SC-401 Sample Questions & Answers
Three areas tie for the top weight: classifying data and applying sensitivity labels in Purview, data loss prevention and retention policies, and insider risk management alongside protecting data used by AI and managing security alerts.
Launch the full SC-401 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Implement data loss prevention and retention · Implement and manage retention
A law firm, Juris Digital, has a retention label named 'Legal-Case-Final' configured to start a 7-year retention period based on the 'event' of a case being closed. An administrator needs to trigger the retention for all documents related to the 'Case-123' matter. What is the correct sequence of actions?
Show answer & explanation
Correct answer: C
For event-based retention, the process is to first define an 'event type' (e.g., 'Case Closed'). Once the label is associated with this event type, you then create a specific 'event' when a case actually closes. This event uses asset IDs (like a case number or project ID) to correlate with the metadata in the documents. This action triggers the start of the retention period for all documents tagged with that asset ID and the corresponding retention label. Manually applying the label does not trigger the event. The label policy just makes the label available; it doesn't trigger the retention start.
- Question 2Intermediate
Implement information protection · Create and manage custom sensitive info types
A compliance administrator at a bank is creating a custom sensitive info type to detect a 9-character internal transaction ID format, which always starts with 'TX' followed by 7 numbers (e.g., TX1234567). They need to increase the detection confidence by requiring a supporting keyword like 'transaction' or 'payment' within 50 characters of the ID. Which component of the sensitive info type definition should be used for the keyword requirement?
Show answer & explanation
Correct answer: D
In a custom SIT pattern, the primary element defines the main pattern (the TX ID regular expression). Supporting elements are additional evidence, such as a keyword list containing 'transaction' or 'payment', that must appear within the configured character proximity of the primary element to raise confidence. Character proximity is only the distance setting, and 'corroborative evidence' is the XML rule-package term for these same supporting match elements. Source: Microsoft Learn 'Create custom sensitive information types' / 'Learn about sensitive information types'.
- Question 3Intermediate
Implement data loss prevention and retention · Interpret policy and rule precedence in data loss prevention
A company has two DLP policies. Policy A is the most restrictive and applies to Exchange online. Policy B is less restrictive and applies to Exchange online, SharePoint online, and OneDrive accounts. A user sends an email that triggers both policies. Which policy will be enforced?
Show answer & explanation
Correct answer: D
When multiple DLP policies are triggered for the same content in the same location, Microsoft Purview enforces the most restrictive policy. It does not simply aggregate them. The policy with the lowest priority order number (e.g., 0) is processed first, but the final action is determined by the most restrictive outcome among all matching policies. In this case, since Policy A is explicitly the most restrictive, its actions will be enforced on the email.
- Question 4Intermediate
Implement information protection · Apply bulk classification to on-premises data by using the Microsoft Purview Information Protection scanner
A government contractor, AeroDynamics Manufacturing, stores sensitive schematics on an on-premises file share. They need to discover and apply a 'Confidential - ITAR' sensitivity label to all existing files containing specific project codes. The solution must not require migrating the data to the cloud. Which Microsoft Purview tool should be deployed to meet this requirement?
Show answer & explanation
Correct answer: A
The Microsoft Purview Information Protection scanner is designed specifically for discovering, classifying, and protecting files on on-premises data stores like file shares and SharePoint Server. It can be configured to run in discovery mode or enforcement mode to automatically apply sensitivity labels based on content inspection. Defender for Cloud Apps is for cloud services, the MPIP client is for user endpoints, and Endpoint DLP focuses on preventing data loss from managed devices, not bulk classification of file shares.
- Question 5Intermediate
Manage risks, alerts, and activities · Configure audit retention policies
An organization is configuring Microsoft Purview Audit (Premium). They want to retain audit logs for their executive leadership group for 10 years, while all other users' logs are retained for the default 1 year. Which feature allows for this granular retention configuration?
Show answer & explanation
Correct answer: D
Microsoft Purview Audit (Premium) allows the creation of specific audit log retention policies. These policies can be configured to retain logs for specific users, activities, or record types for longer periods (up to 10 years). This is the correct tool for applying different retention durations to different sets of users, such as the executive group. The default policy applies to everyone and cannot be customized in this granular way. eDiscovery holds and retention labels apply to user content, not audit logs.
- Question 6Advanced
Manage risks, alerts, and activities · Protect data used by AI services
Case Study: QuantumLeap Analytics
Company Background:
QuantumLeap Analytics is a data science startup that provides predictive modeling for the financial industry. They handle highly sensitive datasets from their clients, including transaction records, investment portfolios, and proprietary trading algorithms. The company has a Microsoft 365 E5 license and is rapidly growing, with a strong emphasis on leveraging AI and cloud-native tools.Current Environment:
All client data is stored in dedicated SharePoint Online sites, one per client. Data scientists collaborate on projects using Microsoft Teams. A significant portion of their work involves using Microsoft Copilot to analyze code and summarize research papers. The security team is small but skilled, and management is extremely concerned about both accidental data leakage and intentional data theft, especially as employees join and leave the company.Requirements:
- Client datasets must be automatically classified and encrypted upon upload to SharePoint. The encryption key must be managed by QuantumLeap to meet contractual obligations (Double Key Encryption is being considered).
- When a data scientist resigns, an automated process must be initiated to analyze their Microsoft 365 activity for the 90 days prior to their resignation date for any signs of data exfiltration.
- A DLP policy must prevent any content classified with 'Client Data' from being sent via email to external recipients, but allow internal sharing.
- Data security posture for client data used in AI workloads must be continuously monitored for risks like overexposure or data drift.
Problem:
The company recently onboarded a new client, 'Vanguard Investments'. The security team needs to implement the required protections for this new client's data. They are struggling to automate the process for departing employees and are unsure how to monitor the AI workload security.Which Microsoft Purview solution should be implemented to address the requirement for monitoring AI workload security (Requirement 4)?
Show answer & explanation
Correct answer: D
Requirement 4 specifically calls for continuously monitoring the data security posture for data used in AI workloads. This is the exact purpose of Microsoft Purview Data Security Posture Management (DSPM) for AI. DSPM is designed to discover sensitive data, evaluate its security posture, and detect risks like overexposure or drift in AI environments. Defender for Cloud Apps protects cloud apps, Insider Risk Management focuses on user behavior, and Audit is for logging activities, none of which directly address the AI data security posture requirement.
- Question 7Advanced
Manage risks, alerts, and activities · Implement and manage Microsoft Purview Insider Risk Management
Case Study: QuantumLeap Analytics
Company Background:
QuantumLeap Analytics is a data science startup that provides predictive modeling for the financial industry. They handle highly sensitive datasets from their clients, including transaction records, investment portfolios, and proprietary trading algorithms. The company has a Microsoft 365 E5 license and is rapidly growing, with a strong emphasis on leveraging AI and cloud-native tools.Current Environment:
All client data is stored in dedicated SharePoint Online sites, one per client. Data scientists collaborate on projects using Microsoft Teams. A significant portion of their work involves using Microsoft Copilot to analyze code and summarize research papers. The security team is small but skilled, and management is extremely concerned about both accidental data leakage and intentional data theft, especially as employees join and leave the company.Requirements:
- Client datasets must be automatically classified and encrypted upon upload to SharePoint. The encryption key must be managed by QuantumLeap to meet contractual obligations (Double Key Encryption is being considered).
- When a data scientist resigns, an automated process must be initiated to analyze their Microsoft 365 activity for the 90 days prior to their resignation date for any signs of data exfiltration.
- A DLP policy must prevent any content classified with 'Client Data' from being sent via email to external recipients, but allow internal sharing.
- Data security posture for client data used in AI workloads must be continuously monitored for risks like overexposure or data drift.
Problem:
The company recently onboarded a new client, 'Vanguard Investments'. The security team needs to implement the required protections for this new client's data. They are struggling to automate the process for departing employees and are unsure how to monitor the AI workload security.To meet the requirement for departing employees (Requirement 2), what should the administrator configure?
Show answer & explanation
Correct answer: C
Requirement 2 describes a classic use case for Insider Risk Management. The 'Data theft by departing users' policy template is designed for this exact scenario. To automate the process, an HR connector must be configured to feed employee resignation dates into Purview. This event automatically triggers the policy, which then analyzes the user's past activity for risky behaviors. A scheduled Content Search is a manual and less intelligent approach. A DLP policy is for prevention, not retrospective analysis of departing user behavior.
- Question 8Intermediate
Implement data loss prevention and retention · Create, configure, and manage adaptive scopes
A financial services company needs to define an adaptive scope for a retention policy that targets all users in the 'Investment Banking' department who are also located in 'Switzerland'. Which type of properties should be used to create this scope?
Show answer & explanation
Correct answer: D
Adaptive scopes for users are based on user attributes (filterable recipient properties that map to Microsoft Entra attributes) such as Department and Country or region. In the simple query builder you select these attributes; in the advanced query builder you use OPATH, for example (Department -eq 'Investment Banking') -and (CountryOrRegion -eq 'Switzerland'). Site properties and Microsoft 365 Group properties are used for SharePoint site and group scopes, not users. Source: Microsoft Learn - Adaptive scopes.
- Question 9Beginner
Implement data loss prevention and retention · Interpret the results of policy precedence, including using Policy lookup
When using the 'Policy lookup' tool in the Microsoft Purview compliance portal to troubleshoot retention, what information does the tool provide?
Show answer & explanation
Correct answer: C
Policy lookup (in Data lifecycle management or Records management in the Microsoft Purview portal) finds the retention policies and retention label policies that are assigned to a specific user (mailbox), SharePoint site or OneDrive account, or Microsoft 365 group. You must specify the exact email address or URL. It doesn't query individual items, show eDiscovery holds, or calculate which setting wins; you apply the principles of retention to the results. Source: Microsoft Learn - Learn about retention ('Policy lookup').
- Question 10Intermediate
Implement information protection · Design and implement Microsoft Purview Advanced Message Encryption
A company is implementing Microsoft Purview Advanced Message Encryption. They want to provide recipients of encrypted emails with a branded portal that includes the company logo and custom text. Which tool or portal is used to configure this branding?
Show answer & explanation
Correct answer: A
Branding for Microsoft Purview Message Encryption (logo, introductory text, disclaimer, portal text, background color) is configured with the Set-OMEConfiguration cmdlet in Exchange Online PowerShell; with Advanced Message Encryption you can also create additional branding templates with New-OMEConfiguration and apply them with mail flow rules. Microsoft also documents DLP policies as an alternative way to apply branding. It isn't configured in the SharePoint admin center, Entra admin center, or Microsoft 365 admin center. Source: Microsoft Learn, 'Add your organization's brand to your Microsoft Purview Message Encryption encrypted messages'.
Ready for the real thing?
The full SC-401 simulator has every exam-style question, timed mode, and instant scoring.