SC-100

SC-100

by Beeavo
Season 1

Series 1A.03 — Identity Security Flash Cards

AI
A fast flash-card review of Chapter 3: Designing an Identity Security Strategy. Review ten key vocabulary terms, four primary concepts, and three pause-and-answer recall questions. Part of Series 1A: Flash Cards per Chapter, the short-form companion to the SC-100 study podcast.

Series 1A.02 — Security Operations Flash Cards

AI
A fast flash-card review of Chapter 2: Designing a Security Operations Strategy. Review ten key vocabulary terms, four primary concepts, and three pause-and-answer recall questions. Part of Series 1A: Flash Cards per Chapter, the short-form companion to the SC-100 study podcast.

Series 1A.01 — Strategy and Architecture Flash Cards

AI
A fast flash-card review of Chapter 1: Building an Overall Security Strategy and Architecture. Review ten key vocabulary terms, four primary concepts, and three pause-and-answer recall questions. Part of Series 1A: Flash Cards per Chapter, the short-form companion to the SC-100 study podcast.

Agentic SOC: From Alert Queues to Continuous Defense

AI
James, Emma, and SOC transformation specialist Maya unpack Microsoft's Agentic SOC whitepaper and its proposed operating model for continuous defense. The episode explains why task-driven alert queues struggle against outcome-driven attackers, how protection objectives become the new unit of work, where specialized agents fit, how human roles change, and why an integrated SOC needs shared context, governance, and assurance. It also adds a practical adoption roadmap, implementation guardrails, a payment-service scenario, and recall questions to help the ideas stick. Based on Microsoft Security's 2026 whitepaper, Agentic SOC: The new operating model for continuous defense.

Ransomware: Designing for Resilience and Recovery

AI
James and Emma close the series by designing an architecture that can resist, contain, and recover from human-operated ransomware. Topics include the ransomware economy, attack stages, identity and endpoint controls, segmentation, privileged access, backup isolation, recovery planning, incident response, and rehearsed restoration. Guest incident commander Daniel Frost explains why tested recovery capability creates negotiating power. Includes the final rapid-review round for the series.

Cloud Adoption Framework and Secure Delivery

AI
James and Emma examine how security fits into the full cloud-adoption lifecycle. This episode covers the Cloud Adoption Framework, governance, secure methodology, DevSecOps, feedback loops, ownership, policy, platform teams, and the operating model required to turn findings into remediation. Guest DevSecOps lead Grace Nwosu explains why a finding without an owner, deadline, and delivery path is inventory rather than remediation.

Security Best Practices and RaMP

AI
James and Emma turn security best practices into practical architecture decisions. Topics include common antipatterns, credential theft, administrative separation, the Microsoft Cloud Security Benchmark, internal standards, security transformation, and the Ransomware and Malicious Extortion Protection approach. Guest transformation lead Ben Carter explains why recommendations only reduce risk when they become repeated, owned, measurable behavior.

Data Security, Classification, and Protection

AI
James and Emma follow data through classification, labeling, protection, monitoring, and retention. This episode covers Microsoft Purview, sensitivity labels, data loss prevention, encryption, classification quality, taxonomy design, retention policies, and architectural decisions that keep controls aligned with the meaning of the data. Guest data-governance specialist Dr Evelyn Park explains why classification gives every later control useful context.

Application Security and Threat Modeling

AI
James and Emma walk through secure application architecture from design to deployment. Topics include threat modeling, STRIDE, trust boundaries, secure development practices, application identities, managed identities, API authorization, secrets, pipelines, and runtime protection. Guest application-security engineer Felix Morgan explains why the cheapest breach is the one removed from the design diagram. Includes recall pauses and exam-focused review.

Securing Cloud Services

AI
James and Emma map security responsibilities across IaaS, PaaS, SaaS, containers, Kubernetes, IoT, and cloud storage. The episode explains shared responsibility, configuration risks, network exposure, dangling DNS, data access, and how architects choose controls at the correct service boundary. Guest cloud-platform engineer Aisha Rahman provides a memorable way to locate accountability before selecting a control.
2 of 3