SC-400 Sample Questions & Answers
Sensitivity labels, trainable classifiers and sensitive info types carry the most weight, alongside Endpoint DLP monitoring and DLP policy creation, insider and privacy risk management, records management through retention labels, and Purview investigation tools.
Launch the full SC-400 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Manage insider and privacy risk in Microsoft 365 · Implement and manage Microsoft Purview Information Barriers (IBs)
A multinational corporation uses Microsoft Teams for collaboration between its Research and Development (R&D) and Sales departments. To prevent conflicts of interest and protect sensitive intellectual property, the company needs to prevent users in the R&D department from communicating via chat or calls with users in the Sales department. However, both departments must be able to communicate with the Legal department. Which Microsoft Purview solution should be implemented to enforce this communication boundary?
Show answer & explanation
Correct answer: C
Information Barriers (IB) are specifically designed to prevent individuals or groups from communicating with each other in Microsoft Teams, SharePoint, and OneDrive. You would define segments for R&D, Sales, and Legal, and then create IB policies to block communication between R&D and Sales while allowing both to communicate with Legal. Communication Compliance is for monitoring communications for inappropriate content, and DLP is for preventing data exfiltration.
- Question 2Intermediate
Implement information protection · Create and manage sensitive info types
A consultant is tasked with creating a custom sensitive information type (SIT) to detect a new, internally developed project code format:
PROJ-followed by two uppercase letters and four digits (e.g.,PROJ-AB1234). The consultant needs to define a regular expression that has a high confidence level and minimizes false positives. Which of the following regular expressions is the most accurate and efficient for this requirement?Show answer & explanation
Correct answer: B
This is the most precise regex.
\bdenotes a word boundary, preventing partial matches within longer strings (e.g., 'OLDPROJ-AB12345').PROJ-is a literal match.[A-Z]{2}specifically matches exactly two uppercase letters.[0-9]{4}(or\d{4}) specifically matches exactly four digits. This combination accurately reflects the required format while minimizing false positives. - Question 3Intermediate
Monitor and investigate data and activities by using Microsoft Purview · Plan and manage eDiscovery and Content search
An eDiscovery manager for a global enterprise is preparing for litigation. The case involves custodians located in both Germany and the United States. Due to data residency regulations, data for German custodians must be processed and stored within the European Union. The manager needs to create a single eDiscovery (Premium) case to manage the litigation efficiently while respecting these regional data boundaries. What feature within Microsoft Purview eDiscovery (Premium) must be configured when creating the case to meet this requirement?
Show answer & explanation
Correct answer: D
When creating an eDiscovery (Premium) case, there is a setting to specify the region where case data will be stored and processed. By selecting a region in the European Union for this case, the manager ensures that when data from German custodians is collected and processed, it will remain within the specified EU data boundary, thus complying with data residency regulations.
- Question 4Beginner
Implement information protection · Create and manage trainable classifiers
A university is using trainable classifiers to identify student admission forms. After initial training with 250 positive examples, the classifier is performing with low accuracy, frequently misclassifying research papers as admission forms. A compliance administrator has collected an additional 50 admission forms and 200 research papers. What is the correct next step to improve the classifier's performance?
Show answer & explanation
Correct answer: C
The most effective way to improve a trainable classifier is to provide it with feedback on its mistakes. By identifying the items it got wrong (the research papers) and explicitly telling it 'Not a match', you help the model learn the difference between positive and negative examples. This retraining process is more efficient than starting over and directly addresses the source of the inaccuracy.
- Question 5Advanced
Implement information protection · Implement and manage sensitivity labels
Case Study:
Contoso, Ltd. is a global consulting firm with a new Chief Compliance Officer (CCO) who has mandated a complete overhaul of the company's data governance strategy using Microsoft Purview. The primary goal is to automatically classify and protect sensitive client data without impeding employee productivity.
Existing Environment:
Contoso uses Microsoft 365 E5 licenses. All employees store documents in SharePoint Online and OneDrive for Business and use Exchange Online for email. A basic sensitivity label structure (Public, Internal, Confidential) exists but is applied manually and inconsistently.Key Requirements:
- Project Proposals: Documents containing the keyword "Project Proposal" and a custom sensitive info type for "Client ID" must be automatically labeled as 'Confidential - Client'. This label must encrypt the document and apply a 'Contoso Confidential' watermark.
- Financial Reports: Excel workbooks containing more than 10 credit card numbers must be automatically labeled as 'Highly Confidential - Finance'. This label must encrypt the document and restrict access to members of the 'Finance_Team' security group.
- User Experience: When a label is automatically applied, users should be notified via a policy tip in Office apps. Users must not be allowed to downgrade the classification from 'Highly Confidential - Finance' to 'Confidential - Client' without providing a business justification.
- Deployment: The CCO wants to test the accuracy of the auto-labeling logic for one month before any labels are actually applied to documents.
Which single Microsoft Purview configuration should the administrator create to meet all these requirements?
Show answer & explanation
Correct answer: B
This solution correctly addresses all requirements. A single auto-labeling policy can contain multiple rules for different conditions. Running it in simulation mode meets the testing requirement. The two new sensitivity labels can be configured with the specific encryption, watermarking, and access restrictions. The requirement to provide justification for lowering classification is a setting within the sensitivity label policy that publishes the labels, not the auto-labeling policy itself, but this option correctly identifies that the auto-labeling policy and the label policy work together. This is the most comprehensive and accurate approach.
- Question 6Intermediate
Implement information protection · Create and manage sensitive info types
A global logistics company, Fabrikam Shipping, is using Exact Data Match (EDM) to protect a database of over 1 million customer tracking numbers. The database is updated twice daily. The compliance team has identified a need to add a new 'Carrier Code' column to the EDM schema. The goal is to update the EDM schema and data with zero downtime for the DLP policies that rely on it. What is the correct sequence of actions?
Show answer & explanation
Correct answer: C
The correct procedure for updating an EDM schema without causing downtime is to download the existing schema, modify it by adding the new fields, and then upload it. This creates a new version of the schema while the old one remains active. Once the new schema is in place, you can upload the data that conforms to the new structure. Deleting the schema would cause an outage for dependent policies. The upload agent cannot automatically update the schema; it only uploads data that conforms to the existing schema. Modifying the schema in place is not a supported operation; a new version must be created by uploading the modified XML file.
- Question 7Intermediate
Implement information protection · Implement and manage sensitivity labels
A financial consulting firm needs to automatically apply a 'Confidential - Finance' sensitivity label to documents in a specific SharePoint Online site named 'Quarterly Audits'. This label must be applied at the service level to all new and modified documents containing credit card numbers. In contrast, for user endpoints, the firm wants to recommend this same label to users when they work on documents with credit card numbers in Word or Excel, but allow them to accept or dismiss the recommendation. Which combination of policies achieves this?
Show answer & explanation
Correct answer: A
This scenario requires two distinct behaviors: mandatory automatic labeling in SharePoint (service-side) and recommended labeling in Office apps (client-side). A single auto-labeling policy can be configured with different rules or settings for different locations. The policy can be set to 'Automatically apply the label' for the 'Quarterly Audits' SharePoint site, and the label itself can be configured to 'Recommend that users apply this label' within its settings for Office applications. This combination provides the required granular control. Using two separate policies could create complexity and potential conflicts. A DLP policy can apply a label, but it's primarily for preventing data loss, and auto-labeling policies are the direct tool for this classification task. Configuring the label only for recommendation would fail the SharePoint requirement.
- Question 8AdvancedSelect 3
Implement information protection · Design and implement encryption for email messages
A law firm, Trey Research, needs to implement a highly secure email communication solution for a sensitive merger and acquisition case. They must ensure that emails sent to the external counsel can be revoked at any time and automatically expire after 15 days. Additionally, the firm wants to use a custom branding template for these emails that includes the case name. Which THREE of the following components must be configured to meet all requirements? (Select THREE)
Show answer & explanation
Correct answers: B, C, D
A mail flow rule is required to trigger the encryption process automatically for emails sent to the external counsel's domain.
Features like message revocation, expiration, and custom branding are part of Advanced Message Encryption, which requires specific licensing (e.g., Microsoft 365 E5 or an add-on).
Custom branding templates for Office 365 Message Encryption (OME), which include settings for expiration, are created and managed via PowerShell using cmdlets like New-OMEConfiguration and Set-OMEConfiguration.
- Question 9Beginner
Implement information protection · Create and manage sensitive info types
A government agency processes standardized application forms that are submitted as PDF files. While the content inside the forms varies for each applicant, the layout, boilerplate text, and graphical elements are always identical. The agency wants to create a Data Loss Prevention (DLP) policy to prevent these specific forms from being emailed outside the agency network, regardless of the applicant data they contain. Which method is most suitable for accurately identifying these forms?
Show answer & explanation
Correct answer: D
Document fingerprinting is designed for this exact use case. It converts a standard form or template into a sensitive information type. The system then detects any documents that match this fingerprint, even if they have been filled out with different information. Trainable classifiers are better for identifying content based on what it is (e.g., a resume, a contract) rather than its exact layout. EDM is used for matching specific values from a database. A keyword dictionary would be unreliable as the keywords might appear in other, non-sensitive documents.
- Question 10Intermediate
Implement DLP · Implement and monitor Endpoint DLP
A hospital has deployed Endpoint DLP policies to prevent patient records from being copied to personal USB drives. The policy is configured to block 'Copy to removable USB device' for any content with the 'Patient Health Information' sensitivity label. A doctor reports that they are blocked from copying files to their hospital-issued, encrypted USB drive, which should be allowed. A security analyst confirms the doctor is in the correct user group and the USB drive is on the approved hardware list. What is the most likely cause of the issue?
flowchart TD A[User attempts to copy file] --> B{File has 'Patient Health Info' label?}; B -->|Yes| C{Is destination a USB drive?}; B -->|No| D[Allow Copy]; C -->|Yes| E{Is USB drive in 'Approved Devices' group?}; C -->|No| F[Allow Copy to non-USB]; E -->|Yes| G[Allow Copy]; E -->|No| H[Block Copy - Current Behavior];Show answer & explanation
Correct answer: B
Endpoint DLP policies operate on a principle of least privilege. A common misconfiguration is setting a general 'Block' action for copying to USB drives without creating a specific, higher-priority rule that explicitly 'Allows' the action for a defined group of approved devices. Simply listing a device as 'approved' in the settings is not sufficient; a policy rule must be configured to leverage that group and permit the copy action. If the only rule is a broad 'Block', it will apply to all USB devices, including the approved ones. The diagram illustrates that the logic is failing at the step checking if the device is in the approved group, leading to the 'Block' action.
Ready for the real thing?
The full SC-400 simulator has every exam-style question, timed mode, and instant scoring.