SC-401 sample questions with answers

10 free practice questions for the Microsoft Certified: Information Security Administrator Associate exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1Implement information protection

Woodgrove Bank must detect only the account numbers that belong to its 180,000 real customers, and no other numbers of the same shape. You decide to build an exact data match based sensitive information type. Which two tasks must you complete before the exact data match type can return matches? Each correct answer presents part of the solution. (Choose TWO.)

Choose 2.

  1. A.

    Create a custom trainable classifier that is trained on a sample of the account number table.

  2. B.

    Hash and upload the sensitive information source table by using the EDM Upload Agent, signed in with an account in the EDM_DataUploaders security group.

  3. C.

    Enable optical character recognition for the tenant so that account numbers in images are read.

  4. D.

    Define the exact data match schema, which maps the columns of the sensitive information source table and identifies the primary fields that can start a lookup.

  5. E.

    Publish an auto-labeling policy in simulation mode that references the exact data match type.

Show answer

Answer: B, D

An exact data match type needs a schema that declares which columns are searchable and a hashed, uploaded copy of the sensitive data table before it can match anything.

  • A. Trainable classifiers learn a fuzzy content category and are never part of the exact data match build process.
  • B. The EDM Upload Agent hashes the table with a salt and uploads only the hashes; the uploading account must belong to the EDM_DataUploaders group, and without an uploaded, indexed table there is nothing to compare content against.
  • C. Optical character recognition only extends scanning into images and is not a prerequisite for exact data match detection.
  • D. The schema maps the source table's columns and marks which fields are primary (searchable); in the new experience it is generated from a sample file in the same workflow that creates the SIT, but it must exist before anything can match.
  • E. Simulation mode is how you test a policy that consumes the classifier; it does nothing to make the exact data match type functional.
Question 2Implement information protection

Lamna Healthcare's Restricted label adds a Restricted footer to documents. After a SharePoint auto-labeling policy applies Restricted to thousands of existing files, users open the files in Word and notice that they carry the label but no footer. What explains this?

  1. A.

    The footer text is longer than the 255-character limit for footers in Word

  2. B.

    Footers are applied to documents only when the label also encrypts, so the Restricted label needs encryption

  3. C.

    Auto-labeling policies don't apply visual markings to documents; the footer is added only when a user reapplies the label in an Office app

  4. D.

    The footer is applied only after the policy's simulation results are deleted from the portal and the policy is turned off and then turned on again for the same locations

Show answer

Answer: C

Service-side auto-labeling writes the label to documents without inserting headers, footers, or watermarks.

  • A. Word footers allow up to 1,024 characters; 255 is the watermark limit.
  • B. Content markings don't depend on encryption; they can be applied by labels that don't encrypt.
  • C. When you use auto-labeling policies, headers, footers, and watermarks configured on the label aren't applied to documents; solutions labeling outside Office apps write metadata, and users can apply markings by reapplying the label.
  • D. Simulation has no bearing on markings; the policy is already labeling files.
Question 3Implement information protection

Wide World Importers publishes its sensitivity labels to all users. Analysts with Power BI Pro licenses report that the sensitivity option is unavailable on their reports and semantic models in the Power BI service, and in Power BI Desktop. What should you do?

  1. A.

    In the Fabric admin portal, turn on the tenant setting Allow users to apply sensitivity labels for content

  2. B.

    Create an auto-labeling policy that includes Power BI as a location

  3. C.

    Add the Groups & sites scope to the labels, because Power BI items are labeled as containers

  4. D.

    Assign the analysts to the Information Protection Admins role group so they can see labels in Power BI

Show answer

Answer: A

Power BI and Fabric can use sensitivity labels only after a Fabric admin turns on Allow users to apply sensitivity labels for content.

  • A. Sensitivity labels must be enabled in the Fabric tenant settings, under Information protection, before they can be used in the Fabric service and Power BI Desktop.
  • B. Auto-labeling policies target Exchange, SharePoint, and OneDrive; there's no Power BI location.
  • C. Power BI items are labeled with the Files & other data assets scope; container labels aren't supported for Power BI.
  • D. Applying labels requires no admin role, only licensing, published labels, and the tenant setting.
Question 4Implement information protection

Sable Rock Security set up billing and enabled optical character recognition for every supported location. The team lists four requirements that depend on text inside images, such as screenshots and scans. Which requirement can't be met by using OCR results?

  1. A.

    Apply the Confidential sensitivity label through an auto-labeling policy to outgoing Exchange email with an image of a passport

  2. B.

    Auto-apply a retention label to SharePoint files whose embedded images contain a contract number

  3. C.

    Block Teams chat messages that contain a screenshot of a credit card number

  4. D.

    Raise a user's insider risk score when images that contain customer account numbers are attached to email sent from Exchange

Show answer

Answer: D

OCR results feed insider risk management only from SharePoint, Teams, and devices, not from Exchange.

  • A. Exchange supports auto-labeling policies with OCR.
  • B. SharePoint supports auto-apply retention label policies with OCR, using keywords and sensitive information types.
  • C. Teams chat and channel messages support DLP with OCR, so a DLP rule can act on text inside images.
  • D. Exchange supports DLP, auto-labeling, and auto-apply retention with OCR, but not insider risk management; insider risk uses OCR results from SharePoint, Teams, and devices.
Question 5Implement information protection

At Coho Winery, a new information protection engineer must create sensitivity labels, publish label policies, and create auto-labeling policies. He must not receive permissions outside information protection and DLP. Which built-in Microsoft Purview role group should you assign?

  1. A.

    Information Protection Readers

  2. B.

    Organization Management

  3. C.

    Information Protection Analysts

  4. D.

    Information Protection Admins

Show answer

Answer: D

Information Protection Admins is the built-in role group that creates and manages sensitivity labels, label policies, and auto-labeling policies.

  • A. Information Protection Readers have view-only access to reports for DLP policies and sensitivity labels.
  • B. Organization Management grants administration across the whole portal, far beyond information protection.
  • C. Information Protection Analysts manage DLP alerts and activity explorer with view-only access to labels and policies, so they can't create labels.
  • D. Information Protection Admins can create, edit, and delete DLP policies, sensitivity labels and their policies, and all classifier types, and manage simulation mode for auto-labeling policies.
Question 6Implement information protection

The information protection manager at Vireo Telecom must report how many items in SharePoint, OneDrive, and Exchange currently carry the Highly Confidential sensitivity label, and in which locations those items are stored. Which Microsoft Purview tool provides this current view?

  1. A.

    Data explorer in Information Protection

  2. B.

    Policy lookup in Data Lifecycle Management

  3. C.

    Activity explorer in Information Protection, filtered on the Label applied activity for the past 30 days

  4. D.

    The audit log search in Microsoft Purview Audit, filtered on sensitivity label activities

Show answer

Answer: A

Data explorer is the current snapshot of labeled and classified items by location, while activity explorer is the activity history.

  • A. Data explorer shows a current snapshot of items that have a sensitivity label, a retention label, or a sensitive information type match, organized by location.
  • B. Policy lookup shows which retention policies apply to a user or site; it doesn't report sensitivity labels on items.
  • C. Activity explorer is a historical view of activities over up to 30 days; it shows labeling events, not an inventory of where labeled items are now.
  • D. Audit search returns individual events; it doesn't provide a current inventory of labeled items per location.
Question 7Implement information protection

At Relecloud, a user creates a new team in Microsoft Teams and selects the Project sensitivity label, which is configured for groups and sites with Private privacy. The team's SharePoint site already holds uploaded files. Which containers receive the label?

  1. A.

    Only the SharePoint site; the Microsoft 365 group can be labeled only in the Microsoft Entra admin center

  2. B.

    Only the team in Teams; the SharePoint site must be labeled separately by an administrator

  3. C.

    The team's Microsoft 365 group and the connected SharePoint team site

  4. D.

    Every file stored in the team's SharePoint site, which inherits the label

Show answer

Answer: C

Labeling a new team labels its Microsoft 365 group and connected SharePoint site, but not the items stored there.

  • A. The group is labeled automatically along with the site when the team is created with a label.
  • B. No separate step is needed for the site; the label is applied to both automatically.
  • C. When a user creates a team with a label, the service automatically applies the same label to the Microsoft 365 group and the connected SharePoint team site.
  • D. Items in labeled containers don't inherit the container's label or its item-level settings.
Question 8Implement information protection

Summit Peak Airlines issues corporate cards whose numbers always start with 41, 42, or 43. The DLP team must detect only those card numbers and ignore every other card number, while keeping the checksum and keyword logic of the built-in Credit Card Number type. What should the team do?

  1. A.

    Edit the built-in Credit Card Number type and replace its primary regular expression with one that begins with the three prefixes

  2. B.

    Build an EDM type from a table of every corporate card number that has been issued to employees

  3. C.

    Add a keyword list that contains 41, 42, and 43 as a supporting element of a copy of the built-in type, and set its proximity window to 300 characters

  4. D.

    Copy the built-in Credit Card Number type and add a Starts with additional check that lists 41, 42, and 43

Show answer

Answer: D

Copying the built-in type preserves its logic, and the Starts with additional check restricts matches to the listed prefixes.

  • A. Built-in types can't be edited; changes are made on a copy.
  • B. EDM would work only for numbers already in the table and adds schema, hashing, and refresh overhead for a rule that a prefix check expresses directly.
  • C. Supporting elements only raise confidence when found near the match; they don't restrict which numbers match, so other cards would still be detected.
  • D. A copy keeps the built-in pattern, checksum, and keywords, and the Starts with additional check limits matches to numbers that begin with the listed characters, which is the documented example.
Question 9Implement information protection

Vireo Telecom's security team requires that documents and messages containing leaked secrets, such as storage account keys, connection strings, and access tokens, be detected by Microsoft Purview policies. The team plans to use the built-in credential scanning sensitive information types. Which requirement must be confirmed before those types can be used?

  1. A.

    Optical character recognition is enabled, because secrets are usually pasted as screenshots

  2. B.

    An exact data match schema is created from a table of every key, token, and connection string that the organization has ever issued, and the table is refreshed daily

  3. C.

    The users in scope are licensed with an E5-level subscription, because credential scanning sensitive information types require an E5 license

  4. D.

    A custom regular expression type is written for each secret format, because no built-in type detects credentials

Show answer

Answer: C

Credential scanning sensitive information types, including the All credentials type, are an E5-licensed capability.

  • A. Optical character recognition only extends detection into images; it isn't a prerequisite for credential detection in text.
  • B. EDM compares content against a table of known values; secrets are detected by the credential scanning types without uploading any table of keys.
  • C. Purview states that an E5 license is required to use the credential scanning sensitive information types, including the All credentials type that groups them.
  • D. Built-in credential scanning types already exist, grouped under All credentials, so writing a regular expression per format isn't required.
Question 10Implement information protection

Kestrel Mutual currently licenses Microsoft 365 E3 and already encrypts external email with Message Encryption. The compliance team wants external encrypted email to expire after 30 days and wants the ability to revoke messages. Which license change provides Microsoft Purview Advanced Message Encryption?

  1. A.

    No change, because Microsoft 365 E3 includes Advanced Message Encryption

  2. B.

    Exchange Online Plan 2 for every user who sends email to external recipients

  3. C.

    Azure Information Protection Plan 1, added to Microsoft 365 E3

  4. D.

    Microsoft 365 E5, or the Microsoft 365 E5 Information Protection and Governance add-on

Show answer

Answer: D

Advanced Message Encryption, which adds expiration and revocation, comes with E5-level licensing, such as Microsoft 365 E5 or the E5 Information Protection and Governance add-on.

  • A. E3 includes Message Encryption but not Advanced Message Encryption.
  • B. Exchange Online Plan 2 doesn't include Advanced Message Encryption.
  • C. Azure Information Protection Plan 1 provides basic Message Encryption to plans that lack it, not the advanced features.
  • D. The service description lists Advanced Message Encryption for Microsoft 365 E5/A5/G5, Microsoft 365 E5 Information Protection and Governance, Office 365 E5, and related suites.

Keep going with 502 more SC-401 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

SC-401 sample questions with answers (10 free) · CertifyCloudx