Microsoft · SC-401
Plan and implement information security of sensitive data using Microsoft Purview and related services. Covers information protection, data loss prevention, retention, and managing risks and alerts.
Practice Questions
939
≈ 18 practice exams
Duration
100 minutes
Passing Score
700/1000
Difficulty
AssociateLast Updated
Jan 2026
Use this SC-401 practice exam to prepare for Administering Information Security in Microsoft 365 (SC-401) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 939 questions for Microsoft SC-401, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The SC-401 exam, Administering Information Security in Microsoft 365, validates a candidate's ability to plan and implement information security for sensitive data using Microsoft Purview and related Microsoft services. The exam covers a broad set of data security disciplines including information protection, data loss prevention (DLP), data lifecycle retention, and insider risk management—all within the Microsoft 365 ecosystem. It also addresses the increasingly critical domain of protecting data used by AI services, reflecting Microsoft's focus on securing AI-driven workloads through tools like Data Security Posture Management (DSPM) for AI.
Passing SC-401 earns the Microsoft Certified: Information Security Administrator Associate certification, which replaced the retired SC-400 (Information Protection and Compliance Administrator) certification as of May 31, 2025. The exam encompasses deep technical skills across Microsoft Purview's sensitivity labels, exact data match classifiers, trainable classifiers, endpoint DLP, adaptive scopes, insider risk policies, and audit capabilities—as well as integration points with Microsoft Defender for Cloud Apps, Microsoft Defender XDR, and Microsoft Entra. Candidates must demonstrate proficiency not only in configuring these tools but also in interpreting policy precedence, managing alerts and cases, and responding to security incidents.
This certification is designed for information security administrators and compliance professionals who work primarily within Microsoft 365 environments. Ideal candidates hold roles such as Information Security Administrator, Compliance Specialist, Security Analyst, Microsoft 365 Security Engineer, or Governance and Risk Consultant. These professionals are responsible for designing and enforcing data protection policies, responding to DLP and insider risk alerts, and collaborating with workload administrators, business application owners, and governance stakeholders to implement organization-wide security controls.
The certification is particularly well-suited for mid-career professionals who already have hands-on experience with Microsoft 365 services and are looking to formalize and advance their expertise in the data security and compliance space. It also serves as a stepping stone toward the expert-level Microsoft Certified: Cybersecurity Architect Expert credential.
Microsoft does not enforce formal prerequisites for SC-401, but strong familiarity with the Microsoft 365 platform is essential for success. Candidates should have working knowledge of Microsoft Purview services (including sensitivity labels, DLP policies, retention policies, and insider risk management), Microsoft Entra (formerly Azure AD), the Microsoft Defender portal, and Microsoft Defender for Cloud Apps. Comfort with PowerShell for administrative scripting is also expected, as some exam topics involve command-line management of Purview components.
In terms of experience, Microsoft recommends that candidates have practical, hands-on experience administering information security within a Microsoft 365 tenant. Familiarity with data governance concepts such as data classification, information barriers, records management, and regulatory compliance frameworks will provide important context. Candidates who previously held the SC-400 certification (now retired) will find much of the foundational content familiar, though SC-401 expands coverage into AI data security and updated Purview features.
SC-401 is a proctored exam administered through Pearson VUE and can be taken online or at a testing center. Candidates are given 100 minutes to complete the assessment. The exam contains approximately 65 questions, including a case study with approximately 4 questions and a set of yes/no (binary choice) questions. No performance-based lab (PBT) questions are included. Question types typically include multiple choice, multiple select, drag-and-drop scenario questions, and case study-based items.
The exam is scored on a scale of 1–1000, and a passing score of 700 is required. Scores are reported immediately upon completion. Candidates who fail may retake the exam after 24 hours; subsequent retakes have a variable waiting period per Microsoft's retake policy. The exam is available in English, Portuguese (Brazil), French, German, Japanese, Chinese (Simplified), and Spanish. Non-English speakers may request an additional 30 minutes if taking the exam in a non-native language.
Earning the Microsoft Certified: Information Security Administrator Associate through SC-401 positions professionals for high-demand roles at the intersection of cybersecurity, compliance, and data governance. Certified individuals typically qualify for titles such as Information Security Administrator, Compliance Specialist, Security Analyst, Microsoft 365 Security Engineer, and Governance and Risk Consultant. According to industry salary data for 2025, certified information security administrators in Microsoft environments can expect annual compensation ranging from approximately $90,000 to $120,000 depending on experience, geography, and organization size—with senior and consulting roles commanding higher figures.
The certification carries strong market recognition because it validates expertise in Microsoft Purview, one of the most widely deployed enterprise compliance platforms globally. It directly replaces the retired SC-400 certification, meaning organizations that previously required SC-400 are now looking for SC-401 holders. The credential also integrates well into broader Microsoft security career paths: it builds on the SC-900 foundations and aligns with the SC-100 (Cybersecurity Architect Expert) expert-level certification for those pursuing advanced roles. Microsoft certifications renew annually via a free online assessment on Microsoft Learn, keeping the credential current without requiring a full re-examination.
5 sample questions with answers and explanations. The full bank has 939 questions, enough for 18 full-length practice exams.
Preview — answers shown1. Fabrikam Legal Department has confidential contract templates that are reused across the organization. These templates contain sensitive information like party names, contract values, and signature blocks. The department needs to automatically detect and restrict sharing of documents matching this template structure. Which solution best addresses this requirement?
Explanation
Document fingerprinting is the optimal solution because it analyzes the template structure, headings, and layout patterns to create a sensitive information type that detects when similar documents are shared. This approach is specifically designed for reusable templates containing sensitive information. Custom sensitive information types with keywords would require manually defining each field and lack the structural pattern recognition that fingerprinting provides. EDM classifiers require exact data matching against known values rather than template structure detection. Trainable classifiers, while capable of document classification, require more time and resources and are better suited for categorizing document types rather than detecting specific template instances.
2. Solution: Contoso implements Activity Explorer with filters configured for label changes, DLP matches, and endpoint file actions. They create custom filter sets combining date range, user, and activity type. Does this solution meet the goal of identifying which users violated DLP policies and when violations occurred?
Explanation
Activity Explorer is specifically designed to track DLP policy matches and violations with detailed filtering by user, activity type, date, and location. Custom filter sets can combine multiple criteria to show exactly which users triggered DLP rules and when. The predefined DLP detection filter set makes this analysis straightforward and comprehensive.
3. Fabrikam's compliance team is creating multiple custom sensitive information types (SITs) in Microsoft Purview. For SIT1, they need to copy and modify an existing built-in SIT to use as a template while maintaining compliance with their data classification standards. Which SIT category should they select to enable copying and modification of existing SITs?
Explanation
Only the Built-in category permits copying and modifying existing SITs to use as templates for custom configurations. The Named Entity categories (both bundled and unbundled) are designed for pattern-based detection and cannot be modified or copied. Exact Data Match (EDM) uses fingerprint-based matching against reference data and also does not support copying or modification. Built-in SITs provide the flexibility needed for customization while maintaining the integrity of the classification framework.
4. Fabrikam's IT administrator has enabled Advanced Classification Scanning in Endpoint DLP settings. What is the primary benefit of this configuration?
Explanation
Advanced Classification Scanning sends data classification results back to the local device, enabling faster and more responsive policy enforcement with better user experience. This configuration improves performance by processing classification locally rather than waiting for cloud evaluation. Blocking network shares is controlled through separate DLP rules and actions. Automatic encryption is a separate DLP action that can be configured independently. Multi-factor authentication is an identity and access management control, not a classification scanning feature.
5. Fabrikam has deployed the Microsoft Purview Information Protection scanner to protect sensitive data in on-premises file shares and SharePoint Server 2019. The organization needs to automatically apply confidentiality labels to employee records containing social security numbers. The scanner infrastructure is in place with proper permissions and SQL Server configured. What is the primary requirement that must be met for the scanner to successfully apply labels to matching files?
Explanation
The scanner requires a sensitivity label with defined matching criteria and enforcement enabled in the scan job settings to automatically apply labels. The label must contain conditions that identify the sensitive information type being sought. Custom SharePoint search service configuration is not required as the scanner uses Windows IFilters for file inspection. Version control and metadata tagging are optional settings that support the scanner but are not prerequisites for labeling. Detection mode is a best practice for validation but not a mandatory prerequisite for enforcement.
Microsoft 365 Certified: Administrator Expert (MS-102)
MS-102 · 965 questions
Microsoft 365 Certified: Copilot and Agent Administration Fundamentals (AB-900)
AB-900 · 700 questions
Microsoft 365 Certified: Fundamentals (MS-900)
MS-900 · 1201 questions
Administering Windows Server Hybrid Core Infrastructure (AZ-800)
AZ-800 · 898 questions
Microsoft Certified: Agentic AI Business Solutions Architect (AB-100)
AB-100 · 700 questions
Microsoft Certified: Azure Administrator Associate (AZ-104)
AZ-104 · 757 questions
$17.99
One-time access to this exam