Skip to content

SC-401 Practice Questions

Prepare for SC-401 with more than an answer.

183 questions in the full set20 sample questionsUpdated Feb 19, 2026

Unlock the full exam and previous versions

  • v1Version 1 183 questions Current
  • SC-400Legacy Microsoft Information Protection Administrator 172 questions Locked
Exam fee
$165 USD
Level
Associate
Valid for
2 years
Domains covered on the exam 3
  1. Implement information protection30%
  2. Implement data loss prevention and retention30%
  3. Manage risks, alerts, and activities30%
  1. 1

    You are creating a DLP policy to prevent the sharing of documents containing U.S. Social Security Numbers. You need to configure the policy to trigger only when more than 5 unique Social Security Numbers are detected in a single document to reduce false positives from test data. Which setting in the DLP rule configuration should you modify?

    Show answer details

    Correct answer: A

    The 'Instance count' setting allows you to specify the number of occurrences of a sensitive info type that must be found before the policy rule is triggered. By setting the instance count range from 6 to 'any' (or '5 to any' if you mean 5 or more), you ensure the policy only acts on content with a high volume of the sensitive data, which is a common way to reduce false positives.

  2. 2

    A company has applied a sensitivity label to a Microsoft Teams team. What is the effect of this label on the connected SharePoint site? Select ALL that apply.

    graph TD Team[Microsoft Team] -- Labeled --> A{Label Settings} A -- Inheritance --> Site[Connected SharePoint Site] A -- Inheritance --> Group[M365 Group] subgraph A [Label Settings] Privacy[Privacy: Private] ExtSharing[External Sharing: Controlled] DeviceAccess[Unmanaged Device Access: Blocked] end
    Show answer details

    Correct answer: A, B, D

    Container settings of a sensitivity label (privacy, external sharing from SharePoint sites, and access from unmanaged devices through Microsoft Entra Conditional Access / SharePoint app-enforced restrictions) are enforced on the team's Microsoft 365 group and its connected SharePoint site. Items in the container don't inherit the label, so documents in the site's libraries aren't labeled by it. Source: Microsoft Learn, 'Use sensitivity labels to protect content in Microsoft Teams, Microsoft 365 Groups, and SharePoint sites'.

    Container settings of a sensitivity label (privacy, external sharing from SharePoint sites, and access from unmanaged devices through Microsoft Entra Conditional Access / SharePoint app-enforced restrictions) are enforced on the team's Microsoft 365 group and its connected SharePoint site. Items in the container don't inherit the label, so documents in the site's libraries aren't labeled by it. Source: Microsoft Learn, 'Use sensitivity labels to protect content in Microsoft Teams, Microsoft 365 Groups, and SharePoint sites'.

    Container settings of a sensitivity label (privacy, external sharing from SharePoint sites, and access from unmanaged devices through Microsoft Entra Conditional Access / SharePoint app-enforced restrictions) are enforced on the team's Microsoft 365 group and its connected SharePoint site. Items in the container don't inherit the label, so documents in the site's libraries aren't labeled by it. Source: Microsoft Learn, 'Use sensitivity labels to protect content in Microsoft Teams, Microsoft 365 Groups, and SharePoint sites'.

  3. 3

    True or False: Exact Data Match (EDM) works by uploading the actual sensitive data to the Microsoft cloud, where it is used for pattern matching in DLP policies.

    Show answer details

    Correct answer: B

    This statement is false. EDM is designed for security and privacy. You do not upload the raw sensitive data. Instead, the data is hashed using a salted hash algorithm on-premises before the hash values are uploaded to Microsoft 365. The service then compares hashes of content against the uploaded hashes, ensuring the actual sensitive data never leaves the customer's environment.

  4. 4

    A compliance admin needs to investigate an incident by finding all emails sent by a specific user that contain the phrase 'Project Titan' and have an attachment. Which Microsoft Purview tool is best suited for this task?

    Show answer details

    Correct answer: B

    Content search is the primary tool for finding content in place across Microsoft 365 locations such as Exchange mailboxes, SharePoint sites and Teams. It supports Keyword Query Language (KQL) queries that combine conditions such as the sender (from:), keywords ("Project Titan") and properties (hasattachment:true). Activity explorer and Audit log search return records of activities (who did what and when), not the content itself. Content explorer lists items by sensitive information type or label, not by sender or keyword. Source: learn.microsoft.com/purview/ediscovery-content-search.

  5. 5

    An administrator is configuring a sensitivity label policy. They want the 'Confidential' label to be the default label for all new documents and emails, but they also want to require users to provide a justification if they remove the label or choose a lower classification label. Which TWO settings should be configured in the label policy? (Select TWO)

    Show answer details

    Correct answer: A, E

    Label policy settings map directly to these requirements: 'Apply this default label to documents' / 'Apply this default label to emails' sets 'Confidential' on new unlabeled content, and the setting that requires users to provide a justification to remove a label or lower its classification prompts users when they downgrade or remove the label. 'Require users to apply a label' (mandatory labeling) is a different setting, auto-labeling isn't configured in the label policy, and choosing users/groups only scopes the policy. Source: Microsoft Learn, 'Learn about sensitivity labels' (What label policies can do).

    Label policy settings map directly to these requirements: 'Apply this default label to documents' / 'Apply this default label to emails' sets 'Confidential' on new unlabeled content, and the setting that requires users to provide a justification to remove a label or lower its classification prompts users when they downgrade or remove the label. 'Require users to apply a label' (mandatory labeling) is a different setting, auto-labeling isn't configured in the label policy, and choosing users/groups only scopes the policy. Source: Microsoft Learn, 'Learn about sensitivity labels' (What label policies can do).

  6. 6

    A pharmaceutical research company, BioGen Innovations, has implemented Microsoft Purview Insider Risk Management. They are concerned about potential data theft of clinical trial results. An analyst needs to capture video clips of on-screen activity on endpoints when approved high-risk users perform specific risky activities, such as copying files to USB devices. Which setting must be enabled to achieve this?

    Show answer details

    Correct answer: A

    Forensic evidence is the opt-in Insider Risk Management feature that captures video clips of user on-screen activity on devices. Captures happen either for specific activities (when a triggering event brings an approved user into scope and a policy indicator is detected) or for all activities. Users must be requested and approved (dual authorization), and devices must be onboarded to Microsoft Purview with the Microsoft Purview Client installed. Microsoft Defender for Endpoint integration is not required. Policy indicators and device indicators only define what's scored; they don't capture clips. Source: Microsoft Learn 'Learn about Insider Risk Management forensic evidence'.

  7. 7

    A global logistics firm, TransGlobal Freight, uses Microsoft 365 E5. It plans to deploy an Endpoint DLP policy that blocks printing of documents containing SWIFT codes on Windows 11 devices. What is required for the policy to be enforced on a user's device?

    Show answer details

    Correct answer: D

    Endpoint DLP (and insider risk management) require Windows 10/11 devices to be onboarded so they can send monitoring data and enforce policies. You can onboard them directly in the Microsoft Purview portal (Settings > Device onboarding), or they're already onboarded if they're in Microsoft Defender for Endpoint. The Information Protection client isn't required. Advanced classification is optional (it adds cloud-based classification), and a policy in simulation mode doesn't enforce blocks. Source: Microsoft Learn - Onboard Windows devices into Microsoft 365 overview.

  8. 8

    An engineering firm uses a custom trainable classifier named 'Project Blueprints' to identify proprietary design documents. To improve accuracy, the administrator needs to provide feedback on items the classifier has identified. Where in the Microsoft Purview portal would the administrator perform this action?

    Show answer details

    Correct answer: B

    Match/Not a match feedback for a trainable classifier's matched items is given in the Microsoft Purview portal from the classifier's matched-items view (Data classification > Classifiers > Trainable classifiers, select the classifier). The same feedback is also available in Content explorer and Data explorer, but that isn't one of the listed choices. Activity explorer shows labeling and DLP activity, and the auto-labeling page manages auto-labeling policies. Note that published custom classifiers can't be retrained; feedback helps tune accuracy. Source: Microsoft Learn, 'Increase classifier accuracy'.

  9. 9

    A healthcare organization, HealthMetric Solutions, needs to protect patient data used by its data science team with Microsoft Copilot. They want to prevent Copilot from accessing and processing any documents containing Electronic Health Records (EHR). Which TWO actions should be implemented to achieve this goal? (Select TWO)

    Show answer details

    Correct answer: C, E

    Microsoft 365 Copilot honors sensitivity label encryption through the EXTRACT (Copy) usage right. If a label applies encryption that grants users VIEW but not EXTRACT, Copilot won't summarize or return the content. An auto-labeling policy that detects EHR data applies that label reliably across existing and new documents. A DLP policy that only blocks sharing doesn't restrict Copilot. The Copilot-specific control is a DLP policy scoped to the 'Microsoft 365 Copilot and Copilot Chat' location with a sensitivity-label condition. Information barriers and retention policies don't control Copilot processing. Sources: learn.microsoft.com/purview/ai-m365-copilot-considerations and dlp-microsoft365-copilot-location-learn-about.

    Microsoft 365 Copilot honors sensitivity label encryption through the EXTRACT (Copy) usage right. If a label applies encryption that grants users VIEW but not EXTRACT, Copilot won't summarize or return the content. An auto-labeling policy that detects EHR data applies that label reliably across existing and new documents. A DLP policy that only blocks sharing doesn't restrict Copilot. The Copilot-specific control is a DLP policy scoped to the 'Microsoft 365 Copilot and Copilot Chat' location with a sensitivity-label condition. Information barriers and retention policies don't control Copilot processing. Sources: learn.microsoft.com/purview/ai-m365-copilot-considerations and dlp-microsoft365-copilot-location-learn-about.

  10. 10

    True or False: When configuring a retention policy in Microsoft Purview, the principle of preservation always ensures that if a user deletes a file from a SharePoint site included in the policy, a copy is retained in the Preservation Hold Library, regardless of the policy's action.

    Show answer details

    Correct answer: B

    False. Whether a copy is kept in the Preservation Hold library depends on the retention settings. With retain-only or retain-and-delete settings, a file that's deleted during the retention period is copied to the Preservation Hold library. With delete-only settings nothing is preserved: the deleted document goes to the first-stage Recycle Bin, then the second-stage Recycle Bin, and is permanently deleted after 93 days. Source: Microsoft Learn, 'Learn about retention for SharePoint and OneDrive' (content paths for retain-only and delete-only settings).

Create an account to continue.