Microsoft SC-401 Practice Exam Questions & Answers
6 Free Questions
· Last reviewed: September 23, 2026
· Prepared & Reviewed by the ValidExamDumps Editorial Team
Exam Facts
Microsoft SC-401 Exam Details
Key details for this exam, checked against the published exam outline
223
Practice Questions (Our Bank)
30 minutes
Exam Duration
700 out of 1000
Passing Score
USD 165
Official Exam Fee
- Exam Code
- SC-401
- Full Name
- Administering Information Security in Microsoft 365
- Issuing Body
- Microsoft
- Question Format (Our Bank)
- Multiple Choice, Hotspot, Drag & Drop, Case Studies
- Delivery
- Online proctored or at a Pearson VUE test centre
- Eligibility
- No formal prerequisites required. Familiarity with Microsoft 365 services, PowerShell, Microsoft Entra, and Microsoft Defender tools is recommended.
- Validity
- 1 year from the date of passing. renewal requires passing a free online assessment on Microsoft Learn
Practice Questions
Free SC-401 Practice Questions
Each question shows the correct answer and an explanation of why it is right
VA
ValidExamDumps Editorial Team
Every question and its answer is checked by our SC-401 exam
preparation team, who also write the explanation shown with each one.
How we research and review these pages
You have a Microsoft 365 subscription that contains two Microsoft SharePoint Online sites named Site1 and Site2. You plan to use policies to meet the following requirements:
* Add a watermark of Confidential to a document if the document contains the words Project1 or Project2.
* Retain a document for seven years if the document contains credit card information.
* Add a watermark of Internal Use Only to all the documents stored on Site2.
* Add a watermark of Confidential to all the documents stored on Site1.
You need to recommend the minimum number of sensitive info types required.
How many sensitive info types should you recommend?
Correct Answer:
C
Explanation
Trainable classifiers in Microsoft 365 need sample content to learn from patterns. SharePoint Online sites work well as training sources because they contain substantial amounts of real organizational data. Email folders and OneDrive locations are other valid sources, but SharePoint Online is commonly used. Exchange public folders are not supported for this purpose. The classifier uses the content you provide to understand what documents match your classification needs.
You have a data loss prevention (DIP) policy that applies to the Devices location. The policy protects documents that contain United States passport numbers
Users report that they cannot upload documents to a travel management website because of the pokey.
Vou need to ensure that the users can upload the documents to the travel management website. The solution must prevent the protected content from being uploaded to other locations.
Which Microsoft 365 Endpoint data loss prevention (Endpoint DIP) setting should you configure?
Correct Answer:
A
You have a Microsoft OneDrive folder that contains the files shown in the following table.

In Microsoft Defender for Cloud Apps, you create a file policy to automatically apply a classification. What is the effect of applying the policy?
Correct Answer:
A
You have a Microsoft 365 E5 subscription.
You need to create static retention policies for the following locations:
Teams chats
Exchange email
SharePoint sites
Microsoft 365 Groups
Teams channel messages
What is the minimum number of retention policies required?
Correct Answer:
C
Explanation
In Microsoft Purview Data Lifecycle Management, different Microsoft 365 locations require separate retention policies because they fall under different storage and compliance models.
Teams Chats & Teams Channel Messages (1 Policy) require a separate retention policy because Teams messages are stored differently than Exchange and SharePoint content. One policy can cover both Teams chats and Teams channel messages. Exchange Email (1 Policy) requires its own separate policy since emails are managed differently than Teams or SharePoint content. SharePoint Sites & Microsoft 365 Groups (1 Policy) are both stored in SharePoint Online, so they can be managed under one policy.
You are planning a data loss prevention (DLP) solution that will apply to Windows Client computers.
You need to ensure that when users attempt to copy a file that contains sensitive information to a USB storage device, the following requirements are met:
If the users are members of a group named Group1, the users must be allowed to copy the file, and an event must be recorded in the audit log.
All other users must be blocked from copying the file.
What should you create?
Correct Answer:
B
Explanation
To meet the requirements, you need one DLP policy with two separate DLP rules to handle the different conditions:
1. First DLP Rule (For Group1 Members): If the user is a member of Group1 and attempts to copy a file with sensitive data to a USB storage device. Allow the file copy but log the event in the audit log.
2. Second DLP Rule (For All Other Users): If any user who is NOT in Group1 attempts to copy a file with sensitive data to a USB storage device. Block the file transfer.
You have a Microsoft J65 ES subscription.
You need to create a Microsoft Defender for Cloud Apps policy that will detect data loss prevention (DIP) violations. What should you create?
Correct Answer:
A
Full Access
Get the complete SC-401 question set
- 223 questions covering all exam domains
- Correct answers with explanations, like the free questions above
- PDF and online practice test
- 90 days of free updates
Domain 1: Implement information protection
30% - 35%
This domain covers data classification, sensitivity labels, and information protection across Windows, file shares, and Exchange. You need hands-on experience creating and managing sensitivity labels, configuring protection settings, and applying labels to containers like Teams, Groups, and SharePoint. Practice building custom sensitive info types and implementing the Purview Information Protection client to classify data across on-premises and cloud environments.
Sample questions from this domain above:
Q1Q2Q4Q5
Domain 2: Implement data loss prevention and retention
30% - 35%
Focus on designing and configuring data loss prevention policies, implementing Endpoint DLP, and managing retention policies and labels. You should understand policy precedence, configure adaptive protection, and set up just-in-time protection. Hands-on work with DLP policy creation, testing policies to trigger alerts, and configuring retention labels for data lifecycle management will strengthen your readiness for this equally weighted domain.
Sample questions from this domain above:
Q3Q6
Domain 3: Manage risks, alerts, and activities
30% - 35%
This domain covers Insider Risk Management implementation, managing information security alerts, and protecting data used by AI services. You need to configure insider risk policies, manage alerts and cases, and respond to Purview alerts. Additionally, understand audit logging, content search, and the new controls for Data Security Posture Management for AI. All three domains carry equal weight, so ignoring this area will cost points.
FAQ
SC-401 Exam FAQ
Common questions about the exam itself
What is the SC-401 exam format and how much time do I have?
You have 100 minutes to answer approximately 40 to 60 questions. The exam uses multiple-choice, drag-and-drop, yes/no binary-choice items, hotspot questions, and case studies with scenario-based questions. One case study typically includes about 4 related questions and tests whether you can apply Purview configuration to a business problem rather than just recall definitions.
How hard is SC-401 compared to SC-400?
SC-401 is significantly different from the retired SC-400. Microsoft removed five entire topic areas, added DSPM for AI and Adaptive Protection, and restructured the exam into three equally weighted domains that test reasoning under time pressure. Candidates who arrive with old SC-400 study materials often score around 650 and fail because the exam now emphasizes practical configuration work over theoretical knowledge.
What hands-on preparation is most important for SC-401?
Complete all 13 lab exercises from the official instructor-led course in the MicrosoftLearning/SC-401T00 GitHub repository. Set up sensitivity labels end to end, build and test DLP policies, configure Insider Risk Management policies, generate alerts, and review them in every relevant portal. Everyone who passed quickly had one thing in common: they completed all the labs.
Do I need any certifications before attempting SC-401?
No. Microsoft lists no formal prerequisites for SC-401. However, you should have familiarity with Microsoft 365 services, PowerShell, Microsoft Entra, the Microsoft Defender portal, and Microsoft Defender for Cloud Apps. Hands-on experience with Purview Information Protection, sensitivity labels, DLP, retention, and insider risk management is strongly recommended.
What is the passing score for SC-401 and how is it calculated?
You need a scaled score of 700 out of 1000 to pass. This scaled score does not translate directly to a percentage of correct answers because Microsoft adjusts for question difficulty. Aim to master every domain rather than scraping through one, and aim for consistent scores of 80 to 90 percent on practice exams before scheduling.
How long should I study for SC-401?
Most candidates need 8 to 10 weeks at 10 to 15 hours per week if new to Microsoft Purview. If you have an active SC-400 background, you can compress to 4 to 6 weeks. If you are brand new to Microsoft security, extend to 12 to 16 weeks. Hands-on lab time in an E5 trial tenant is the single highest return on investment preparation activity.
How long does the SC-401 certification stay valid and how do I renew it?
Your certification is valid for one year from the date you pass. To renew, you must pass a free online assessment on Microsoft Learn before the 12-month window expires. There is no cost for renewing this way. If you miss the renewal window, your credential expires and you must retake the full exam at full price.
Which domain on SC-401 do most candidates struggle with?
The Data Loss Prevention and Retention domain challenges many candidates because it requires understanding policy precedence, adaptive protection rules, and retention label lifecycle management across overlapping scenarios. Many candidates underestimate Insider Risk Management and the new DSPM for AI controls. Since all three domains are equally weighted at 30 to 35 percent each, you cannot safely ignore any one.
What is the difference between SC-401 and SC-400, and which should I take?
SC-400 retired on 31 May 2025. SC-401 is its replacement but covers significantly different material. SC-401 focuses on information protection and data security with added coverage of AI data controls. If you are starting now, take SC-401. If you already hold SC-400, you can renew that certification using the free renewal assessment.
What job role does SC-401 prepare me for?
SC-401 validates skills for Information Security Administrators, Security Operations Analysts, Compliance Officers, and IT professionals involved in securing Microsoft 365 environments. The certification demonstrates expertise in implementing information protection, data loss prevention, managing insider risks, and responding to security alerts using Microsoft Purview and related services.