Closing the Gap: How I'm Prepping for the SC-900 Retake
A week ago I told you I didn't pass the SC-900 — 668 out of 700, thirty-two points short. This is the other half of that post: not the debrief, but the comeback plan, in progress and out loud.
I'll lead with the number that matters, because this whole blog runs on real numbers: four days after the fail, I sat the official Microsoft practice assessment again and scored 90%.
668 on the real exam → 90% four days later.
Not "I'm ready." Something quieter: the knowledge survived the fail.
That number isn't "I'm ready" — it's something quieter and, honestly, more reassuring: the knowledge survived the fail. The foundation held. Now the job is proving it on unseen questions and in the formats that actually beat me. Here's exactly how I'm doing that.
First: I let the score report do the diagnosing
The instinct after a fail is to study everything harder. That's how you burn two weeks and still walk in shaky. My score report refused to let me do that — it named precisely where I was weakest, and it wasn't where I expected.
My scary domain going in was Compliance. Back in June I was at 40% cold, and Purview terrified me. But the report showed Compliance had become one of my strongest sections — the daily drilling in the spring had quietly fixed it. The gap I feared most wasn't the one that got me.
The real weak spot was Microsoft Security solutions — the heaviest-weighted domain on the whole exam (35–40%). And Microsoft handed me a gift: three named skills to prioritize, all sitting right there:
Threat protection with Microsoft 365 Defender
Basic security capabilities in Azure
Security capabilities of Microsoft Sentinel
That's not "study more." That's a bullseye. All my drilling energy went there instead of getting spread thin across domains I'd already earned.
Second: I drilled the format, not just the facts
Here's the lesson from my debrief that I actually built prep around: on SC-900, the content is only half the exam. The format is the other half.
The test leaned hard on drag-and-drop and true/false questions, and those punish "almost" knowing something in a way multiple choice doesn't — no elimination, no reasoning toward the best answer, just do you know this exactly, cold. My strongest test-taking skill (ruling out wrong answers) was gone.
So I stopped studying only to recognize answers and started drilling to produce them:
Matching, cold. I cover the descriptions and force myself to name which Defender owns which surface, which Azure service does which job — no lifeline. That's drag-and-drop, rehearsed.
Hunting the qualifier. For true/false, I take a fact and write the false version by flipping one word — only, all, always, requires — and practice catching the word that breaks it. That's the exact muscle those questions test.
The 90% came from drilling the shape of the questions, not just the material inside them.
The drilling narrowed my weak spot down to almost nothing — at this point it's essentially one recurring confusion: NSG vs. Azure Firewall. A Network Security Group is the basic, rule-based traffic filter attached to a resource or subnet; Azure Firewall is the managed, stateful firewall for a whole virtual network. When a network question shows up, I run one rule — is it asking about simple allow/deny rules on a resource (NSG), or network-wide managed protection (Firewall)? Naming the single distinction that still trips me up, and giving it a rule, is the difference between "I'm weak on networking" and "I have one clean thing left to nail."
Third: practice exams as the real yardstick
This is where I got specific about which practice matters — and I've learned that every practice source lies to you in a different direction unless you know its bias. I've now used three, and they're not interchangeable.
The official Microsoft practice assessment has been my through-line yardstick the whole way: 40% cold in June, 82% right before the exam, and 90% just four days after failing it. That last number is the one I keep coming back to — not because it means "I'm ready," but because of what it proves: four days after a disappointing result, the knowledge was still there. The foundation survived the fail. That's a retention signal, not a victory lap.
The Microsoft assessment has real limits I now understand. It's all multiple choice — so it can't rehearse the drag-and-drop and true/false formats that actually beat me. And it has a limited question pool, so once you've run it a few times, you're measuring your memory of those questions, not your readiness on new ones. It tells the truth about what you know; it can't tell you how you'll do on unfamiliar questions in unfamiliar formats.
Udemy taught me the opposite lesson. I scored 64% on a Udemy practice test before the exam, and at the time that number worried me. But now that I've seen the real exam, I can say something I couldn't before: Udemy's questions are actually harder than the real thing. So that 64% wasn't the alarm it felt like — Udemy over-indexes difficulty, which means it understates your readiness. A tougher yardstick than exam day.
Which is why my real proving ground now is Coursera's practice exams, on the Microsoft Cybersecurity Analyst program — and I haven't sat them yet. That's the point. They're unseen questions, a fresh pool the Microsoft assessment can no longer give me. Two rules I hold myself to when I do sit them:
The first attempt is the real one. Your first score on an unseen practice exam is the only honest one — a second run just measures your memory of that exam. A first-attempt score in the 85–90% range is my signal I'm actually ready to book.
Label every miss. For each wrong answer, I tag why: wrong product, wrong qualifier, wrong license, or wrong direction (traffic in vs. out). The labels turn a vague "I got some wrong" into a visible pattern — and the pattern is what you drill next.
The meta-lesson, and the CC taught me this too: know what each practice source can and can't tell you. Microsoft confirms retention. Udemy is harder than reality. Coursera is the clean, unseen signal. Free or paid, a practice test you misread will lie to you about your readiness.
The part I'm proudest of: I haven't booked yet
Here's the discipline, and it's the whole point.
Ninety percent is a great score. The old me — the me who booked the first attempt — would've taken that number and slammed the retake onto the calendar to make the sting go away. That's exactly the mistake that cost me 32 points the first time: I walked in on a score that was just over the line on practice, and just-over on practice became just-under on the real thing.
So I'm not booking on one good score. I'm holding until my first-attempt scores land comfortably in that 85–90% range across more than one practice exam — proof the 90% wasn't a single good day, but a repeatable margin on unseen questions. The retake policy lets me rebook fast; my readiness decides when, not my impatience.
That's not slowness. It's the pacing lesson I keep writing about, finally applied to the highest-stakes decision on the board: book on the signal, not the schedule.
How I'd explain this in a SOC interview
Ask me how I recover from a failure and prevent the repeat, and here's the answer: I don't just try harder — I get precise. I used the objective post-mortem to isolate the true root cause instead of guessing, focused my limited time on the highest-impact gap rather than spreading it evenly, and I built in a verification gate before I'd call it fixed — I don't close the ticket on one green signal; I confirm the fix holds. That's the same discipline a SOC runs on: root-cause the miss, remediate the specific weakness, and validate before you declare it resolved. A failed exam and a missed detection get the same treatment — diagnose, correct, verify, then move.
Retake's coming — soon, but on my terms. Same map, sharper, and this time I'm walking in with a margin instead of a prayer.
Storm to SOC — read the map, then move. 💜



Comments