A pretty minor update for SC-900 goes live later this month, the changes mostly being naming changes with Microsoft Defender for Cloud and Microsoft Sentinel. If you work across Azure and Microsoft 365 security and compliance capabilities, this should be a pretty straight forward exam for you. If you only focus on the security and compliance capabilities of one of them, just make sure you focus your preparation on the areas that you are least familiar with.

Describe the Concepts of Security, Compliance, and Identity (10-15%)

Describe security and compliance concepts & methodologies

Describe identity concepts

Describe the capabilities of Microsoft Identity and Access Management Solutions (30-35%)

Describe the basic identity services and identity types of Azure AD

Describe the authentication capabilities of Azure AD 

Describe access management capabilities of Azure AD

Describe the identity protection & governance capabilities of Azure AD

Describe the capabilities of Microsoft Security Solutions (35-40%)

Describe basic security capabilities in Azure

Describe security management capabilities of Azure

Describe security capabilities of MicrosoftSentinel

Describe threat protection with Microsoft 365 Defender

Describe security management capabilities of Microsoft 365 

Describe endpoint security with Microsoft Intune

Describe the Capabilities of Microsoft Compliance Solutions (25-30%)

Describe the compliance management capabilities in Microsoft

Describe information protection and governance capabilities of Microsoft 365

Describe insider risk capabilities in Microsoft 365

Describe the eDiscovery and audit capabilities of Microsoft 365

Describe resource governance capabilities in Azure

Check out my other exam reference guides here.