dc dotCreds
Microsoft SC-401 Practice Test

Microsoft SC-401 Practice Test

Start today’s free 10-question Microsoft SC-401 set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 23, 2026, 8:12 PM CDT

Go Pro - One Time Unlock

Unlock the full SC-401 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 Microsoft SC-401 questions

Use this Microsoft SC-401 practice test to review Microsoft SC-401 Information Security Administrator. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Implement and monitor Microsoft Purview Endpoint DLP Implement data loss prevention and retention (30%-35%)

A user performs a monitored endpoint action and the SOC does not see it immediately in Activity Explorer. They are considering using Activity Explorer as if it were a real-time blocking console. What should the analyst understand about that surface?

Concept tested:
Question 2 of 10
Objective Implement and manage data classification Implement information protection (30%-35%)

A healthcare SaaS provider uses a proprietary member number that appears near specific labels in documents, but the raw number format overlaps with benign inventory codes. The custom detector must raise confidence only when contextual evidence appears close to the primary pattern. Which proposal best meets the requirement?

Concept tested:
Question 3 of 10
Objective Implement and manage Microsoft Purview Insider Risk Management Manage risks, alerts, and activities (30%-35%)

An insider-risk scenario depends on employee resignation and termination events, but those events are not present in ordinary Microsoft 365 activity telemetry. The policy template expects HR-derived trigger data. What should the administrator implement?

Concept tested:
Question 4 of 10
Objective Implement and manage retention Implement data loss prevention and retention (30%-35%)

A policy requires every item in selected Exchange and SharePoint locations to be retained for five years and then deleted. There is no content-specific exception and no need for users to classify individual items. Which lifecycle design has the lowest unnecessary complexity?

Concept tested:
Question 5 of 10
Objective Implement information protection for Windows, file shares, and Exchange Implement information protection (30%-35%)

The desktop team plans to use File Explorer and PowerShell to apply Purview labels to local files. Before deployment, it must account for supported file types, client installation, user permissions, and label-policy availability. What should the implementation plan include?

Concept tested:
Question 6 of 10
Objective Manage information security alerts and activities Manage risks, alerts, and activities (30%-35%)

A Defender for Cloud Apps file policy generates alerts on a large number of legitimate partner files. The security team wants to understand the matched files and sharing context before changing enforcement. What is the appropriate response?

Concept tested:
Question 7 of 10
Objective Implement and manage sensitivity labels in Microsoft Purview Implement information protection (30%-35%)

A regional compliance team needs to create and publish sensitivity labels for its delegated business area. It does not need tenant-wide compliance administration and it must not gain broad access to protected content. Which delegation model is most appropriate?

Concept tested:
Question 8 of 10
Objective Protect data used by AI services Manage risks, alerts, and activities (30%-35%)

Leadership wants aggregate AI-risk posture and policy recommendations, while investigators need event-level detail for selected AI interactions. How should the team use DSPM views for those two levels of analysis?

Concept tested:
Question 9 of 10
Objective Create and configure data loss prevention policies Implement data loss prevention and retention (30%-35%)

An item in SharePoint matches several rules: one notifies, one blocks with override, and a higher-priority restrictive rule blocks without override. The administrator must predict which action is enforced without assuming every matching rule action is independently applied. Which design is technically valid?

Concept tested:
Question 10 of 10
Objective Implement information protection for Windows, file shares, and Exchange Implement information protection (30%-35%)

Advanced Message Encryption is configured, but the rollout team tested only internal senders and never validated the external recipient portal or post-delivery experience. What should be added to the acceptance test?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SC-401 Pro $4.99 one-time

Best if you only need this one certification.

50 Exam Practice Test $1.99 one-time

A 50-question SC-401 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Microsoft Security Bundle $9.99 one-time

Unlock all 6 active Microsoft Security Bundle practice banks in one permanent purchase.

What’s includedSC-900, SC-200, SC-300, SC-401, SC-500, SC-100
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SC-401 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SC-401 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily Microsoft SC-401 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A user performs a monitored endpoint action and the SOC does not see it immediately in Activity Explorer. They are considering using Activity Explorer as if it were a real-time blocking console. What should the analyst understand about that surface?

Answer choices

  1. A. Use eDiscovery review sets; review sets are the live telemetry feed for device DLP, within the documented operational, security, ownership, and validation requirements.
  2. B. Use a sensitivity-label publishing policy; its status page is the authoritative log of endpoint copy and print activity, as the selected response to the described condition.
  3. C. Allow for documented ingestion delay; Activity explorer is an investigation and reporting surface, not a real-time endpoint blocking console, as proposed.
  4. D. Use Content explorer only; it is the real-time endpoint event stream and exposes all USB and print actions as they happen, for the required operational result and control objective.

Correct answer

Allow for documented ingestion delay; Activity explorer is an investigation and reporting surface, not a real-time endpoint blocking console, as proposed.

Allow for documented ingestion delay; Activity explorer is an investigation and reporting surface, not a real-time endpoint blocking console. Activity explorer is the Purview activity-analysis surface for labeled/sensitive content and endpoint DLP events, with useful filters and expected ingestion latency.

Wrong-answer review

  • A. Use eDiscovery review sets; review sets are the live telemetry feed for device DLP, within the documented operational, security, ownership, and validation requirements.: Using 'Use eDiscovery review sets' as the answer confuses eDiscovery search, hold, review, or export with the operational behavior required for 'Allow for documented ingestion delay; Activity explorer is an investigation and reporting surface, not a real-time endpoint blocking console.'.
  • B. Use a sensitivity-label publishing policy; its status page is the authoritative log of endpoint copy and print activity, as the selected response to the described condition.: 'Use a sensitivity-label publishing policy' assigns sensitivity-label definition, publication, or automatic application a job that belongs to another stage of the labeling model, while 'Allow for documented ingestion delay; Activity explorer is an investigation and reporting surface, not a real-time endpoint blocking console.' uses the stage that actually owns the required behavior.
  • D. Use Content explorer only; it is the real-time endpoint event stream and exposes all USB and print actions as they happen, for the required operational result and control objective.: The endpoint behavior in 'Use Content explorer only' is limited by supported onboarded-device and JIT semantics and therefore cannot be generalized into the different scope implied by 'Allow for documented ingestion delay; Activity explorer is an investigation and reporting surface, not a real-time endpoint blocking console.'.

Extra learning features

Why candidates miss this

The distractors 'Use eDiscovery review sets' and 'Use a sensitivity-label publishing policy' both attempt to frame the issue as a process within the broader DLP ecosystem, obscuring the core understanding of Activity Explorer's real-time limitations. The decisive clue is the explicit statement that Activity Explorer is an investigation and reporting surface, not a real-time endpoint blocking console. Likely wrong answer: Use eDiscovery review sets; review sets are the live telemetry feed for device DLP. Review focus: Get started with activity explorer

Why this matters

Understanding the delayed ingestion of endpoint DLP events in Activity Explorer is crucial for analysts. Without this knowledge, they might incorrectly assume Activity Explorer functions as a real-time blocking console, leading to delayed incident response and potentially missed threats. This directly impacts the ability to proactively mitigate risks and maintain data security posture.

Objective/domain: Implement data loss prevention and retention (30%-35%)

Source: Get started with activity explorer

Question 2 A healthcare SaaS provider uses a proprietary member number that appears near specific labels in documents, but the raw number format overlaps with benign inventory codes. The custom detector must raise confidence only when contextual evidence appears close to the primary pattern. Which proposal best meets the requirement?

Answer choices

  1. A. Create a custom sensitive information type whose primary element matches the member number and whose supporting evidence, proximity, and confidence requirements distinguish it from inventory codes, within the stated policy framework.
  2. B. Use a keyword dictionary as the primary element and ignore proximity because supporting evidence cannot affect confidence, within the documented operational, security, ownership, and validation requirements.
  3. C. Use an Endpoint DLP setting to define the member-number regex because endpoint settings create tenant-wide sensitive information types, as the recommended implementation across the complete governed service lifecycle.
  4. D. Configure a custom retention label with regex and confidence levels; retention labels provide the same classification engine, for the described technical objective and its associated operational control requirements, when applied.

Correct answer

Create a custom sensitive information type whose primary element matches the member number and whose supporting evidence, proximity, and confidence requirements distinguish it from inventory codes, within the stated policy framework.

Objective/domain: Implement information protection (30%-35%)

Source: Create a custom sensitive information type

Question 3 An insider-risk scenario depends on employee resignation and termination events, but those events are not present in ordinary Microsoft 365 activity telemetry. The policy template expects HR-derived trigger data. What should the administrator implement?

Answer choices

  1. A. Create a sensitivity-label policy for departing users; label assignment is the HR triggering event source, for the described technical objective and its associated operational control requirements, in context.
  2. B. Use eDiscovery custodians as the connector; adding an employee to a case supplies all HR indicators to Insider Risk Management, for the stated implementation and support requirements.
  3. C. Use Endpoint DLP device groups; device scope automatically imports performance reviews and resignation dates, within the documented scope, ownership, and validation boundaries.
  4. D. Map the type of HR data collected to the selected policy template because different Insider Risk Management scenarios require different trigger data, within the described context.

Correct answer

Map the type of HR data collected to the selected policy template because different Insider Risk Management scenarios require different trigger data, within the described context.

Objective/domain: Manage risks, alerts, and activities (30%-35%)

Source: Set up a connector to import HR data

Question 4 A policy requires every item in selected Exchange and SharePoint locations to be retained for five years and then deleted. There is no content-specific exception and no need for users to classify individual items. Which lifecycle design has the lowest unnecessary complexity?

Answer choices

  1. A. Create an auto-apply retention label policy that attempts to label every item by a broad content condition; item-level labeling is required even when all content in the locations shares the same lifecycle.
  2. B. Apply a retention policy to the selected locations with the required retain-then-delete settings, because the lifecycle is broad and location based rather than item specific, within the implement data loss prevention and retention (30%-35%) context.
  3. C. Publish a five-year retention label and require users to apply it to every message and document in the selected locations; manual labeling is the normal mechanism for location-wide retention, for the stated security, delivery, and accountability requirements.
  4. D. Create a default retention label for only new content and leave existing content governed by user choice; broad retention policies cannot cover existing Exchange or SharePoint content, for the stated implementation and support requirements.

Correct answer

Apply a retention policy to the selected locations with the required retain-then-delete settings, because the lifecycle is broad and location based rather than item specific, within the implement data loss prevention and retention (30%-35%) context.

Objective/domain: Implement data loss prevention and retention (30%-35%)

Source: Create and configure retention policies

Question 5 The desktop team plans to use File Explorer and PowerShell to apply Purview labels to local files. Before deployment, it must account for supported file types, client installation, user permissions, and label-policy availability. What should the implementation plan include?

Answer choices

  1. A. Enable a SharePoint container label; it installs File Explorer labeling support automatically on every joined Windows device, as the primary proposed approach.
  2. B. Plan client deployment, permissions, supported file types, and labeling policy availability before relying on shell or PowerShell actions in production.
  3. C. Use the Azure Information Protection unified labeling client for new deployments because it replaced the Purview Information Protection client, for the stated scenario.
  4. D. Deploy only Endpoint DLP; Endpoint DLP includes all Purview Information Protection PowerShell cmdlets without the client, for the required operational result and control objective.

Correct answer

Plan client deployment, permissions, supported file types, and labeling policy availability before relying on shell or PowerShell actions in production.

Objective/domain: Implement information protection (30%-35%)

Source: Microsoft Purview Information Protection client PowerShell

Question 6 A Defender for Cloud Apps file policy generates alerts on a large number of legitimate partner files. The security team wants to understand the matched files and sharing context before changing enforcement. What is the appropriate response?

Answer choices

  1. A. Use file-policy alerts to investigate affected files and sharing context, then adjust the file policy's filters or governance action when the policy is too broad.
  2. B. Create overlapping policies so every governance action is guaranteed to run in sequence on the same file, for the described technical objective and its associated operational control requirements, as configured.
  3. C. Move the file policy to Endpoint DLP; endpoint policy mode directly changes Cloud Apps alert limits, as the selected approach for the stated technical and business outcome.
  4. D. Use Audit Premium retention to tune file-policy alert thresholds; audit retention controls Cloud Apps governance, as the selected approach for the stated technical and business outcome, for review.

Correct answer

Use file-policy alerts to investigate affected files and sharing context, then adjust the file policy's filters or governance action when the policy is too broad.

Objective/domain: Manage risks, alerts, and activities (30%-35%)

Source: File policies in Microsoft Defender for Cloud Apps

Question 7 A regional compliance team needs to create and publish sensitivity labels for its delegated business area. It does not need tenant-wide compliance administration and it must not gain broad access to protected content. Which delegation model is most appropriate?

Answer choices

  1. A. Use a tenant-wide compliance administrator assignment because sensitivity-label administration cannot be delegated through Purview role groups or scoped roles, for the described technical objective and its associated operational control requirements, for the affected environment.
  2. B. Create a role group that includes both label administration and content-view permissions; viewing protected content is a prerequisite for publishing labels even when the team never investigates items, within the stated policy framework.
  3. C. Use an eDiscovery management role scoped to the region; eDiscovery role groups are the supported administration path for sensitivity-label creation and publishing, within the implement information protection (30%-35%) context.
  4. D. Use Purview role groups and scoped roles to grant only the label-management tasks the regional team needs, without adding unrelated tenant-wide or content-view privileges, under the documented operational and governance requirements.

Correct answer

Use Purview role groups and scoped roles to grant only the label-management tasks the regional team needs, without adding unrelated tenant-wide or content-view privileges, under the documented operational and governance requirements.

Objective/domain: Implement information protection (30%-35%)

Source: Permissions in the Microsoft Purview portal

Question 8 Leadership wants aggregate AI-risk posture and policy recommendations, while investigators need event-level detail for selected AI interactions. How should the team use DSPM views for those two levels of analysis?

Answer choices

  1. A. Use DSPM posture and recommendations for aggregate risk and coverage, then drill into AI activities when investigators need event-level context, within the proposed design.
  2. B. Use a sensitivity-label policy report; label publication is the authoritative AI activity event feed, for the described technical objective and its associated operational control requirements.
  3. C. Use retention Policy lookup; it lists all AI apps, agents, prompts, responses, and posture recommendations, under the documented operational and governance requirements.
  4. D. Use eDiscovery review sets as the default live DSPM dashboard; review sets continuously ingest all future AI activity automatically, as proposed.

Correct answer

Use DSPM posture and recommendations for aggregate risk and coverage, then drill into AI activities when investigators need event-level context, within the proposed design.

Objective/domain: Manage risks, alerts, and activities (30%-35%)

Source: Map DSPM and DSPM for AI tasks to the current Data Security Posture Management experience

Question 9 An item in SharePoint matches several rules: one notifies, one blocks with override, and a higher-priority restrictive rule blocks without override. The administrator must predict which action is enforced without assuming every matching rule action is independently applied. Which design is technically valid?

Answer choices

  1. A. The lowest-priority rule always wins because later-created rules override earlier rules, for the stated security, delivery, and accountability requirements.
  2. B. All matched hosted-service rule actions are always summed together exactly like Endpoint DLP, under the organization’s defined implementation and exception-management process.
  3. C. For hosted-service locations, evaluate rules in priority order and account for the documented most-restrictive-action behavior when multiple rules match, as the recommended response to this scenario.
  4. D. Simulation-mode policies always take precedence over enforced policies when their rule number is lower, within the implement data loss prevention and retention (30%-35%) context.

Correct answer

For hosted-service locations, evaluate rules in priority order and account for the documented most-restrictive-action behavior when multiple rules match, as the recommended response to this scenario.

Objective/domain: Implement data loss prevention and retention (30%-35%)

Source: Data Loss Prevention policy reference

Question 10 Advanced Message Encryption is configured, but the rollout team tested only internal senders and never validated the external recipient portal or post-delivery experience. What should be added to the acceptance test?

Answer choices

  1. A. Use a retention label to revoke a delivered external message; retention deletion removes the recipient's previously delivered encrypted copy, as the recommended implementation across the complete governed service lifecycle.
  2. B. Test external recipient access and portal experience because Advanced Message Encryption controls affect how protected messages are consumed after delivery, within the defined security and accountability boundaries.
  3. C. Use Audit Premium retention to expire the encrypted message when its audit event ages out, as the selected approach for the stated technical and business outcome.
  4. D. Use Endpoint DLP JIT protection to revoke the delivered message; JIT protects endpoint egress, not recipient access to previously delivered email, in context.

Correct answer

Test external recipient access and portal experience because Advanced Message Encryption controls affect how protected messages are consumed after delivery, within the defined security and accountability boundaries.

Objective/domain: Implement information protection (30%-35%)

Source: Advanced Message Encryption

Where to go after the daily web set

How are Microsoft SC-401 questions generated?

dotCreds builds Microsoft SC-401 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start Microsoft SC-401 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.