SC-100 · Domain 1
Design solutions that align with security best practices and priorities
About 23% of the exam
Zero Trust principles and pillars
- Verify explicitly
- authenticate and authorize on all signals
- Least privilege
- just enough, just in time
- Assume breach
- segment, encrypt, monitor, verify continuously
- Identity pillar
- the primary control plane
- Devices pillar
- compliance signals feed access decisions
- Applications pillar
- discover, govern and monitor them
- Data pillar
- classify, label and protect it
- Infrastructure and network
- harden, segment and detect at runtime
Microsoft sequences identity and devices first because Conditional Access needs those signals before any later pillar can make a real decision
The frameworks and what each is for
- Cloud Adoption Framework
- enterprise adoption and platform governance
- Well-Architected Framework
- design quality of one workload
- Cybersecurity Reference Architectures
- capability diagrams across the portfolio
- Cloud security benchmark
- prescriptive controls per service
- Security Adoption Framework
- a program for modernizing security
- Landing zones
- the governed platform workloads land on
- Technique mapping
- diagrams tied to adversary behavior
Conditional Access as policy engine
- Signals in, an access decision out
- User, device, location, application and risk
- Grant controls require compliance or authentication
- Session controls limit what happens next
- Block legacy authentication tenant wide
- Report only mode before enforcement
Common design mistakes
- A trusted network as an alternative grant
- Emergency accounts excluded and forgotten
- Policies scoped to users, missing workloads
- Compliance self asserted by the device
- No break glass account ever tested
Turning goals into requirements
- Name the measurable outcome and window
- Tie each control to a pillar
- State the signal the decision uses
- Define the evidence that proves it
- Sequence by risk reduction per effort
Resiliency in the design
- Assume identity provider outages happen
- Backups isolated from production credentials
- Immutable copies for ransomware recovery
- Recovery objectives agreed with the business
- Rehearse recovery, not just backup
Zero Trust across the pillars
Identity and devices
- Strong phishing resistant authentication
- Conditional Access on every application
- Compliance evaluated by device management
- Privileged roles activated just in time
Network and workloads
- Private endpoints instead of public access
- Microsegmentation between application tiers
- Bastion sessions for administration
- Runtime detection on every host
Building the roadmap
- Assess the current posture
- Agree business risks and priorities
- Modernize identity and device controls
- Extend to applications and data
- Segment networks and workloads
- Mature operations and response
- Measure and report continuously
- Identity first buys the widest reduction
- Quick wins fund the longer work
- Each phase needs measurable exit criteria
- Architecture decisions recorded, not remembered
Governance guardrails
- A management group hierarchy before policy
- Policy inherited by future subscriptions
- Deny effects stop bad deployments
- Deploy effects fix missing configuration
- Exemptions documented with an owner
- Landing zones separate platform and workload
Measuring progress
- Secure score trend across clouds
- Share of applications behind policy
- Standing privileged assignments remaining
- Mean time to detect high severity
- Coverage against relevant adversary techniques
- Compliance dashboard against chosen standards
Translating a business ask
- Partners lose access when projects end
- Personal devices view but never download
- Administrators work only from hardened devices
- Nothing internet facing unless justified
- Detection measured in minutes, not days
Which framework answers what
- Enterprise platform question
- the Cloud Adoption Framework
- Single workload design
- the Well-Architected Framework
- Which capability does this
- the reference architectures
- Service level control
- the cloud security benchmark
- Program sequencing
- the Security Adoption Framework
- Adversary coverage
- attack technique mapping
Words the exam repeats
- Explicit verification
- check every available signal
- Least privilege
- just enough and time bound
- Assume breach
- design as though already inside
- Control plane
- where permissions are granted
- Blast radius
- how far a compromise spreads
Reviewing a proposed design
- Does identity gate every path
- Are device signals actually required
- Is standing privilege eliminated or justified
- Can the workload be reached publicly
- Where does telemetry land and who watches
- What happens when the control fails
- Is recovery tested against ransomware
An either or between a compliance requirement and a trusted location silently reintroduces network trust, which is exactly what the model set out to remove
Reference strip: principles, frameworks, policy, roadmap, metrics
Principles
- Verify explicitly, least privilege
- Assume breach in every design
- Identity is the control plane
Frameworks
- Adoption framework governs the estate
- Well-Architected reviews one workload
- The benchmark supplies service controls
Policy
- Conditional Access decides access
- Azure Policy decides configuration
- Both inherit from the top
Roadmap
- Identity and devices first
- Then applications and data
- Operations mature throughout
Metrics
- Secure score over time
- Standing privilege count
- Detection and response times
Quick exam traps
- Trap: Zero Trust means removing the network perimeter and nothing else
- Trap: The Well-Architected Framework governs the whole enterprise estate
- Trap: A trusted corporate address is a sufficient access signal
- Trap: Zero Trust is a product you deploy rather than a strategy
- Trap: Conditional Access policies only need to cover interactive users
- Trap: Reference architectures are prescriptive control requirements
- Trap: Once secure score is high the roadmap is finished
cybercertprep.com · original revision sheet written from the public body of knowledge