CertGrid
Microsoft Certification

SC-401: Information Security Administrator Practice Exam

Validates administering information security in Microsoft 365 with Microsoft Purview - information protection and sensitivity labels, DLP and retention, insider risk, alerts and eDiscovery, and protecting data used by AI. The successor to the retired SC-400.

Start with a free SC-401 practice test, then work through 902 exam-style questions with full answer explanations, and take timed mock exams to track your readiness against the exam objectives.

902
Practice pool
40-60 qs
Real exam (typical)
100 min
Real exam time
Intermediate
Level
700 / 1000
Passing score

CertGrid runs a fixed 50-question timed mock, separate from the real exam format above.

Objective-mapped practice, aligned to current exam objectives · Reviewed Aug 2026 · Independent practice platform.

What the SC-401 exam covers

Free SC-401 practice test questions

A sample of 10 questions with answers and explanations. Sign up free to practice all 902.

  1. Question 1Implement information protection

    In Microsoft Purview, what are sensitivity labels used for?

    • ADetecting inappropriate messaging and policy violations in chat and email for compliance review
    • BPreserving mailbox and site content on legal hold so it cannot be altered during active litigation
    • CIndexing tenant content so that eDiscovery searches return relevant matching results quickly
    • DClassifying and protecting content (encryption, watermarking, access) based on sensitivityCorrect
    ✓ Correct answer: D

    Sensitivity labels in Microsoft Purview are the primary mechanism for classifying and protecting content throughout your organization. When a sensitivity label is applied to a document or email, it enforces configured protections including encryption that restricts who can open the file, usage rights that determine edit/copy/print permissions, and visual markings like watermarks or headers. These protections travel with the file even when shared externally, ensuring consistent data security regardless of location.

    Why the other options are wrong
    • ADetecting policy violations in messaging is the job of Communication Compliance, not sensitivity labels, which classify and protect files and email.
    • BPreserving content on hold is an eDiscovery and litigation-hold function, not the classification and protection role sensitivity labels perform.
    • CIndexing content for eDiscovery search is unrelated to sensitivity labels, which apply classification and protection such as encryption and marking.
  2. Question 2Implement information protection

    Which design avoids the performance cost of repeatedly re-encrypting documents as they move between Office apps?

    • AStore the document protection key in a publicly readable network location for all apps
    • BManually re-encrypt the file inside each Office app that opens or edits it
    • CUse a consistent label with persistent encryption so protection travels with the fileCorrect
    • DStrip the encryption off the file on every single save operation performed
    ✓ Correct answer: C

    When users open, edit, and resave encrypted documents in Word/Excel/PowerPoint, re-encrypting on every save operation incurs overhead. Instead, use a sensitivity label with persistent encryption built into the label definition. Once applied, the label's encryption is part of the document and persists through edits and saves in Office apps without re-encryption. The RMS protection follows the file, and the label remains applied. This design avoids repeated encryption operations while maintaining end-to-end protection.

    Why the other options are wrong
    • AStoring the key publicly breaks protection entirely and does nothing to avoid re-encryption overhead as files move between apps.
    • BManually re-encrypting in each app is exactly the repeated overhead to avoid; persistent label encryption keeps protection with the file.
    • DStripping encryption on every save removes protection and forces re-encryption, the opposite of persistent label-based encryption.
  3. Question 3Implement data loss prevention and retention

    An adaptive scope based on a user attribute query is not including newly hired employees in the retention policy. What is the most likely cause?

    • AAdaptive scopes are evaluated only once at creation and never refresh their membership afterward, so any employee hired after the scope was first defined is permanently excluded from the retention policy
    • BAdaptive scopes require an administrator to manually upload a CSV file listing each user, so every new hire must be appended to that file and re-imported before they fall within the retention policy scope
    • CAdaptive scopes only support SharePoint sites and Microsoft 365 Groups and cannot target user mailboxes at all, so no individual employees are ever included by a user-attribute query in the policy
    • DAdaptive scope membership is refreshed on a schedule (roughly daily) and depends on the attribute being populated in the directory, so newly created users have not yet been evaluatedCorrect
    ✓ Correct answer: D

    Adaptive scopes select users with an attribute query and recalculate membership on a schedule (approximately daily). A newly hired employee is not included until their directory attributes are populated and the next evaluation cycle runs, which explains why recent hires are missing from the policy.

    Why the other options are wrong
    • AAdaptive scopes are dynamic and re-evaluate on a schedule; they are not static, so the issue is timing and attribute population, not permanence.
    • BAdaptive scopes use attribute queries against the directory, not manual CSV uploads, so no per-user CSV is required.
    • CAdaptive scopes support users, groups, and sites, so a user-attribute query can target mailboxes; the real cause is the scheduled refresh and missing attributes.
  4. Question 4Implement information protection

    A file server that the Microsoft Purview Information Protection scanner protects stores documents that must never be modified by the scanner service account. To honor sensitivity-label protection while scanning, the scanner needs rights that let it read and relabel files it does not own. Which permission model does the scanner use for this?

    • AIt impersonates each individual file owner using delegated Kerberos tickets
    • BThe scanner account is granted the Super User roleCorrect
    • CEach end user must grant the scanner account mailbox delegate rights
    • DThe scanner uses anonymous read access to open protected files
    ✓ Correct answer: B

    To inspect and relabel content that other users have already protected, the scanner's service account is granted the Azure Rights Management Super User role. Super User grants full owner rights to any protected content in the tenant, letting the scanner decrypt, evaluate, and reapply labels. The account also needs read/write NTFS permissions on the repositories it scans.

    Why the other options are wrong
    • AThe scanner does not perform per-user Kerberos impersonation to access protected files.
    • CMailbox delegation applies to Exchange, not to file-share content scanning.
    • DProtected files cannot be read anonymously; Super User rights are required to decrypt them.
  5. Question 5Implement information protection

    Your organization wants automatically classified content to use document fingerprinting so that copies and reformatted versions of a standard contract template are detected. Where in Microsoft Purview is a document fingerprint actually created and consumed?

    • AIt is created as a sensitive information type (SIT) from an uploaded form, then used by DLP or auto-labelingCorrect
    • BIt is created directly on a sensitivity label and applied automatically to every new document
    • CIt is generated by Microsoft Defender for Cloud Apps and then pushed out to managed endpoints as a device configuration profile setting
    • DIt is a Microsoft Purview Information Protection client setting configured per user in the registry
    ✓ Correct answer: A

    In Microsoft Purview, document fingerprinting works by uploading a standard form or template; the service converts the document into a pattern (a fingerprint) and exposes it as a custom sensitive information type (SIT). Once created, that fingerprint-based SIT can be selected as a condition inside Data Loss Prevention policies or auto-labeling policies, allowing the system to match documents that are based on that template even after they are filled in or reformatted. The fingerprint itself is not the classifier action; it is a detection pattern that classification and protection policies consume.

    Why the other options are wrong
    • BFingerprints are not authored on a sensitivity label; labels can reference SITs as conditions but the fingerprint is created and stored as a SIT.
    • CDefender for Cloud Apps and device configuration profiles are unrelated to how fingerprints are created in Purview.
    • DFingerprinting is a cloud Purview SIT capability, not a per-user client registry setting on the endpoint.
  6. Question 6Implement data loss prevention and retention

    Which condition can be used to auto-apply a retention label to content in Microsoft Purview?

    • AMatching a sensitive information type, a keyword query, or a trainable classifier.Correct
    • BThe age of the user account that owns the file, measured from the account creation date.
    • CThe size of the mailbox database in Exchange Online.
    • DThe number of times a document has been printed.
    ✓ Correct answer: A

    An auto-apply retention label policy can target content that matches sensitive information types, that matches a keyword query (KQL), or that matches a trainable classifier. It can also apply to cloud attachments and, for SharePoint, based on metadata. This lets records and retention be applied automatically without relying on users to label content manually.

    Why the other options are wrong
    • BAuto-apply conditions evaluate content, not the age of the owning account.
    • CMailbox database size is not an auto-apply labeling condition.
    • DPrint counts are not a supported auto-apply condition.
  7. Question 7Implement information protectionSelect all that apply

    Which TWO conditions must be true for an auto-labeling policy to apply a sensitivity label that includes encryption to documents at rest in SharePoint Online? (Choose TWO)

    • AThe label's encryption must be configured to assign permissions now (admin-defined), not let users assign permissionsCorrect
    • BSensitivity labels must be enabled for Office files in SharePoint and OneDriveCorrect
    • CEach affected user must individually run a PowerShell consent cmdlet
    • DThe label must be a parent grouping label with at least two sublabels
    ✓ Correct answer: A, B

    Service-side auto-labeling at rest cannot prompt a user, so any label it applies that uses encryption must use admin-defined (assign permissions now) encryption rather than user-defined permissions. Additionally, you must enable sensitivity labels for Office files in SharePoint and OneDrive so that the service can read and label content stored there. With both in place, the auto-labeling policy can label and encrypt matching files automatically.

    Why the other options are wrong
    • CNo per-user PowerShell consent is needed for service-side auto-labeling; it runs in the service across the targeted locations.
    • DThe applied label must be directly applicable; a parent grouping label with sublabels cannot be applied at all, so this is incorrect.
  8. Question 8Implement information protection

    An admin must publish sensitivity labels so they can be applied to Power BI content (datasets, reports, dashboards) and so that protection persists when data is exported to Excel or PowerPoint. What is required?

    • BEnable sensitivity labels for Power BI in the Power BI/Fabric admin settings and ensure the labels are published in a label policy that scopes them to the relevant usersCorrect
    • ANothing extra is required at all, because Power BI automatically inherits every single published Microsoft Purview sensitivity label and applies its protection to any exported data by default
    • CApply a container sensitivity label to the SharePoint site that backs the Power BI workspace so the labels flow down to datasets and reports
    • DConfigure Double Key Encryption on the sensitivity labels so that protection can persist when Power BI content is exported to Excel or PowerPoint
    ✓ Correct answer: B

    To use sensitivity labels in Power BI, an admin must enable the integration in the Power BI/Fabric tenant settings and the labels must be published via a Purview label policy scoped to the relevant users. Once enabled, labels applied to Power BI items can carry protection that persists when supported data is exported to files such as Excel, PowerPoint, and PDF.

    Why the other options are wrong
    • APower BI does not automatically use Purview labels; the Power BI/Fabric admin setting must be enabled and labels must be published to users.
    • CA container label on a SharePoint site does not enable sensitivity labels for Power BI datasets, reports, or dashboards.
    • DDouble Key Encryption is not required for Power BI labeling and does not enable applying labels to Power BI content.
  9. Question 9Implement data loss prevention and retention

    A policy author wants Endpoint DLP to skip monitoring activity for a specific high-churn temp directory used by a build tool, to reduce noise, while keeping all other paths monitored. Which setting accomplishes this, and what is an important caveat?

    • AAdd the directory to file path exclusions in Endpoint DLP settings; excluded paths are not monitored, so sensitive files there are ignored tooCorrect
    • BAdd the directory to the restricted apps list in Endpoint DLP settings; only the build tool's writes to that specific directory are then excluded from all monitoring
    • CAdd the directory to the unallowed apps list in Endpoint DLP settings; the path is then audited but no longer blocked for any activity
    • DAdd the directory as a sensitive service domain exclusion in browser controls; only web browser activity involving the path is affected
    ✓ Correct answer: A

    File path exclusions in Endpoint DLP global settings let you exclude specific folders (with wildcards supported) from monitoring to cut noise. The important caveat is that DLP no longer evaluates activity in those paths at all, so sensitive items placed there would escape detection - exclusions must be scoped narrowly. The other lists govern apps or domains, not path-level monitoring exclusion.

    Why the other options are wrong
    • BThe restricted apps list targets applications, not directories, so it cannot exclude a specific path from monitoring.
    • CThe unallowed apps list governs apps, not paths, and does not turn a directory into an audited-but-unblocked location.
    • DSensitive service domain exclusions apply to web domains in the browser, not to a local file-system directory.
  10. Question 10Manage risks, alerts, and activities

    An investigator's eDiscovery (Premium) collection returned 40,000 items into a review set. To reduce reviewer effort, they want the system to group messages belonging to the same email conversation and flag messages whose content is fully contained in a later message in the thread. Which review set analytics output identifies those fully-contained messages?

    • AEmail threading, which marks messages as inclusive, inclusive minus, or non-inclusiveCorrect
    • BNear-duplicate detection, which groups messages by similarity percentage and can flag a message whose content is fully contained within a later reply in the same conversation thread
    • COptical character recognition (OCR) on attachments, which extracts text from images so the review set can flag any message whose body is fully repeated later in the email thread
    • DThemes clustering by topic, which organizes the review set into topic groups and identifies each message whose full content is already contained within a subsequent thread reply
    ✓ Correct answer: A

    Email threading analyzes conversation structure and labels messages inclusive (contain unique content not in any other), inclusive minus (inclusive but with attachments differing), or non-inclusive (content fully present in a later message). Reviewers can suppress non-inclusive messages to cut volume. Near-duplicate detection groups similar but distinct documents rather than reasoning about thread containment.

    Why the other options are wrong
    • BNear-duplicate detection groups textually similar documents by a similarity score; it does not determine thread inclusiveness, which is email threading's inclusive/inclusive-minus marking.
    • COCR extracts text from images and scanned attachments and has nothing to do with identifying fully contained messages in a conversation thread.
    • DThemes clusters documents by topic for navigation; it does not analyze reply chains to flag messages whose content is fully contained in later messages.

Who this SC-401 practice exam is for

This practice set is for anyone preparing for the SC-401: Information Security Administrator exam at the intermediate level - from first-time candidates building a foundation to experienced Microsoft practitioners doing a final review before test day. If you learn best by working through realistic questions and reading why each answer is right or wrong, it is built for you.

How to use this SC-401 practice exam

  1. Start with the free sample questions above to gauge your current baseline.
  2. Read the full explanation on every question, including why each wrong option is wrong.
  3. Track your weak domains and focus your study where you are losing the most marks.
  4. Once you are scoring consistently well, take a timed, full-length mock exam.
  5. Use your readiness score to decide when you are ready to book the real SC-401 exam.

Related Microsoft resources

SC-401 practice exam FAQ

How many questions are in the SC-401 practice exam on CertGrid?

CertGrid has 902 practice questions for SC-401: Information Security Administrator, covering 3 exam domains. The real SC-401 exam runs 100 min (120 min seat time), typically with 40-60 questions. Microsoft publishes 40-60 questions as a typical range across its exams and states the number varies by exam; it does not publish a count for this one. CertGrid's timed mock is a fixed 50 questions.

What is the passing score for SC-401?

Microsoft grades SC-401 on a scaled score of 1 to 1000 with 700 required to pass; the scaled score is not a straight percentage. CertGrid reports your percent-correct on this mock separately as a readiness indicator. You have about 100 min to complete it. CertGrid tracks your readiness against the exam objectives so you know where to focus.

Are these official SC-401 exam questions?

No. CertGrid is an independent practice platform. We do not provide real or leaked exam questions. Our questions are original and designed to help you practice the concepts, scenarios, and difficulty style of the SC-401: Information Security Administrator exam.

Is there a free SC-401 practice test?

Yes. You can take a free SC-401: Information Security Administrator practice test straight away: a fixed set of 20 practice questions for this exam, retryable as often as you like, with no credit card required. You get readiness scoring and a weak-domain breakdown on those questions. Paid plans unlock the full 902-question bank, timed mock exams and full-bank domain analytics.

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Microsoft. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.