CertSafari

    Free Practice Questions for Microsoft Certified: Information Security Administrator Associate (SC-401) Certification

    🔄 Last checked for updates September 6th, 2026

    Study with 351 exam-style practice questions designed to help you prepare for the Microsoft Certified: Information Security Administrator Associate (SC-401). All questions are aligned with the latest exam guide and include detailed explanations to help you master the material.

    Exam experiencesNew

    Pass and fail outcomes from candidates who prepared here — advice, scores, and prep time.

    View exam experiences

    Start Practicing

    All Domains

    Practice with randomly mixed questions from all topics

    Question MixAll Topics
    FormatRandom Order

    Domain Mode

    Practice questions from a specific topic area

    Quiz History

    Exam Details

    Key information about Microsoft Certified: Information Security Administrator Associate (SC-401)

    Official study guide

    View

    Question formats CertSafari offers
    • Multiple choice
    • Ordering
    • Matching
    • True/False
    prerequisites:

    Familiarity with all Microsoft 365 services, PowerShell, Microsoft Entra, the Microsoft Defender portal, and Microsoft Defender for Cloud Apps.

    target audience:

    Information security administrators responsible for planning and implementing information security of sensitive data using Microsoft Purview and related services.

    Exam Topics & Skills Assessed

    Skills measured (from the official study guide)

    Domain 1: Implement information protection

    Subdomain 1.1: Implement and manage data classification

    Identify sensitive information requirements for an organization's data

    - Translate sensitive information requirements into built-in or custom sensitive info types - Create and manage custom sensitive info types - Implement document fingerprinting - Create and manage exact data match based sensitive information types (EDM) - Create and manage trainable classifiers - Monitor data classification and label usage by using Data explorer and Content explorer - Configure optical character recognition (OCR) support for sensitive info types

    Subdomain 1.2: Implement and manage sensitivity labels in Microsoft Purview

    Implement roles and permissions for administering sensitivity labels

    - Define and create sensitivity labels for items and containers - Configure protection settings and content marking for sensitivity labels - Configure and manage publishing policies for sensitivity labels - Configure and manage auto-labeling policies for sensitivity labels - Apply a sensitivity label to containers, such as Microsoft Teams, Microsoft 365 Groups, Microsoft Power BI, and Microsoft SharePoint - Apply sensitivity labels by using Microsoft Defender for Cloud Apps

    Subdomain 1.3: Implement information protection for Windows, file shares, and Exchange

    Plan and implement the Microsoft Purview Information Protection client

    - Manage files by using the Microsoft Purview Information Protection client - Apply bulk classification to on-premises data by using the Microsoft Purview Information Protection scanner - Design and implement Microsoft Purview Message Encryption - Design and implement Microsoft Purview Advanced Message Encryption

    Domain 2: Implement data loss prevention and retention

    Subdomain 2.1: Create and configure data loss prevention policies

    Design data loss prevention policies based on an organization’s requirements

    - Implement roles and permissions for data loss prevention - Create and manage data loss prevention policies - Configure data loss prevention policies for Adaptive Protection - Interpret policy and rule precedence in data loss prevention - Create file policies in Microsoft Defender for Cloud Apps by using a DLP policy

    Subdomain 2.2: Implement and monitor Microsoft Purview Endpoint DLP

    Specify device requirements for Endpoint DLP, including extensions

    - Configure advanced DLP rules for devices in DLP policies - Configure Endpoint DLP settings - Configure just-in-time protection - Monitor endpoint activities

    Subdomain 2.3: Implement and manage retention

    Plan for information retention and disposition by using retention labels

    - Create, configure, and manage adaptive policy scopes - Create retention labels for data lifecycle management - Configure a retention label policy to publish labels - Configure a retention label policy to auto-apply labels - Interpret the results of policy precedence, including using Policy lookup - Create and configure retention policies - Recover retained content in Microsoft 365

    Domain 3: Manage risks, alerts, and activities

    Subdomain 3.1: Implement and manage Microsoft Purview Insider Risk Management

    Implement roles and permissions for Insider Risk Management

    - Plan and implement Insider Risk Management connectors - Plan and implement integration with Microsoft Defender for Endpoint - Configure and manage Insider Risk Management settings - Configure policy indicators - Select an appropriate policy template - Create and manage Insider Risk Management policies - Manage forensic evidence settings - Enable and configure insider risk levels for Adaptive Protection - Manage insider risk alerts and cases - Manage Insider Risk Management workflow, including notice templates

    Subdomain 3.2: Manage information security alerts and activities

    Assign Microsoft Purview Audit (Premium) user licenses

    - Investigate activities by using Microsoft Purview Audit - Configure audit retention policies - Analyze Purview activities by using Activity explorer - Respond to data loss prevention alerts in the Microsoft Purview portal - Investigate insider risk activities by using the Microsoft Purview portal - Respond to Purview alerts in Microsoft Defender XDR - Respond to Defender for Cloud Apps file policy alerts - Perform searches by using eDiscovery

    Subdomain 3.3: Protect data used by AI services

    Implement controls in Microsoft Purview to protect content in an environment that uses AI services

    - Implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services - Implement pre-requisites for Data Security Posture Management (DSPM) for AI - Manage roles and permissions for DSPM for AI - Configure DSPM for AI policies - Monitor activities in DSPM for AI

    Techniques & products

    Microsoft Purview
    Information Protection
    Data Classification
    Sensitive Information Types
    Custom Sensitive Info Types
    Document Fingerprinting
    Exact Data Match (EDM)
    Trainable Classifiers
    Data Explorer
    Content Explorer
    Optical Character Recognition (OCR)
    Sensitivity Labels
    Microsoft Teams
    Microsoft 365 Groups
    Microsoft Power BI
    Microsoft SharePoint
    Microsoft Defender for Cloud Apps
    Microsoft Purview Information Protection client
    Microsoft Purview Information Protection scanner
    Microsoft Purview Message Encryption
    Microsoft Purview Advanced Message Encryption
    Data Loss Prevention (DLP)
    Adaptive Protection
    Microsoft Purview Endpoint DLP
    Just-in-time protection
    Retention Labels
    Adaptive Policy Scopes
    Data Lifecycle Management
    Retention Policies
    Microsoft Purview Insider Risk Management
    Microsoft Defender for Endpoint
    Forensic Evidence
    Microsoft Purview Audit (Premium)
    Activity Explorer
    Microsoft Defender XDR
    eDiscovery
    AI Services
    Data Security Posture Management (DSPM) for AI
    Microsoft 365
    PowerShell
    Microsoft Entra

    CertSafari is not affiliated with, endorsed by, or officially connected to Microsoft Corporation. Full disclaimer