EnglishDeutschFrançaisEspañolPortuguês

Microsoft · SC-401 · Associate

Administering Information Security in Microsoft 365 (SC-401) — Practice Questions and Mock Exam

Prepare for SC-401 with original practice questions and clear answer explanations. Ask Alex, your AI tutor, when you need more detail, use your results to identify topics to review, and practice your pacing with timed mock exams.

50Mock exam questions
100minTime limit
700/ 1000Passing score

Checked against Microsoft · August 2026 · Current exam version

About the exam

The SC-401 certification validates skills in administering information security using Microsoft Purview and related Microsoft 365 services. It covers implementing data classification, sensitivity labels, data loss prevention (DLP) policies, retention, insider risk management, and protecting data used by AI services. It succeeds SC-400, which Microsoft retired on 31 May 2025.

This certification is designed for information security administrators who protect sensitive data across Microsoft 365 collaboration environments. Candidates should have experience implementing data protection strategies using Microsoft Purview, including configuring DLP policies, sensitivity labels, retention, and compliance solutions for organizations subject to regulatory requirements.

Try five SC-401 questions

Try five practice questions from the app’s current Administering Information Security in Microsoft 365 question bank, with answers and explanations.

Implement information protection2 / 5

An administrator needs to configure a sensitivity label that prevents users from forwarding protected emails. Which encryption setting should be used?

AlexFull explanation from Alex

Do Not Forward is a predefined encryption option for sensitivity labels in Outlook. When applied, recipients cannot forward, print, or copy the email content. Unlike Encrypt-Only (which only encrypts without restricting actions), Do Not Forward enforces usage rights that block forwarding, Save As, and printing. Custom permissions with View Only rights would need manual configuration per recipient and don't auto-apply via label. Co-Author permissions grant editing rights, the opposite of protection. Do Not Forward also protects unencrypted Office attachments with the same restrictions automatically. Ref: learn.microsoft.com/purview/encryption-sensitivity-labels

Sourcelearn.microsoft.com

Implement information protection4 / 5

An administrator needs to implement exact data match (EDM) based sensitive information types to detect employee Social Security numbers in DLP policies. The SSN data is stored in a CSV file with columns for EmployeeName and SSN. Which step must be completed first before uploading the sensitive data table?

AlexFull explanation from Alex

Exact Data Match (EDM) sensitive information types compare content against a hashed table of real sensitive values, delivering near-zero false positives. The workflow requires defining the EDM schema first (column names and data types) before uploading the sensitive data table. The schema defines what fields exist (e.g., EmployeeName, SSN) and their data types, which the upload agent uses to parse and hash the source CSV. Without the schema, the system cannot interpret the uploaded data. A keyword dictionary (distractor) uses pattern matching, not exact value comparison. A trainable classifier uses ML on document samples, not structured data tables. Creating a DLP policy is a downstream step after the EDM SIT exists. Ref: learn.microsoft.com/purview/sit-create-edm-sit-unified-ux-workflow

Sourcelearn.microsoft.com

Implement data loss prevention and retention5 / 5

A compliance officer asks you to configure a DLP policy that protects documents labeled as 'Highly Confidential' regardless of what sensitive information they contain. The policy should block external sharing in SharePoint Online and OneDrive. How should you configure the DLP rule condition?

AlexFull explanation from Alex

Protecting documents with a specific sensitivity label regardless of content uses a DLP policy condition based on the sensitivity label rather than sensitive information types. Configure the DLP rule with condition: "Content contains sensitivity label: Highly Confidential." This triggers the policy whenever any document with that label is shared, regardless of what data the document contains. This approach protects the classification decision rather than the content — even if no sensitive information types are detected, the label itself triggers protection. Actions can include: block external sharing, block with override, require encryption, and notify. This complements content-based DLP rules — label-based rules protect based on human classification judgment, while SIT-based rules protect based on automated content detection. Exam tip: Sensitivity label as DLP condition = protect based on classification regardless of content; SIT condition = protect based on detected content — use both for comprehensive protection.

Sourcelearn.microsoft.com

436 practice questions

The Pass-IT question pool gives you material to practice for SC-401. A Pass-IT mock exam uses 50 questions and a 100-minute time limit; these are practice settings.

Pool details: SC-401

Exam details checked against MicrosoftAugust 28, 2026

date of the last check against the official Microsoft source

Passing score700 / 1,000

as published by Microsoft

Objectives in the guide74 objectives listed in the official guide

across 3 domains in the official exam guide

Pool size436 questions

= The pool size is equivalent to 8 sets of 50 questions; this does not mean that each mock exam uses a separate set.

Blueprint domains3 domains in the exam blueprint

Implement information protection 141 · Implement data loss prevention and retention 142 · Manage risks, alerts, and activities 153

Recorded as checked against sources436 of 436

questions recorded as having their answer, options, and explanation checked against official Microsoft documentation

What's on the exam

The three domains split almost exactly evenly, each landing in the 30–35% range — information protection (classification, sensitivity labels), data loss prevention and retention, and risk/alert/activity management all carry roughly a third of the exam.

That balance means no domain is safe to under-study: sensitivity-label priority and auto-labeling questions count for as much as DLP rule logic, and insider-risk policy templates and information-security alert triage count for as much as either. Candidates coming from SC-400 preparation will find the newest content sits inside risk management rather than as a section of its own: protecting the data that AI services consume.

Exam blueprint: SC-401

Implement information protection30–35%

Implement and manage data classification, implement and manage sensitivity labels in Microsoft Purview, and implement information protection for Windows, file shares, and Exchange

≈ 16 h
Implement data loss prevention and retention30–35%

Create and configure DLP policies, implement and monitor Microsoft Purview Endpoint DLP, and implement and manage retention

≈ 17 h
Manage risks, alerts, and activities30–35%

Implement and manage Microsoft Purview Insider Risk Management, manage information security alerts and activities, and protect data used by AI services

≈ 18 h

Exam format and question types

The exam draws 40–60 questions from a mix of multiple-choice, multiple-select, drag-and-drop, and hot-area formats inside a 100-minute window. Most items are scenario-based, presenting a data-protection requirement and asking you to configure the Microsoft Purview solution that meets it — a DLP rule, a sensitivity-label policy, a retention label, or an insider-risk indicator. Expect the eDiscovery content to stay narrow: SC-401 tests performing a search, not the legal-hold and review-set workflow that belonged to SC-400.

Question types: SC-401

Multiple Choice40%

Select the single answer that best meets the question’s requirements.

Drag & Drop15%

Move items into the slots, groups, or sequence specified by the task.

Multiple Response13%

Select multiple answers. Follow the question’s instructions on how many to choose.

Dropdown13%

Choose options from dropdown menus to complete a statement or configuration.

Ordering11%

Arrange the steps in the sequence needed to complete the process.

True / False8%

Decide whether a statement is true or false, paying attention to its conditions and wording.

See Microsoft for official question-format information. The shares shown describe the Pass-IT practice pool; they do not establish the proportions on the official exam.

Preparing for SC-401

The exam runs through Pearson VUE, either online with a remote proctor or at an authorized testing center, and is offered in English, German, French, Spanish, Portuguese, Japanese, and Chinese. Certification holds for one year, with a free renewal assessment on Learn starting six months before it expires; SC-400, the exam it succeeds, retired on 31 May 2025.

Preparation and logistics: SC-401

Preparation

Illustrative study time30–75 h

illustrative planning range: 30 h with relevant experience to 75 h when starting out; your needs may fall outside this range

LevelAssociate

Taking and maintaining the certification

DeliveryPearson VUE online proctored or at authorized testing centers worldwide
Retake policy24-hour wait after the first attempt, 14 days between subsequent attempts, maximum 5 attempts per exam within a 12-month period
Certification validity1 year

Free renewal assessment on Microsoft Learn, available starting 6 months before expiration. Must be completed before the certification expires.

Common pitfalls

Topics to review: SC-401

  1. 01Sensitivity Labels

    Not understanding sensitivity label priority, auto-labeling policies, and how labels interact across Exchange, SharePoint, and Teams.

  2. 02DLP Rule Logic

    Confusing DLP policy conditions, exceptions, and actions across different Microsoft 365 locations and endpoint DLP scenarios.

  3. 03Insider Risk

    Struggling with insider risk management policy templates, indicators, and the relationship between insider risk and communication compliance.

  4. 04Retention Policies

    Overlooking how retention policies and retention labels interact, and the difference between static and adaptive scopes.

  5. 05eDiscovery Workflow

    SC-401's eDiscovery scope is limited to running searches to locate content; legal hold, review sets, and export belong to a different administrator track and aren't tested here.

Frequently asked questions

How long is the Administering Information Security in Microsoft 365 exam?

The SC-401 exam has 50 questions and a 100-minute time limit.

What is the passing score for Administering Information Security in Microsoft 365?

The passing score for the SC-401 exam is 700 / 1000.

Which pitfalls should I review when preparing for Administering Information Security in Microsoft 365?

Topics to review include Sensitivity Labels, DLP Rule Logic, Insider Risk, Retention Policies, eDiscovery Workflow. Work through examples to check that you understand the distinctions and can explain your answer.

How long before SC-401 expires?

One year from the day you pass, like every Microsoft role-based certification. The free renewal assessment on Microsoft Learn opens six months before that date and has to be completed before it. If the window closes the certification lapses and the full exam is the only way back.

How is the SC-401 exam weighted?

The three areas are close to even: managing risks, alerts and activities at 35%, data loss prevention and retention at 33% and information protection at 32%. Nothing dominates. Insider risk and alert handling is the area people prepare least for, and it is the largest of the three.

What do you need before SC-401?

Microsoft sets no prerequisite. The catalog budget is around 50 hours, and the exam is written around the Microsoft Purview portal rather than around security theory. Access to a tenant with the relevant licences makes a large difference, because several features cannot be seen without them.

How does SC-401 differ from SC-200 and SC-300?

SC-401 is about protecting information: labels, data loss prevention, retention and insider risk inside Microsoft 365. SC-200 is about detecting and responding to attacks, and SC-300 is about identity and access. They are three different jobs rather than three levels, and none is a prerequisite for the others.

One certification, 12 months

Practice for SC-401

Focus your practice on one certification, or choose Pro to practice across all certifications.

Start a free practice sessionTry the first 20 questions without a card to see whether the practice suits you.

For eligible purchases: money-back guarantee if you fail your exam.

View guarantee terms →