98-367 Security Fundamentals Exam Guide
Exam 98-367 was Microsoft’s Security Fundamentals exam within the Microsoft Technology Associate program. It validated introductory knowledge of security layers, operating-system protection, authentication, policies, network security, and client and server safeguards for learners beginning an IT infrastructure career. The important decision now is not simply how to study: Microsoft retired MTA exams on June 30, 2022, so a reader should first determine whether this guide is being used to understand a legacy credential, support an existing course, or choose a current Microsoft fundamentals or role-based learning path.
Is Exam 98-367 still available?
No. Microsoft retired the MTA program and stated that candidates had until June 30, 2022 to register for and take an MTA exam. Microsoft also states that an exam cannot be taken and its associated credential cannot be earned after its retirement date. Treat 98-367 as a historical exam, not as a current scheduling target. See https://learn.microsoft.com/en-us/credentials/certifications/mta-retirement-faqs and https://learn.microsoft.com/en-us/credentials/support/retired-certification-exams.
What the retirement means for learners
A learner who already earned the MTA Security Fundamentals certification does not lose it because the exam retired. Microsoft says existing MTA certifications remain on the certification transcript and remain printable, although retired certifications move to the “Certification History” section of the transcript two years after the certifications retire. The retirement therefore changes future testing and earning options, not the validity of an already earned record.
For someone who has not passed 98-367, preparation should normally support a broader security-learning objective rather than an attempt to schedule this exam. Microsoft describes newer fundamentals certifications as foundation credentials with mixed concepts and applied learning that can lead toward role-based training and certifications. Confirm the current alternative through Microsoft Learn rather than assuming that another exam is a direct replacement.
The practical decision before studying
First identify the reason 98-367 appears in your plan. If it is listed in a historical syllabus, use the objectives to learn foundational security concepts. If you need a current Microsoft credential, pause this study plan and review the current Microsoft certification catalog. If you already hold the credential, use this guide as a refresher without planning a retake, because Microsoft’s retirement guidance does not permit taking the exam after retirement.
What 98-367 was designed to validate
Exam 98-367, identified by Microsoft as “Security Fundamentals,” was associated with the MTA Security Fundamentals certification. Microsoft’s support material placed it in the IT infrastructure group for people intending to build a career in desktop infrastructure, server infrastructure, or private cloud computing. Its intended level was foundational: candidates needed to recognize security concepts and apply them to common systems, policies, and network situations rather than study it as an advanced specialist exam.
Who benefited from the exam
The exam was a reasonable fit for students, educators, and entry-level IT learners building a base in infrastructure security. It also served learners who wanted an introductory credential before moving toward more specialized Microsoft technologies. That audience description should not be mistaken for a current prerequisite: the supplied official material does not establish a present-day prerequisite, required work experience, or replacement route for 98-367.
A useful modern interpretation is to treat the exam as a diagnostic framework. Someone new to security can use its five topic areas to expose gaps in vocabulary and systems thinking. Someone already working with Windows or networks can use the domains to separate familiar operational tasks from concepts that require deliberate review.
What success would have demonstrated
A strong 98-367 candidate would have been able to distinguish layers of security, explain how authentication and authorization differ, connect policies to administrative controls, identify basic network defenses, and describe ways to protect servers and clients. The objective document also incorporated Windows 10 updates and security and threat terminology effective June 23, 2016, so its terminology belongs to the historical scope of the exam.
Which skills belong in the study plan?
Build the study plan around the five topic areas named in Microsoft’s official course material: security layers, authentication/authorization/accounting, security policies, network security, and protecting servers and clients. The objectives document groups these ideas into three weighted domains, so the roadmap should give the most deliberate practice to operating-system security while still covering the conceptual and network areas in full.
Security layers: 25–30% of the exam
Understanding security layers represented 25–30% of the exam. The associated security-layer domain included core security principles, physical security, Internet security, and wireless security. Study these as connected controls rather than isolated definitions: physical access can undermine a well-configured computer, and a wireless or Internet exposure can bypass assumptions made inside a protected office.
Practical study questions include: What asset or boundary is being protected? Which threat is being reduced? Is the control physical, administrative, technical, or a combination? What would fail if that control were absent? These questions help turn terminology into reasoning instead of memorization.
Operating-system security: 30–35% of the exam
Understanding operating-system security represented 30–35% of the exam. The associated operating-system security domain included user authentication, permissions, password policies, audit policies, encryption, and malware. Give this domain the largest study block because it contains several controls that interact directly: authentication establishes identity, permissions govern access, auditing records activity, and encryption protects data even when access boundaries are challenged.
Use a comparison table or handwritten matrix with columns for purpose, example control, likely failure, and evidence of operation. For example, do not record only that permissions control access; record whose access is being controlled, what resource is affected, and how an administrator could review or change that access.
Network security: 20–25% of the exam
Understanding network security represented 20–25% of the exam. The associated network-security domain included dedicated firewalls and Network Access Protection, or NAP. Focus on the boundary each control protects and the condition it evaluates. A firewall concerns traffic control at a network boundary, while NAP concerns whether a connecting computer satisfies defined health requirements.
Avoid treating every network-security term as interchangeable. During review, describe the problem first, then select the control that addresses it. This approach is more useful than memorizing a list of products or features, especially because the exam’s objectives are historical and should not be treated as a current product-design reference.
Authentication, authorization, accounting, policies, and protection
The official course material names authentication, authorization, and accounting as a topic area alongside security policies and protecting servers and clients. These topics should be threaded through the three weighted domains rather than studied as a disconnected glossary. Ask who is identified, what that identity may do, what activity is recorded, which rule governs the action, and what system or data needs protection.
A useful exercise is to write short scenarios involving a user account, a protected resource, a policy decision, and an audit record. Then label each sentence as identity, access, governance, monitoring, or protection. This exposes a common weakness: knowing the words but confusing the stage at which each control operates.
How should you prepare for a historical exam blueprint?
Use the official objectives as the boundary of study, but do not mistake an old blueprint for current security guidance. Start with the domain labels and their stated ranges, learn the underlying concepts, and then verify any present-day Microsoft technology path separately. Because 98-367 is retired, the best preparation outcome is transferable understanding or coursework support, not an unsupported promise of an available exam attempt.
Begin with an objective inventory
Copy each objective into a checklist and mark it as unfamiliar, partly understood, or explainable without notes. Do not begin by reading every available security article. The objective inventory tells you whether the main gap is vocabulary, Windows administration, network boundaries, policy reasoning, or the ability to connect several controls in one situation.
Keep the original wording and domain label beside your notes. This prevents a broad security course from consuming study time on advanced subjects that were not part of the supplied 98-367 evidence. It also makes progress measurable: an item is stronger when you can explain its purpose, use, limitation, and relationship to another control.
Study the largest domain first, but do not skip foundations
Allocate the first substantial block to operating-system security because that domain represented 30–35% of the exam. Then study security layers at 25–30% and network security at 20–25%, keeping the exact domain name attached to each range in your notes. Finish by integrating the five official topic areas through scenario practice.
This order is a practical recommendation, not an additional Microsoft requirement. Weighting does not mean that the other domains are optional, and it does not reveal the exact number or format of questions. It simply provides a defensible way to distribute limited study time.
Use explanation and classification, not dumps
Practice by explaining why a control fits a situation, classifying the security layer involved, and distinguishing identity, permission, policy, monitoring, and protection. Exam dumps or leaked-question claims are not a substitute for learning and cannot guarantee a pass. They can also train recognition of obsolete wording instead of the reasoning needed to work safely with real systems.
Create your own question prompts from the objectives without reproducing live exam content. Examples include: Which control addresses unauthorized local access? Which control records activity for later review? Which policy governs credential behavior? Which boundary does a firewall protect? Answer from principles, then check the objective document and authoritative Microsoft material.
What is a practical study roadmap?
A four-stage roadmap works well for a learner using 98-367 as a legacy syllabus: establish the scope, learn the control families, integrate them in scenarios, and conduct a gap review. The stages are recommendations rather than official scheduling requirements. Since the exam is retired, adjust the final stage toward a current learning objective or credential instead of assuming that an appointment can be booked.
Stage 1: Establish scope and baseline
Start by reading the official objectives document and the official module outline. Record the five topic areas and the three weighted domains. Then take an untimed self-check using your own prompts. For every weak item, write what you do not know: definition, purpose, configuration concept, comparison, or scenario application.
At this stage, do not chase a score. The point is to find whether your problem is broad or concentrated. A learner who understands authentication but cannot explain auditing needs a different plan from one who knows individual terms but cannot classify a network boundary.
Stage 2: Build operating-system security knowledge
Study user authentication, permissions, password policies, audit policies, encryption, and malware as one control system. For each subject, produce a short explanation and a failure example. Then connect the subjects: a password policy affects authentication, permissions affect authorization, audit policies provide evidence, and encryption protects information from disclosure.
Use a lab only where it is safe and appropriate, and do not treat a lab result as proof that a historical exam is available. The useful outcome is the ability to explain what a setting is intended to control and what evidence would show that the control is working.
Stage 3: Connect layers and network defenses
Next, combine core security principles, physical security, Internet security, wireless security, dedicated firewalls, and NAP in scenario notes. Draw a simple path from a person or device to a resource, then mark each possible control point. This makes it easier to see why one defensive measure cannot replace all other layers.
When reviewing a scenario, identify the asset, threat, boundary, control, and residual risk. Keep the language precise: a firewall is not a general answer to every security problem, and a policy is not the same thing as a technical enforcement mechanism.
Stage 4: Integrate and redirect
In the final stage, explain all five topic areas without notes and revisit only the objectives that still produce uncertainty. Then decide whether the result supports a class, an internal knowledge check, or a current Microsoft learning path. Because Microsoft retired MTA exams on June 30, 2022, the correct next action for an uncredentialed learner is normally redirection, not repeated attempts to locate a booking page.
If you already earned the certification, document it through your Microsoft Learn transcript and use the study notes for skills maintenance. Microsoft’s retirement guidance says earned certifications remain on the transcript; it does not say that the retired exam can be renewed or retaken.
Which mistakes waste the most preparation time?
The biggest errors are planning around an obsolete exam, confusing related security controls, studying beyond the objective scope, and relying on memorized answers. Correct these before adding more resources. A disciplined candidate verifies status first, keeps every percentage attached to its domain, and tests whether they can explain a control in a new scenario.
Mistake: assuming an exam page means an exam is schedulable
Microsoft’s retirement pages may preserve links to historical exam detail pages for reference purposes for 12 months after retirement, but a preserved page is not evidence of current registration or delivery. Check the retirement information first. The official guidance states that retired exams cannot be taken and the associated credential cannot be earned after retirement.
Mistake: learning labels without relationships
Security vocabulary becomes fragile when authentication, authorization, accounting, auditing, encryption, and policy are memorized as unrelated definitions. Force each term into a sequence: establish identity, decide access, apply a rule, record activity, and protect data. Then ask what happens when one stage is weak. This is a more durable study method than copying a glossary.
Mistake: treating blueprint ranges as a question forecast
The ranges describe domain allocation, not a guaranteed question count, exact distribution, or passing score. Never convert 25–30% for security layers, 30–35% for operating-system security, or 20–25% for network security into a prediction about a particular test form. Use the ranges only to prioritize coverage while studying the full objective set.
Mistake: ignoring the historical technology context
Microsoft states that the 98-367 objectives incorporated Windows 10 updates and security and threat terminology effective June 23, 2016. That makes the document valuable for understanding the exam’s scope, but it also warns against presenting the blueprint as a complete description of current Microsoft security technologies. Pair historical study with current official learning material when your goal is job preparation.
Are delivery details, prerequisites, and scores available?
The supplied official research does not establish current delivery methods, languages, duration, question count, passing score, price, prerequisites, or retake scheduling for 98-367. Since the exam retired on June 30, 2022, do not rely on third-party listings that present such details as current. For any alternative credential, consult that credential’s current Microsoft Learn page directly.
What can be stated with confidence
Microsoft identified 98-367 as Security Fundamentals and linked passing Exam 367 to the MTA Security Fundamentals certification. Microsoft also stated that passing the required exam before June 30, 2022 earned the certification. These are historical program facts, not an indication that a new candidate can now register, sit the exam, or earn the credential.
What should not be inferred
Do not infer a current replacement exam from the old exam number, assume that a similarly named security certification covers the same objectives, or publish an unverified test-center, online-proctoring, language, fee, or scoring claim. Those details vary by credential and time. A careful study page should direct the reader to the official current catalog instead of filling gaps with catalogue listings or forum speculation.
What should you do next?
Choose the next action based on your status: verify an existing credential, use the blueprint for foundational learning, or move to a current Microsoft pathway. This prevents wasted preparation on an exam that cannot be taken. Keep the official objective document as a historical reference, and use current Microsoft pages for any credential you may pursue now.
If you already hold the MTA credential
Open your Microsoft Learn transcript and confirm that the certification is recorded. Microsoft says an earned MTA certification remains on the transcript and remains printable after retirement. Keep a copy for your records if an employer or education provider needs evidence, and do not plan a 98-367 retake because the retired exam is no longer an earning route.
If you are studying 98-367 for a course
Use the five topic areas as a structured syllabus. Read the objectives, create control-comparison notes, and practice explaining operating-system and network security decisions. Tell your instructor or program administrator that the MTA exam retired on June 30, 2022, so course completion and examination availability are separate matters.
If you need a current career credential
Stop before buying study material marketed specifically as a current 98-367 preparation product. Review Microsoft’s current fundamentals and role-based offerings, select a path aligned with your target work, and then obtain that credential’s official skills outline and delivery information. Microsoft explains that its certification direction shifted toward role-aligned offerings as MTA certifications retired; the current catalog is the authority for what can be earned now.
Conclusion
Exam 98-367 remains useful as a compact map of foundational security thinking, especially across security layers, operating-system controls, policies, authentication, and network defenses. It is not a current Microsoft exam: MTA exams retired on June 30, 2022, and the associated credential cannot be earned afterward. Use the official objectives to study concepts or complete historical coursework, then make your next credential decision from the current Microsoft catalog. Avoid unsupported scheduling claims, memorized dumps, and any study plan that treats the retired blueprint as current product guidance.