Microsoft · SC-401
Microsoft Purview information security practice across protection, DLP, retention, insider risk, alerts, investigations, and AI data security.
Practice Questions
939
≈ 18 practice exams
Duration
100 minutes
Passing Score
700/1000
Difficulty
AssociateLast Updated
Oct 2026
SC-401 is the exam for Microsoft's Information Security Administrator Associate credential. The current published study guide divides the outline evenly across information protection, data loss prevention and retention, and risks, alerts, and activities, each at 30-35%. The role centres on Microsoft Purview and related Microsoft 365 security services.
The proctored exam allows 100 minutes and requires a scaled score of 700 or greater. Microsoft does not publish a fixed question count, and 700 should not be interpreted as exactly 70% correct. The certification page says the English exam will be updated in October 2026, so candidates should recheck the dated study guide before their appointment.
Use these 939 questions to practise policy design and investigation choices across sensitive information types, labels, encryption, Endpoint DLP, retention, insider risk, Audit, eDiscovery, Defender integrations, and protection for AI workloads. Validate configuration details in Microsoft Learn because Purview portals and feature names change frequently.
SC-401 is the required exam for Microsoft Certified: Information Security Administrator Associate. It focuses on protecting sensitive information with Microsoft Purview and related Microsoft 365 services, implementing DLP and retention, managing insider risk and alerts, investigating activity, and protecting data used by AI services.
The target candidate plans and implements information security controls with governance, data, workload, and security stakeholders. Microsoft expects familiarity with Microsoft 365 services, PowerShell, Microsoft Entra, the Microsoft Defender portal, and Microsoft Defender for Cloud Apps.
Microsoft publishes no prerequisite certification. Practical access to Microsoft Purview and related Microsoft 365 security features is important because the outline tests policy behaviour, investigation workflows, roles, alerts, and cross-service integrations.
The proctored exam allows 100 minutes, may include interactive components, and requires a scaled score of 700. Microsoft does not publish a fixed question count, and pricing varies by proctoring country or region. The certification renews annually through a free online Microsoft Learn assessment during the renewal window.
SC-401 validates practical Microsoft 365 information protection and governance skills for information security, compliance, data-protection, and Microsoft 365 administration roles. Its value is strongest when paired with hands-on Purview policy design and investigation experience.
5 sample questions with answers and explanations. The full bank has 939 questions, enough for 18 full-length practice exams.
Preview — answers shown1. Litware has created a DLP policy named DLP1 and needs to ensure it functions as an endpoint DLP policy. To which location should you apply DLP1 to achieve this?
Explanation
Endpoint DLP policies must be applied to Devices to monitor and protect data on onboarded Windows 10, Windows 11, and macOS devices. Applying the policy to devices enables monitoring of local file activities, USB transfers, clipboard operations, and other endpoint-specific data movement scenarios. Exchange email applies policies to email messages and mailboxes. OneDrive accounts targets cloud storage protection. On-premises repositories applies to file shares and on-premises SharePoint servers. Only applying to Devices creates a true endpoint DLP policy.
2. Solution: You configure trainable classifiers using 45 sample files from a single SharePoint site to identify confidential project documents. Does this solution meet the goal of creating an effective trainable classifier?
Explanation
No, this solution does not meet the goal. Trainable classifiers require a minimum of 50 files per site, and you only provided 45 files. This falls below the required threshold, so the classifier cannot be properly trained. The requirement is between 50 and 500 files per site. While you're close to the minimum, Microsoft's system will not process samples below this threshold.
3. Solution: Greenfield Healthcare implements Microsoft Purview Audit (Standard) for their compliance team and configures it to maintain audit logs for 5 years to meet their regulatory requirements. Does this solution meet their compliance goal?
Explanation
No, this solution does not meet the goal because Audit (Standard) only supports the default 180-day retention period and cannot be configured for extended retention. To maintain logs for 5 years, the organization must upgrade to Audit (Premium) with the appropriate licensing, which allows configurable retention policies up to 10 years. Audit (Standard) lacks the retention policy configuration capabilities needed for this requirement.
4. Solution: Litware configures Communication Compliance to detect riskant language in Copilot prompts and automatically blocks all flagged prompts from reaching Copilot. Does this solution meet the goal of detecting and reviewing riskant Copilot usage?
Explanation
Communication Compliance is designed to detect and flag risky content for human review by compliance officers, not to automatically block prompts before they reach Copilot. The blocking functionality is not part of Communication Compliance's capabilities. While Communication Compliance can identify riskant language in prompts and responses, it presents these to reviewers on the Pending tab for investigation and action. The automatic blocking action described in the solution is not what Communication Compliance provides. To prevent prompts from reaching Copilot, organizations would need to use DLP policies instead.
5. Solution: A company creates a custom sensitive information type with a credit card number as the primary element and sets confidence level to low. Does this solution meet the goal of reliably detecting credit card leaks while minimizing false positives?
Explanation
Setting confidence level to low will create excessive false positives because low confidence means the system will flag items with minimal supporting evidence. To reliably detect credit card leaks while minimizing false positives, you should set medium or high confidence levels. High confidence requires supporting elements like expiration dates or CVV codes to be detected alongside the credit card number, which significantly reduces false positives while maintaining detection accuracy. Low confidence would flag any string that resembles a credit card number, leading to alert fatigue and reduced effectiveness.
It covers information protection, data loss prevention and retention, and management of risks, alerts, and activities using Microsoft Purview and related services.
Microsoft's published study guide assigns 30-35% to each of the three high-level skill areas.
Microsoft allows 100 minutes and notes that the proctored exam may include interactive components.
A scaled score of 700 or greater passes. That is not the same as a guaranteed 70% raw score.
Microsoft does not publish a fixed question count, and the number can vary by exam form.
The role-based certification expires annually, but Microsoft offers a free online renewal assessment during the renewal window.
Microsoft 365 Certified: Administrator Expert (MS-102)
MS-102 · 965 questions
Microsoft 365 Certified: Copilot and Agent Administration Fundamentals (AB-900)
AB-900 · 700 questions
Microsoft 365 Certified: Fundamentals (MS-900)
MS-900 · 1201 questions
Administering Windows Server Hybrid Core Infrastructure (AZ-800)
AZ-800 · 898 questions
Microsoft Certified: Agentic AI Business Solutions Architect (AB-100)
AB-100 · 700 questions
Microsoft Certified: Azure Administrator Associate (AZ-104)
AZ-104 · 757 questions
$17.99
One-time access to this exam