dc dotCreds
Microsoft SC-401 Practice Test

Microsoft SC-401 Practice Test

Start today’s free 10-question Microsoft SC-401 set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 22, 2026, 7:44 PM CDT

Go Pro - One Time Unlock

Unlock the full SC-401 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 Microsoft SC-401 questions

Use this Microsoft SC-401 practice test to review Microsoft SC-401 Information Security Administrator. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Implement and monitor Microsoft Purview Endpoint DLP Implement data loss prevention and retention (30%-35%)

New files can reach an egress action before classification finishes. A JIT pilot protects that gap but occasionally delays legitimate activity. How should the team scope and validate the control before enterprise rollout?

Concept tested:
Question 2 of 10
Objective Protect data used by AI services Manage risks, alerts, and activities (30%-35%)

An AI security program needs administrators who can configure DSPM, analysts who can view posture data, and a much smaller group that may view prompt or response content. The organization refuses to grant Global Administrator for routine work. How should roles be assigned?

Concept tested:
Question 3 of 10
Objective Create and configure data loss prevention policies Implement data loss prevention and retention (30%-35%)

An item in SharePoint matches several rules: one notifies, one blocks with override, and a higher-priority restrictive rule blocks without override. The administrator must predict which action is enforced without assuming every matching rule action is independently applied. Which design is technically valid?

Concept tested:
Question 4 of 10
Objective Implement and manage sensitivity labels in Microsoft Purview Implement information protection (30%-35%)

A company is redesigning its label taxonomy for files, emails, Teams, and SharePoint sites. The current design uses one container-oriented setting as if it provides the same protection for every item. What should drive the revised taxonomy?

Concept tested:
Question 5 of 10
Objective Implement and manage retention Implement data loss prevention and retention (30%-35%)

A SharePoint document remains preserved longer than a site owner expected. Policy Lookup shows a location-wide retention policy, and the item may also carry an explicit retention label. What is the most reliable way to explain the effective retention behavior?

Concept tested:
Question 6 of 10
Objective Manage information security alerts and activities Manage risks, alerts, and activities (30%-35%)

Two Defender for Cloud Apps file policies match the same file and specify different governance actions. The operations team expects both actions to execute. What documented behavior should guide the response to the alert?

Concept tested:
Question 7 of 10
Objective Implement and manage data classification Implement information protection (30%-35%)

An organization wants OCR for images in several Purview locations and plans to assume it is automatically available everywhere. Which implementation checks are required before broad deployment?

Concept tested:
Question 8 of 10
Objective Implement and monitor Microsoft Purview Endpoint DLP Implement data loss prevention and retention (30%-35%)

A managed endpoint user can print a sensitive file, copy it to USB, move it to a network share, and upload it through a browser. The organization wants different outcomes for those activities rather than one generic cloud-sharing action. How should the DLP rule be designed?

Concept tested:
Question 9 of 10
Objective Implement and manage Microsoft Purview Insider Risk Management Manage risks, alerts, and activities (30%-35%)

A reviewer confirms a low-severity, inadvertent policy violation and the organization's response playbook calls for education rather than discipline. The reviewer needs a repeatable communication step within the Insider Risk Management workflow. Which implementation is appropriate?

Concept tested:
Question 10 of 10
Objective Implement information protection for Windows, file shares, and Exchange Implement information protection (30%-35%)

The desktop team plans to use File Explorer and PowerShell to apply Purview labels to local files. Before deployment, it must account for supported file types, client installation, user permissions, and label-policy availability. What should the implementation plan include?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SC-401 Pro $4.99 one-time

Best if you only need this one certification.

50 Exam Practice Test $1.99 one-time

A 50-question SC-401 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Microsoft Access $6.99/month

Unlock Microsoft, Azure, Power Platform, Copilot, and AI practice exams.

Why it fitsUnlock Microsoft, Azure, Power Platform, Copilot, and AI practice exams, Includes MS-700 Managing Microsoft Teams, Includes current and future Microsoft practice banks on dotCreds, Best for learners taking more than one Microsoft exam, PDF downloads sold separately where available

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SC-401 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SC-401 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily Microsoft SC-401 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 New files can reach an egress action before classification finishes. A JIT pilot protects that gap but occasionally delays legitimate activity. How should the team scope and validate the control before enterprise rollout?

Answer choices

  1. A. Use Audit Premium; audit logging pauses endpoint transfers until the event is searchable. Use a retention label with record locking; record retention is the JIT classification queue for endpoints.
  2. B. Enable and scope Endpoint DLP just-in-time protection so supported egress can be temporarily blocked while classification and policy evaluation are pending. Use OCR; OCR always blocks file egress while every file in the tenant is being classified.
  3. C. Enable and scope Endpoint DLP just-in-time protection so supported egress can be temporarily blocked while classification and policy evaluation are pending. Pilot JIT scope and user impact because the control intentionally favors protection during an evaluation gap and can temporarily block activity.
  4. D. Use an eDiscovery hold; holds prevent a newly created endpoint file from being uploaded until DLP classification completes. Pilot JIT scope and user impact because the control intentionally favors protection during an evaluation gap and can temporarily block activity.

Correct answer

Enable and scope Endpoint DLP just-in-time protection so supported egress can be temporarily blocked while classification and policy evaluation are pending. Pilot JIT scope and user impact because the control intentionally favors protection during an evaluation gap and can temporarily block activity.

Enable and scope Endpoint DLP just-in-time protection so supported egress can be temporarily blocked while classification and policy evaluation are pending. Pilot JIT scope and user impact because the control intentionally favors protection during an evaluation gap and can temporarily block activity. JIT protection is specifically designed for the short period when Endpoint DLP has not yet obtained a current policy classification result for a candidate file.

Wrong-answer review

  • A. Use Audit Premium; audit logging pauses endpoint transfers until the event is searchable. Use a retention label with record locking; record retention is the JIT classification queue for endpoints.: Audit can provide searchable or retained event evidence for the activity described in 'Use Audit Premium', but those audit records do not become the source-content control needed to achieve 'Enable and scope Endpoint DLP just-in-time protection so supported egress can be temporarily blocked while classification and policy evaluation are pending. Pilot JIT scope and user impact because the control…'.
  • B. Enable and scope Endpoint DLP just-in-time protection so supported egress can be temporarily blocked while classification and policy evaluation are pending. Use OCR; OCR always blocks file egress while every file in the tenant is being classified.: The endpoint behavior in 'Enable and scope Endpoint DLP just-in-time protection so supported egress can be temporarily blocked while classification and…' is limited by supported onboarded-device and JIT semantics and therefore cannot be generalized into the different scope implied by 'Enable and scope Endpoint DLP just-in-time protection so supported egress can be temporarily blocked while classification and policy evaluation are pending. Pilot JIT scope and user impact because the control…'.
  • D. Use an eDiscovery hold; holds prevent a newly created endpoint file from being uploaded until DLP classification completes. Pilot JIT scope and user impact because the control intentionally favors protection during an evaluation gap and can temporarily block activity.: Using 'Use an eDiscovery hold' as the answer confuses eDiscovery search, hold, review, or export with the operational behavior required for 'Enable and scope Endpoint DLP just-in-time protection so supported egress can be temporarily blocked while classification and policy evaluation are pending. Pilot JIT scope and user impact because the control…'.

Extra learning features

Why candidates miss this

The distractor 'Use Audit Premium; audit logging pauses endpoint transfers until the event is searchable' is tempting because it suggests a fallback mechanism. However, audit logging doesn't actively block egress; it merely provides forensic data. The decisive clue is the control's intentional blocking behavior, highlighting the JIT protection's core function. Likely wrong answer: Use Audit Premium; audit logging pauses endpoint transfers until the event is searchable. Use a retention label with record locking; record retention is the JIT classification queue for endpoints. Review focus: Learn about just-in-time protection

Interview question

Q: Enable and scope Endpoint DLP just-in-time protection so supported egress can be temporarily blocked while classification and policy evaluation are pending. Pilot JIT scope and user impact because the control intentionally favors protection during an evaluation gap and can temporarily block activity. Strong answer: The JIT protection is designed to temporarily block supported egress during the classification and policy evaluation phase, mitigating the risk of unclassified data being transmitted.

  • Just-in-time protection
  • Egress control
  • Policy evaluation
  • Temporary blocking

Caution: Do not restate the multiple-choice stem or ask the learner merely to name a product, rule, or term.

Objective/domain: Implement data loss prevention and retention (30%-35%)

Source: Learn about just-in-time protection

Question 2 An AI security program needs administrators who can configure DSPM, analysts who can view posture data, and a much smaller group that may view prompt or response content. The organization refuses to grant Global Administrator for routine work. How should roles be assigned?

Answer choices

  1. A. Use eDiscovery Manager as the mandatory DSPM policy-administration role.
  2. B. Assign AI Administrator to every analyst and assume it grants unrestricted Purview content viewing by default.
  3. C. Use the documented DSPM management and view-only roles, and grant AI-content or Content Explorer content-view permissions only to the limited reviewers who require prompt or response visibility.
  4. D. Grant Global Administrator to every DSPM viewer because read-only posture roles do not exist.

Correct answer

Use the documented DSPM management and view-only roles, and grant AI-content or Content Explorer content-view permissions only to the limited reviewers who require prompt or response visibility.

Objective/domain: Manage risks, alerts, and activities (30%-35%)

Source: Permissions for Microsoft Purview Data Security Posture Management

Question 3 An item in SharePoint matches several rules: one notifies, one blocks with override, and a higher-priority restrictive rule blocks without override. The administrator must predict which action is enforced without assuming every matching rule action is independently applied. Which design is technically valid?

Answer choices

  1. A. The lowest-priority rule always wins because later-created rules override earlier rules.
  2. B. All matched hosted-service rule actions are always summed together exactly like Endpoint DLP.
  3. C. For hosted-service locations, evaluate rules in priority order and account for the documented most-restrictive-action behavior when multiple rules match.
  4. D. Simulation-mode policies always take precedence over enforced policies when their rule number is lower.

Correct answer

For hosted-service locations, evaluate rules in priority order and account for the documented most-restrictive-action behavior when multiple rules match.

Objective/domain: Implement data loss prevention and retention (30%-35%)

Source: Data Loss Prevention policy reference

Question 4 A company is redesigning its label taxonomy for files, emails, Teams, and SharePoint sites. The current design uses one container-oriented setting as if it provides the same protection for every item. What should drive the revised taxonomy?

Answer choices

  1. A. Design the label taxonomy so users see labels appropriate to the supported workloads and protection outcome rather than using one container setting as a substitute for item protection.
  2. B. Use a retention label for Teams privacy and guest-access settings because retention labels are the container-protection mechanism.
  3. C. Create separate DLP policies for each label name because a sensitivity label itself cannot contain protection settings.
  4. D. Apply a Groups & sites label to a SharePoint site and rely on it to encrypt every existing and future file in the site.

Correct answer

Design the label taxonomy so users see labels appropriate to the supported workloads and protection outcome rather than using one container setting as a substitute for item protection.

Objective/domain: Implement information protection (30%-35%)

Source: Learn about sensitivity labels

Question 5 A SharePoint document remains preserved longer than a site owner expected. Policy Lookup shows a location-wide retention policy, and the item may also carry an explicit retention label. What is the most reliable way to explain the effective retention behavior?

Answer choices

  1. A. Use Policy Lookup and inspect both the location-wide retention policies and any item-level retention label before applying Purview retention precedence principles to the document.
  2. B. Stop after identifying the location-wide policy; an item-level retention label cannot influence retention once a site is already included in a retention policy.
  3. C. Assume the item-level label always shortens the effective retention period because item-level settings are more specific than location-wide policy settings in every case.
  4. D. Assume the longest location-wide policy always controls even if the item has explicit label-based retention or record settings; item-level retention never changes the result.

Correct answer

Use Policy Lookup and inspect both the location-wide retention policies and any item-level retention label before applying Purview retention precedence principles to the document.

Objective/domain: Implement data loss prevention and retention (30%-35%)

Source: Learn about retention policies and retention labels

Question 6 Two Defender for Cloud Apps file policies match the same file and specify different governance actions. The operations team expects both actions to execute. What documented behavior should guide the response to the alert?

Answer choices

  1. A. Account for the fact that only the first triggered file policy's governance action is guaranteed when overlapping file policies match the same file.
  2. B. Set the daily alert limit to zero; that disables all file-policy governance actions on matching files.
  3. C. Use Audit Premium retention to tune file-policy alert thresholds; audit retention controls Cloud Apps governance.
  4. D. Move the file policy to Endpoint DLP; endpoint policy mode directly changes Cloud Apps alert limits.

Correct answer

Account for the fact that only the first triggered file policy's governance action is guaranteed when overlapping file policies match the same file.

Objective/domain: Manage risks, alerts, and activities (30%-35%)

Source: File policies in Microsoft Defender for Cloud Apps

Question 7 An organization wants OCR for images in several Purview locations and plans to assume it is automatically available everywhere. Which implementation checks are required before broad deployment?

Answer choices

  1. A. Enable and scope Microsoft Purview OCR so text can be extracted from supported images and then evaluated by the existing sensitive information types and classifiers. Configure document fingerprinting on each image extension because fingerprinting is the required OCR engine.
  2. B. Replace every sensitive information type with a trainable classifier because OCR cannot feed existing classifiers. Validate licensing or pay-as-you-go requirements and supported locations before broad OCR rollout because OCR is an optional capability, not an automatic property of every Purview policy.
  3. C. Enable a sensitivity label policy; publishing a label automatically performs OCR on all tenant images. Use Endpoint DLP JIT protection as the OCR service because JIT converts images to text before classification.
  4. D. Enable and scope Microsoft Purview OCR so text can be extracted from supported images and then evaluated by the existing sensitive information types and classifiers. Validate licensing or pay-as-you-go requirements and supported locations before broad OCR rollout because OCR is an optional capability, not an automatic property of every Purview policy.

Correct answer

Enable and scope Microsoft Purview OCR so text can be extracted from supported images and then evaluated by the existing sensitive information types and classifiers. Validate licensing or pay-as-you-go requirements and supported locations before broad OCR rollout because OCR is an optional capability, not an automatic property of every Purview policy.

Objective/domain: Implement information protection (30%-35%)

Source: Learn about optical character recognition in Microsoft Purview

Question 8 A managed endpoint user can print a sensitive file, copy it to USB, move it to a network share, and upload it through a browser. The organization wants different outcomes for those activities rather than one generic cloud-sharing action. How should the DLP rule be designed?

Answer choices

  1. A. Use a Defender for Cloud Apps file policy; Cloud Apps governance is the direct control for local USB and printer activity.
  2. B. Use a SharePoint container label to block removable-media copy; container labels are the endpoint activity engine.
  3. C. Create an audit retention policy for FileCopied events; audit retention turns those historical events into real-time endpoint blocks.
  4. D. Use endpoint activity controls to differentiate what is audited, blocked, or allowed instead of applying one generic cloud sharing action to every device event.

Correct answer

Use endpoint activity controls to differentiate what is audited, blocked, or allowed instead of applying one generic cloud sharing action to every device event.

Objective/domain: Implement data loss prevention and retention (30%-35%)

Source: Learn about Endpoint data loss prevention

Question 9 A reviewer confirms a low-severity, inadvertent policy violation and the organization's response playbook calls for education rather than discipline. The reviewer needs a repeatable communication step within the Insider Risk Management workflow. Which implementation is appropriate?

Answer choices

  1. A. Use a DLP policy tip after the historical event; DLP tips are the Insider Risk Management case-notice template system.
  2. B. Send an eDiscovery legal hold notification for every low-risk insider case; hold notices are the standard education workflow.
  3. C. Use a customized Insider Risk Management notice template to send the approved reminder or guidance as part of the case workflow.
  4. D. Close the case without documenting remediation because notice templates are only available before an alert is reviewed.

Correct answer

Use a customized Insider Risk Management notice template to send the approved reminder or guidance as part of the case workflow.

Objective/domain: Manage risks, alerts, and activities (30%-35%)

Source: Learn about Insider Risk Management

Question 10 The desktop team plans to use File Explorer and PowerShell to apply Purview labels to local files. Before deployment, it must account for supported file types, client installation, user permissions, and label-policy availability. What should the implementation plan include?

Answer choices

  1. A. Enable a SharePoint container label; it installs File Explorer labeling support automatically on every joined Windows device.
  2. B. Plan client deployment, permissions, supported file types, and labeling policy availability before relying on shell or PowerShell actions in production.
  3. C. Use the Azure Information Protection unified labeling client for new deployments because it replaced the Purview Information Protection client.
  4. D. Deploy only Endpoint DLP; Endpoint DLP includes all Purview Information Protection PowerShell cmdlets without the client.

Correct answer

Plan client deployment, permissions, supported file types, and labeling policy availability before relying on shell or PowerShell actions in production.

Objective/domain: Implement information protection (30%-35%)

Source: Microsoft Purview Information Protection client PowerShell

Where to go after the daily web set

How are Microsoft SC-401 questions generated?

dotCreds builds Microsoft SC-401 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start Microsoft SC-401 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.