looking for a summary of the changes, because there isn't one. It also means any site advertising "the SC-500 changes for 2026" is not reading them off Microsoft's page.

Format, score, and the 120 minutes

The certification page gives you 120 minutes. It rates the certification Intermediate and ties it to the security engineer role. The exam is proctored, and Microsoft warns that it may include interactive components.

You pass at 700. The scoring page explains the part people misread: technical exam scores run on a scale from 1 to 1,000, and the number is scaled. 700 is not 70% of the questions answered correctly. The bar reflects two things: the skills being measured, and how hard your particular question set was. That is why an easier set needs more points to pass, and a harder set needs fewer.

Three scoring rules should change how you answer. Guessing is free — a wrong answer earns no point and nothing is subtracted, so never leave an item blank. Multi-part questions usually award a point per correct component, so a partly correct answer still scores. And some questions are unscored trial items that Microsoft is still evaluating; you cannot tell which, so treat every one as if it counts.

Microsoft publishes no question count for SC-500. Several sites state one with confidence. We would rather tell you the number is unpublished than invent it. What you can plan against is the clock: 120 minutes, on an exam whose outline runs to 87 sub-bullets across four areas.

The exam is currently listed in English only. The study guide carries a policy that matters if English is not your first language. When an exam is not offered in the language you prefer, you can request an extra 30 minutes. Booking goes through Pearson VUE. Microsoft recommends registering with a personal Microsoft account rather than a work or school one. The reason is practical: exam records held against an organizational account are lost if you leave that organization. Price is set by the country or region where the exam is proctored. If you fail, the first retake is available after 24 hours; later retakes have longer waits.

Your score report gives an overall number, a pass or fail result, and a bar chart per skill area. Microsoft is explicit that the bars cannot be converted into a count of correct answers, and that it will not tell you which questions you got wrong.

Who SC-500 is for, and what you need first

Microsoft lists no required exam or certification. What it publishes instead is an audience profile, and on an associate exam that profile does more work than a prerequisite would.

It describes a security engineer who protects systems and data across cloud and hybrid estates. That work crosses identity, network, application, data and compute. The same engineer is accountable for the platforms, data, identities and infrastructure that AI workloads depend on. Six responsibilities are listed. Four of them name ground you can point at: access, held through Microsoft Entra ID plus Azure Key Vault; storage, databases and networking; compute; and AI solutions. The remaining two are the wide ones — enforcing security and regulatory compliance, and managing and monitoring security posture.

Then comes the part to take seriously. Microsoft expects three things of you. First, practical experience administering Azure and hybrid environments, compute, network and storage included. Second, deep knowledge of Microsoft Entra ID. Third, at least a working familiarity with Microsoft 365 administration.

That last item surprises people, and what follows is our reading rather than Microsoft's wording. SC-500 is presented as an Azure security exam, yet parts of the AI content live in Microsoft 365 and Microsoft Purview. Identifying oversharing in SharePoint and managing agents from the Microsoft 365 admin center are Azure-adjacent at best. If your background is purely Azure infrastructure, that is the gap to close first.

If you arrived here from AZ-500, we cover that exam's status in a separate article so this one can stay about what SC-500 is.

Does the certification expire?

Yes — and this is where an associate certification differs from a fundamentals one. Microsoft's renewal page puts associate, expert and specialty certifications on an annual cycle, while fundamentals certifications do not expire at all. Cloud and AI Security Engineer Associate is an associate certification, so it renews every year.

Renewal is easier than the exam. The assessment is free, unproctored and open book, taken online through Microsoft Learn inside a six-month window before your expiry date. You can retake it as often as you need within that window, and each pass extends the certification by one year from the expiry date. Given how quickly the AI half of this syllabus is moving, we would treat the annual renewal as a feature rather than a chore.

How to prepare — and the free study aid that is missing

Start with the study guide itself, then the certification page. Between them they carry the outline, the format, the policies and the official preparation links, and they are the only two pages that are guaranteed to be current.

There is one gap you should know about before you build a plan. Microsoft usually publishes a free practice assessment for each exam. For SC-500 it says that assessment is "not currently available", adding that practice assessments usually appear within about eight weeks of an exam leaving beta and reaching general availability. So the free official practice questions many guides tell you to start with do not exist for this exam yet. Check the certification page before you assume otherwise — that line is exactly the sort of thing that changes without an announcement.

What is available for free is the exam sandbox, and it is worth twenty minutes. It puts you in the real interface with the real question types before exam day. Be clear about what it is, though: it demonstrates the mechanics, not SC-500 subject matter.

For structured training, Microsoft publishes course SC-500T00-A, a four-day instructor-led course with hands-on labs that you can also work through as self-paced study. It is rated Intermediate and assumes the same starting point the exam does. One detail for readers outside English-speaking countries: the course is published in several languages, while the exam is currently listed in English only.

Practice questions do their real work in the space the reading leaves behind — the choices this exam actually asks you to make. A private endpoint against a service firewall rule. Defender for Storage against a storage access policy. A managed identity against an app registration. Conditional access applied to a person against conditional access applied to an Entra Agent ID. Reading about a decision is not the same as being asked to make one under a clock.

Our SC-500 practice exams and study guide were written against this outline, with every question tied to the official Microsoft documentation that supports it. No dumps, ever.

Is SC-500 worth it?

Our honest answer depends on what you want from it. As a line on a CV it is an associate security certification like several others, and we will not pretend a badge changes a hiring decision on its own.

Its real value is the coverage. Very few people currently hold all four of these areas at once: Entra ID and Key Vault, the storage and network edge, container and app platform security, and a posture stack that now runs from Defender for Cloud through Sentinel to Security Copilot. Bolted on top is an AI security layer — agent identity, AI gateways, guardrails, DSPM — that is genuinely new work rather than old work renamed. Studying for this exam forces you across all of it in a structured order, which is hard to arrange for yourself.

The cost side is honest too. This is an associate exam with an annual renewal, so it is a commitment rather than a one-off. If you want the schedule instead of the verdict, we wrote an SC-500 study plan and an honest look at how hard it is.

Independent study material. ciply.io is not affiliated with, endorsed by, or sponsored by Microsoft.

Practice SC-500 with real, original questions

Every answer explained and linked to the official page behind it.

Studying for SC-500? Don't study a stale outline.

Microsoft updates exams between your first read and your test date. If SC-500 changes, we email you — one short note, only when it happens.

Only exam-change emails. No marketing. Unsubscribe any time.

Official sources used in this article