Skip to content

SC-400 Practice Questions

Prepare for SC-400 with more than an answer.

172 questions in the full set20 sample questionsUpdated Jan 25, 2026

Unlock the full exam and previous versions

  • v1Version 1 183 questions Locked
  • SC-400Legacy Microsoft Information Protection Administrator 172 questions Current
Exam fee
$165 USD
Level
Associate
Valid for
2 years
Domains covered on the exam 5
  1. Implement information protection27.5%
  2. Implement DLP17.5%
  3. Implement data lifecycle and records management12.5%
  4. Monitor and investigate data and activities by using Microsoft Purview17.5%
  5. Manage insider and privacy risk in Microsoft 36517.5%
  1. 1

    A company wants to prevent employees from uploading documents containing sensitive intellectual property, identified by a custom trainable classifier named 'Project Phoenix', to their personal cloud storage accounts like Dropbox and Google Drive. The company uses Microsoft Defender for Cloud Apps. Which configuration is required to enforce this control?

    Show answer details

    Correct answer: B

    Microsoft Defender for Cloud Apps integrates with Microsoft Purview Information Protection. To control real-time user activities like file uploads to specific cloud apps, you must configure a session policy. This policy can be configured to perform content inspection, leveraging data classification services like the 'Project Phoenix' trainable classifier. When a match is found, the policy can apply a control, such as blocking the upload. A file policy scans files at rest, not in-transit uploads. An app governance policy is for OAuth app behaviors, and a standard DLP policy in Purview without Defender for Cloud Apps integration cannot control unsanctioned third-party apps.

  2. 2

    True or False: A Data Loss Prevention (DLP) policy tip configured to display in Microsoft Outlook for Windows (desktop client) will also automatically display in Outlook on the web without any separate configuration.

    Show answer details

    Correct answer: A

    DLP policies for Exchange Online are configured at the service level. When you enable policy tips in a DLP policy, the setting applies to all supported Outlook clients that can render them, including modern versions of Outlook for Windows, Outlook for Mac, and Outlook on the web. No separate configuration is needed to enable the same policy tip in Outlook on the web if it's already configured for the Exchange location.

  3. 3

    A pharmaceutical company has a strict regulatory requirement to retain all research data related to a clinical trial for 15 years after the trial is officially completed and approved by regulators. The completion date varies for each trial. The IT team needs to design an automated retention solution in Microsoft 365. Trial-related documents are stored in dedicated SharePoint sites and Teams channels. What is the most appropriate Microsoft Purview feature to initiate the 15-year retention period from the specific completion date of each trial?

    Show answer details

    Correct answer: C

    Event-based retention is designed for scenarios where the retention period starts from an event that occurs outside of the content's properties (like creation or modification date). In this case, the 'TrialCompleted' date is the external event. An administrator would create an event type, apply a retention label configured to start retention based on that event to all trial documents, and then create an event instance with the specific completion date for each trial. This starts the 15-year clock for all associated documents on the correct date. Static policies or creation-date-based labels would not meet the requirement of starting retention from a variable completion date.

  4. 4

    An administrator is investigating why a document in a SharePoint library that should be retained for 5 years was permanently deleted. The administrator suspects a conflict between multiple retention policies and labels. The document had a 'Contracts' retention label applied, but the SharePoint site is also included in a site-wide retention policy. Which Microsoft Purview tool should the administrator use to determine which policy won and resulted in the item's deletion?

    Show answer details

    Correct answer: C

    The Policy lookup tool is specifically designed to troubleshoot retention policy conflicts. It allows an administrator to specify a site, mailbox, or user and see all retention policies and labels that apply. Most importantly, it simulates the principles of retention to show which policy (the one with the longest retention period, or the explicit inclusion) would 'win' for a given location, helping to diagnose why content might have been deleted or retained unexpectedly. Content Explorer shows what data is classified, Activity Explorer shows user activities, and Audit Log shows actions taken, but only Policy lookup explains the 'why' behind policy application.

  5. 5

    A company is enabling Microsoft Purview Audit (Premium) to gain deeper insights into user activities, particularly for forensic investigations. A key requirement is to log when users perform searches in Exchange Online and SharePoint Online. To ensure these search activities are captured, which prerequisite must be met?

    Show answer details

    Correct answer: C

    Audit (Premium) features, including high-value events like MailItemsAccessed and user search activities, are not enabled by default with standard auditing. The primary prerequisite for these advanced audit events to be logged is that the users being audited must have the appropriate license, which is typically a Microsoft 365 E5 license or a specific Microsoft 365 E3 with a compliance add-on that includes Audit (Premium). Without the correct license assigned, these premium events will not be generated or captured in the audit log.

  6. 6

    A financial services firm is implementing Microsoft Purview Data Loss Prevention (DLP) to protect client data on corporate Windows 11 devices. The firm's policy must prevent users from copying sensitive content, identified by the 'Financial Records' sensitivity label, to any personal USB storage device. However, copying to company-issued, encrypted USB devices must be permitted. All other USB devices should be blocked entirely for any file transfer. Which Endpoint DLP setting is the most precise and efficient for achieving this granular control?

    Show answer details

    Correct answer: C

    This is the most precise and scalable solution. By creating a 'Removable storage device group' for the authorized devices, you can create specific DLP rules that reference this group. This allows you to build a policy that explicitly permits copying of sensitive data ONLY to this approved group, while a more general rule can block copying to all other USB devices. Simply allowing hardware IDs in the global settings doesn't integrate with the sensitivity label context, and a simple block rule doesn't allow for the required exception for company-issued devices.

  7. 7

    A legal firm is required to retain all client-related email communications for a period of 10 years after a case is officially closed. The closure of a case is a specific event that varies for each client. The firm needs to automate this retention process to ensure compliance and minimize manual overhead. Which combination of features in Microsoft Purview should be implemented to meet this requirement? (Select TWO).

    Show answer details

    Correct answer: B, E

    A retention label is required to define the retention settings, such as the 10-year period and the disposition action. Critically, it must be configured to start the retention period based on an event rather than the content creation or modification date.

    Event-based retention requires an event type to be defined (e.g., 'Case Closed'). When a case is closed, an instance of this event is created (often via a script or Power Automate) with asset IDs (like the email message IDs or mailbox), which triggers the 10-year retention countdown defined in the associated retention label.

  8. 8

    A healthcare organization is configuring Microsoft Purview Insider Risk Management to detect potential HIPAA data violations. They have connected their HR system, which provides employee termination dates. A policy needs to be created that specifically monitors for high-volume downloads of files containing patient health information (PHI) from SharePoint Online by employees within 30 days of their termination date. What is the most critical prerequisite for this policy to function effectively?

    Show answer details

    Correct answer: C

    Insider Risk Management relies heavily on signals from the Microsoft 365 audit log to detect user activities. Without auditing enabled for SharePoint file activities (like FileDownloaded), the policy will not receive the necessary signals to detect the high-volume downloads, rendering the policy ineffective regardless of other configurations like the HR connector or policy template.

  9. 9

    An administrator at a manufacturing company has created a file plan in Microsoft Purview Records Management. They have defined several retention labels, including 'Engineering-Blueprints' which is configured to mark items as a regulatory record. The administrator now needs to ensure that this label is automatically applied to all documents within a specific SharePoint document library named 'Active Projects\Final Blueprints'. What is the most direct method to achieve this?

    Show answer details

    Correct answer: B

    The most direct and simplest way to apply a default retention label to all new content in a specific document library is to configure it directly in that library's settings. This ensures any new document uploaded or created in that location automatically inherits the 'Engineering-Blueprints' label. An auto-apply policy is more complex and typically used for applying labels based on content or metadata across multiple locations.

  10. 10

    True or False: After a Preservation Lock is applied to a retention policy in the Microsoft Purview compliance portal, a Global Administrator can remove the lock if a valid business or legal justification is provided through a Microsoft support case.

    Show answer details

    Correct answer: B

    A Preservation Lock is designed to make a retention policy immutable to meet strict regulatory requirements (like SEC Rule 17a-4). Once a lock is applied, it cannot be disabled or made less restrictive by anyone, including a Global Administrator or Microsoft Support. This is a fundamental principle of the feature.

Create an account to continue.