CertSafari

    Free Microsoft Certified: Information Security Administrator Associate (SC-401) Sample Questions

    35 free sample questions from our bank of 351+, covering every exam domain, with answers and detailed explanations. Updated September 2026.

    Domain 1: Implement information protection

    Subdomain 1.1: Implement and manage data classification

    1.Northwind Traders wants to create a document fingerprint sensitive information type from a standard non-disclosure agreement template. An administrator scans the paper template and saves it as a single image-only PDF, then uploads it as the fingerprint source. After testing, the fingerprint fails to detect any completed agreements. What is the most likely cause?

    1. A.Document fingerprinting cannot extract a word pattern from a file that contains only an image with no underlying text.
    2. B.The completed agreements exceed the 4 MB file size limit that applies to document fingerprint matching.
    3. C.The template file was still password protected when it was uploaded as the fingerprint source.
    4. D.The completed agreements were sent to recipients outside the organization instead of internal reviewers.
    Show answer & explanation

    Correct answer: ADocument fingerprinting cannot extract a word pattern from a file that contains only an image with no underlying text.

    • A. Document fingerprinting works by extracting the text pattern from the uploaded form; an image-only scan has no extractable text, so no fingerprint pattern can be created and no documents will ever match it.
    • B. A file size limit could block a large completed agreement, but the scenario describes a fingerprint that never matches anything at all, which points to the template's lack of extractable text rather than a size limit on completed files.
    • C. Password protection prevents Purview from scanning a document, but the scenario states the failure is total detection failure tied to the scanned image template, not a login or decryption issue on individual completed files.
    • D. The recipient's location does not affect whether document fingerprinting can recognize the underlying template text; the failure described here happens before any policy location logic is evaluated.

    Subdomain 1.1: Implement and manage data classification

    2.Endpoint DLP at Woodgrove Bank must detect sensitive information type matches inside images that employees embed in Word documents on managed Windows devices. Which setting must be enabled to allow this image-based scanning?

    1. A.Advanced classification scanning and protection, which enables optical character recognition for image content.
    2. B.The default endpoint DLP policy mode, since image scanning is enabled automatically for all devices.
    3. C.The Microsoft Purview Information Protection client, installed instead of the standard Office add-in.
    4. D.The exact data match upload agent, configured on each managed device that generates image content.
    Show answer & explanation

    Correct answer: AAdvanced classification scanning and protection, which enables optical character recognition for image content.

    • A. Advanced classification scanning and protection is the endpoint DLP setting that enables optical character recognition, allowing sensitive information type detection inside embedded images rather than only in extractable text.
    • B. Image-based scanning through OCR is not turned on by default; it specifically requires the advanced classification scanning and protection setting to be enabled for the endpoint DLP policy.
    • C. The Purview Information Protection client handles labeling and encryption for Office files but is not what enables optical character recognition scanning of images for endpoint DLP.
    • D. The EDM upload agent is used by administrators to upload hashed sensitive data tables to the service; it has no role in enabling OCR-based scanning of images on endpoint devices.

    Subdomain 1.1: Implement and manage data classification

    3.A records manager is evaluating whether to use a Microsoft-provided pretrained classifier or build a custom trainable classifier to identify board meeting minutes. Which two statements about trainable classifiers are accurate? (Choose 2.)(Select 2)

    1. A.Pretrained classifiers are ready to use immediately and do not need to be trained by the organization.
    2. B.Custom classifiers currently support training only on content written in English.
    3. C.Custom classifiers can be retrained after publishing simply by adding more sample documents to the same classifier.
    4. D.Trainable classifiers can evaluate the contents of encrypted items without any additional configuration.
    5. E.Pretrained classifiers must be seeded with the organization's own positive and negative sample documents before use.
    Show answer & explanation

    Correct answers: A, BPretrained classifiers are ready to use immediately and do not need to be trained by the organization.; Custom classifiers currently support training only on content written in English.

    • A. Correct: Microsoft-provided pretrained classifiers appear with a status of ready to use and do not require the organization to train them before applying them to policies.
    • B. Correct: support for building and training a custom classifier is currently limited to English-language content, which is an important constraint when planning classifiers for non-English document sets.
    • C. Incorrect: retraining a published custom classifier is not supported; improving one after publishing requires removing it and starting over with a new, larger sample set rather than adding samples to the existing one.
    • D. Incorrect: trainable classifiers only work with items that are not encrypted, so an encrypted item cannot be evaluated by a classifier without first being decrypted or otherwise made readable.
    • E. Incorrect: pretrained classifiers are already trained by Microsoft and do not need to be seeded with an organization's own sample documents; seeding with samples applies to building custom classifiers instead.

    Subdomain 1.1: Implement and manage data classification

    4.Which three of the following statements accurately describe optical character recognition support for sensitive information type detection in endpoint DLP? (Choose 3.)(Select 3)

    1. A.It is enabled as part of the advanced classification scanning and protection setting.
    2. B.Image files are subject to a 50 MB size limit when optical character recognition is enabled.
    3. C.Text files are subject to a 64 MB size limit for advanced classification scanning, separate from the image limit.
    4. D.It is enabled by default for every endpoint DLP policy with no additional configuration required.
    5. E.It removes all file size limits for advanced classification scanning once turned on.
    Show answer & explanation

    Correct answers: A, B, CIt is enabled as part of the advanced classification scanning and protection setting.; Image files are subject to a 50 MB size limit when optical character recognition is enabled.; Text files are subject to a 64 MB size limit for advanced classification scanning, separate from the image limit.

    • A. Correct: optical character recognition for endpoint DLP is enabled through the advanced classification scanning and protection setting, which also governs other advanced content-extraction behavior.
    • B. Correct: when optical character recognition is enabled, individual image files are limited to 50 MB for advanced classification scanning purposes.
    • C. Correct: text files have their own separate 64 MB size limit for advanced classification scanning, which applies even when the bandwidth limit is set to unlimited.
    • D. Incorrect: optical character recognition is not on by default; an administrator must explicitly enable advanced classification scanning and protection for endpoint DLP policies to use it.
    • E. Incorrect: enabling advanced classification scanning does not remove file size limits; the 64 MB text file limit and 50 MB image limit still apply even when bandwidth is set to unlimited.

    Subdomain 1.2: Implement and manage sensitivity labels in Microsoft Purview

    5.A Power BI report has acquired a parent label because a sublabel was later added under it. A user tries to export this report to PDF. What happens?

    1. A.The export fails, and the user needs to apply an appropriate sublabel to the report instead.
    2. B.The export succeeds, and the parent label is automatically converted to its default sublabel.
    3. C.The export succeeds, but the exported PDF has no label or protection applied.
    4. D.The export is blocked only if the parent label has encryption, but succeeds unprotected otherwise.
    Show answer & explanation

    Correct answer: AThe export fails, and the user needs to apply an appropriate sublabel to the report instead.

    • A. Exporting data from an item that has a parent label fails outright, and the documented fix is to apply a suitable sublabel to the item instead.
    • B. There's no automatic conversion to a default sublabel; the export simply fails until an admin or user manually applies a specific sublabel.
    • C. The export doesn't succeed unprotected; it fails entirely rather than producing an unlabeled file.
    • D. The export failure applies to parent labels generally, regardless of whether the parent label itself has encryption settings configured.

    Subdomain 1.2: Implement and manage sensitivity labels in Microsoft Purview

    6.Before turning on an auto-labeling policy for SharePoint and OneDrive, an admin reviews the prerequisites checklist to avoid a policy that runs without labeling anything. Which of the following are required?(Select 3)

    1. A.Auditing is turned on for Microsoft 365.
    2. B.Sensitivity labels are enabled for Office files in SharePoint and OneDrive.
    3. C.The auto-labeling rule includes at least one non-EDM sensitive information type.
    4. D.The tenant has purchased a dedicated auto-labeling add-on license.
    5. E.Every target site has been manually pre-labeled by an administrator.
    6. F.The policy is configured to run in simulation mode permanently.
    Show answer & explanation

    Correct answers: A, B, CAuditing is turned on for Microsoft 365.; Sensitivity labels are enabled for Office files in SharePoint and OneDrive.; The auto-labeling rule includes at least one non-EDM sensitive information type.

    • A. Auditing must be turned on for Microsoft 365 because simulation mode depends on the audit log to record and display matches.
    • B. Sensitivity labels must be enabled for Office files in SharePoint and OneDrive before any label, automatic or manual, can be applied to files in those locations.
    • C. A rule that relies only on EDM-based sensitive information types silently disables auto-labeling for the label, so at least one non-EDM sensitive information type is required.
    • D. Auto-labeling is included with existing E5-tier or P2-tier licensing rather than requiring a separate dedicated add-on license.
    • E. Auto-labeling exists specifically to apply labels automatically; requiring sites to already be manually pre-labeled would defeat its purpose.
    • F. Simulation mode is a required first step, not a permanent state; the policy must eventually be turned on to actually apply labels.

    Subdomain 1.2: Implement and manage sensitivity labels in Microsoft Purview

    7.Which Power BI content types can have a sensitivity label applied directly in the Power BI service?(Select 3)

    1. A.Reports.
    2. B.Dashboards.
    3. C.Dataflows.
    4. D.Excel workbooks stored in OneDrive.
    5. E.Azure SQL databases.
    6. F.Power Automate flows.
    Show answer & explanation

    Correct answers: A, B, CReports.; Dashboards.; Dataflows.

    • A. Reports are one of the Power BI content types that support a directly applied sensitivity label in the service.
    • B. Dashboards also support a directly applied sensitivity label in the Power BI service.
    • C. Dataflows are included among the Power BI content types that support sensitivity labels.
    • D. Excel workbooks aren't currently available for direct sensitivity labeling within the Power BI service's supported content types.
    • E. Azure SQL databases have their own separate data discovery and classification feature, not the Power BI service's sensitivity label feature.
    • F. Power Automate flows aren't a labeled content type in Power BI; they may consume labeled data but don't carry their own sensitivity label.

    Subdomain 1.2: Implement and manage sensitivity labels in Microsoft Purview

    8.Which of the following are true about using Microsoft Defender for Cloud Apps to apply Microsoft Purview sensitivity labels?(Select 3)

    1. A.The sensitivity label must already be published as part of a label policy before Defender for Cloud Apps can apply it.
    2. B.Applying labels this way requires both a Defender for Cloud Apps license and a Microsoft Purview license.
    3. C.Supported apps for this capability currently include Box, Google Workspace, SharePoint Online, and OneDrive.
    4. D.Any sensitivity label can be selected as a session policy action, regardless of its encryption configuration.
    5. E.Defender for Cloud Apps applies labels to every connected cloud app automatically, with no per-app support list.
    6. F.This label-application capability is available for files stored in Dropbox and Slack.
    Show answer & explanation

    Correct answers: A, B, CThe sensitivity label must already be published as part of a label policy before Defender for Cloud Apps can apply it.; Applying labels this way requires both a Defender for Cloud Apps license and a Microsoft Purview license.; Supported apps for this capability currently include Box, Google Workspace, SharePoint Online, and OneDrive.

    • A. A file policy can only apply a label that's already been published as part of a sensitivity label policy in Microsoft Purview.
    • B. This integration requires both a Defender for Cloud Apps license and a Microsoft Purview license to function.
    • C. The documented supported apps for this label-application capability are Box, Google Workspace, SharePoint Online, and OneDrive.
    • D. Only labels configured with encryption settings appear as an available action in a session policy, so not every label qualifies.
    • E. Support for applying labels is limited to a specific set of connected apps, not every cloud app connected to Defender for Cloud Apps.
    • F. Dropbox and Slack aren't among the currently supported apps for this label-application capability; support is limited to Box, Google Workspace, SharePoint Online, and OneDrive.

    Subdomain 1.3: Implement information protection for Windows, file shares, and Exchange

    9.An engineer at Fabrikam applies a sensitivity label with encryption to a Visio (.vsd) diagram using the Purview Information Protection client. Because Visio diagrams don't support native rights-management encryption, the client applies generic encryption and renames the file with a .pvsd extension. To make sure the engineer can still open and edit the file normally after protection is applied, what should the administrator do?

    1. A.Configure the label to skip encryption entirely for any file type that only supports generic encryption.
    2. B.Convert the Visio file to PDF format before labeling so native encryption can be applied instead.
    3. C.Assign the engineer the co-owner usage right on the label so full access to the generically encrypted file is retained.
    4. D.Disable generic encryption tenant-wide so only natively supported file types can ever be protected.
    Show answer & explanation

    Correct answer: CAssign the engineer the co-owner usage right on the label so full access to the generically encrypted file is retained.

    • A. Incorrect: skipping encryption for all such file types would remove the protection the label is meant to provide, rather than preserving the engineer's ability to access an encrypted copy.
    • B. Incorrect: converting the file to a different format changes the deliverable the engineer needs and isn't how generic encryption compatibility for a file type is addressed.
    • C. Correct: for file types that only support generic encryption, assigning the co-owner permission is recommended so the authorized user retains full access and can keep working with the protected file.
    • D. Incorrect: disabling generic encryption tenant-wide would remove protection from every file type that isn't natively supported, not just fix access for this one file.

    Subdomain 1.3: Implement information protection for Windows, file shares, and Exchange

    10.Northwind Traders is about to configure automatic labeling in a content scan job for the Microsoft Purview Information Protection scanner. Before enforcing labels across a large file share, the compliance team wants to see what would be labeled without actually changing any files. Which scanner mode should they use first?

    1. A.Enforce mode, which immediately applies labels and protection to every matched file.
    2. B.Continuous scanning mode, which relabels files every time they are modified.
    3. C.Cluster mode, which distributes the scan workload across multiple scanner nodes.
    4. D.Discovery mode, which reports what would happen without applying labels to any files.
    Show answer & explanation

    Correct answer: DDiscovery mode, which reports what would happen without applying labels to any files.

    • A. Incorrect: enforce behavior would immediately apply labels and, if configured, encryption to matching files, which is the risky outcome the team wants to avoid until they've reviewed the report.
    • B. Incorrect: the scanner does not label files in real time as they change; it periodically crawls data stores on a configured cycle, so there is no continuous relabeling mode to select.
    • C. Incorrect: distributing work across multiple nodes is about scaling scan performance for large repositories, not about previewing labeling results before enforcement.
    • D. Correct: running the scanner in discovery mode only produces reports showing what would be labeled and protected, without changing any files, which is exactly what's needed before enforcing labels broadly.

    Subdomain 1.3: Implement information protection for Windows, file shares, and Exchange

    11.What is the minimum version of Windows PowerShell required to use the PowerShell module for the Microsoft Purview Information Protection client?

    1. A.Windows PowerShell 4.0
    2. B.Windows PowerShell 2.0
    3. C.Windows PowerShell 5.1
    4. D.Windows PowerShell 3.0
    Show answer & explanation

    Correct answer: AWindows PowerShell 4.0

    • A. Correct: the PowerShell module for the client requires a minimum version of Windows PowerShell 4.0, and older operating systems may need this version installed manually.
    • B. Incorrect: PowerShell 2.0 predates the minimum version supported by the client's PowerShell module and does not meet the documented requirement.
    • C. Incorrect: PowerShell 5.1 is newer than the documented minimum and would work, but it is not the lowest version required, so it isn't the correct answer to a minimum-version question.
    • D. Incorrect: PowerShell 3.0 is below the documented minimum version of 4.0 required for the client's PowerShell module.

    Subdomain 1.3: Implement information protection for Windows, file shares, and Exchange

    12.The Microsoft Purview Information Protection client relies on sensitivity labels built into Office, rather than including its own Office Add-in, for labeling inside Word, Excel, and PowerPoint. True or False?

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: ATrue

    • A. Correct: there's no Office Add-in included with the client, because labeling inside Office apps is handled by the sensitivity labels that are built into Office rather than by an add-in from this client.
    • B. Incorrect: the client genuinely doesn't include its own Office Add-in; in-app labeling in Word, Excel, and PowerPoint comes from the sensitivity labels built into Office instead.

    Domain 2: Implement data loss prevention and retention

    Subdomain 2.1: Create and configure data loss prevention policies

    13.A retailer wants a DLP policy that stops employees from emailing payment card data to external recipients, but still lets an employee proceed if they provide a business justification, which should be logged for later review. Which configuration best matches this requirement?

    1. A.Configure a rule with a block action that includes an override and requires a written justification
    2. B.Configure a rule with a block action that has no override option so the message can never be delivered externally
    3. C.Configure a rule with an audit-only action that records the activity without interrupting mail delivery
    4. D.Configure a rule that only shows a policy tip without any block action, leaving the choice entirely to the user
    Show answer & explanation

    Correct answer: AConfigure a rule with a block action that includes an override and requires a written justification

    • A. A block-with-override rule stops the send by default but lets the user justify continuing, and that justification is captured for review, matching the requirement exactly.
    • B. A block-without-override rule permanently prevents the send with no way for the user to proceed, which is more restrictive than the scenario allows.
    • C. Audit-only logs the activity for visibility but never actually blocks the message, so it wouldn't stop the initial attempt as required.
    • D. A tip-only rule warns the user but doesn't block anything, so external delivery would proceed without any enforcement or captured justification.

    Subdomain 2.1: Create and configure data loss prevention policies

    14.True or False: For DLP policies applied to hosted locations such as Exchange and SharePoint, when content matches multiple rules, the highest-priority matching rule's action is enforced while every match is still logged.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: ATrue

    • A. Correct — hosted-location evaluation applies the action from the highest-priority matching rule, while every rule that matched is still recorded for reporting.
    • B. This is incorrect — hosted locations do follow exactly this first-match, most-restrictive-wins behavior, with all matches still logged regardless of which single action is enforced.

    Subdomain 2.1: Create and configure data loss prevention policies

    15.True or False: A file policy in Microsoft Defender for Cloud Apps scans existing content as well as newly created content, but only the governance action of the first policy it matches is guaranteed to apply.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: ATrue

    • A. Correct — file policies continuously scan both content already at rest and newly created content, and only the first matching policy's governance action is guaranteed to take effect on a given file.
    • B. This is incorrect — file policies do scan existing and new content continuously, and the single-first-match governance behavior is an accurate, documented limitation.

    Subdomain 2.2: Implement and monitor Microsoft Purview Endpoint DLP

    16.An admin onboards several Windows Server 2019 machines into Microsoft Purview using Microsoft Defender for Endpoint, expecting Endpoint DLP events to appear in Activity explorer. No events show up for the servers even though file activity is occurring. What is the most likely cause?

    1. A.The servers are missing the Microsoft Purview Chrome Extension for browsers
    2. B.The servers were onboarded as Domain Controllers, which blocks all classification
    3. C.Activity explorer only displays events from Windows 10 and 11 client devices
    4. D.Endpoint DLP isn't enabled by default for Windows servers after onboarding
    Show answer & explanation

    Correct answer: DEndpoint DLP isn't enabled by default for Windows servers after onboarding

    • A. Incorrect: the Chrome extension governs browser-based upload enforcement and has no bearing on whether server file activity reaches Activity explorer.
    • B. Incorrect: the scenario doesn't indicate the servers are Domain Controllers, and that specific server role is a separate blocking condition, not the default-state explanation here.
    • C. Incorrect: Activity explorer can display events from properly configured Windows servers as well as Windows 10 and 11 endpoints, so device type alone isn't the limiting factor.
    • D. Correct: Endpoint DLP is not turned on by default for Windows servers even after they're onboarded through Defender for Endpoint; an admin must explicitly enable it before server events populate Activity explorer.

    Subdomain 2.2: Implement and monitor Microsoft Purview Endpoint DLP

    17.Before enabling just-in-time protection across its Windows fleet, an admin wants to confirm devices meet the minimum prerequisite. Which requirement must be met first?

    1. A.Devices must have Endpoint DLP file path exclusions already configured
    2. B.Devices must run Microsoft Defender antimalware client version 4.18.23080 or later
    3. C.Devices must be enrolled in Microsoft Intune for compliance reporting
    4. D.Devices must have completed a full content scan job at least once
    Show answer & explanation

    Correct answer: BDevices must run Microsoft Defender antimalware client version 4.18.23080 or later

    • A. Incorrect: file path exclusions are an optional fine-tuning setting for JIT, not a prerequisite that must exist before JIT can be enabled at all.
    • B. Correct: just-in-time protection requires devices to run at least antimalware client version 4.18.23080, and devices below this version need a specific KB installed to disable JIT instead.
    • C. Incorrect: Intune enrollment relates to device management and compliance reporting generally, not to the antimalware client version JIT protection depends on.
    • D. Incorrect: JIT protection doesn't require a prior content scan job; it evaluates files as they're accessed rather than depending on a one-time scan being completed.

    Subdomain 2.2: Implement and monitor Microsoft Purview Endpoint DLP

    18.Which of the following are configurable under Data loss prevention settings > Endpoint settings in the Microsoft Purview portal? (Choose 3.)(Select 3)

    1. A.Unallowed browsers
    2. B.Sensitive service domain groups
    3. C.Retention label disposition review
    4. D.Restricted apps and app groups
    5. E.eDiscovery hold notifications
    6. F.Insider risk management policy indicators
    Show answer & explanation

    Correct answers: A, B, DUnallowed browsers; Sensitive service domain groups; Restricted apps and app groups

    • A. Correct: the unallowed browsers list is one of the Endpoint settings used to restrict which browser executables can access protected files.
    • B. Correct: sensitive service domain groups are configured under Endpoint settings to define destinations restricted for uploads by DLP rules.
    • C. Incorrect: disposition review is part of retention label configuration, a separate area of Purview from Endpoint DLP settings.
    • D. Correct: restricted apps and app groups are configured under Endpoint settings to control which applications can access protected files.
    • E. Incorrect: eDiscovery hold notifications belong to the eDiscovery solution, not to Endpoint DLP settings.
    • F. Incorrect: insider risk policy indicators are configured within insider risk management, a separate Purview solution from Endpoint DLP settings.

    Subdomain 2.2: Implement and monitor Microsoft Purview Endpoint DLP

    19.True or False: Endpoint DLP is not supported on Windows Servers that are configured as Domain Controllers.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: ATrue

    • A. Correct: Endpoint DLP explicitly isn't supported on Windows Servers configured as Domain Controllers, or on servers using the Core Server installation option.
    • B. Incorrect: this restriction is explicitly documented, so a statement saying Endpoint DLP isn't supported on Domain Controllers is accurate, not false.

    Subdomain 2.3: Implement and manage retention

    20.A records manager is deciding when the retention period should begin for different retention labels across the organization. Which statements about the start of the retention period are accurate? (Select all that apply)(Select 4)

    1. A.The default start of the retention period is when the content was created
    2. B.For files in SharePoint, OneDrive, and Microsoft 365 Groups, the retention period can instead start from when the content was last modified
    3. C.The retention period can be configured to start when the content is labeled, for SharePoint, OneDrive, and email items
    4. D.The retention period can be configured to start when a defined event occurs, such as an employee leaving the organization
    5. E.Once configured, the start-of-period setting for a retention label can never be changed under any circumstances
    Show answer & explanation

    Correct answers: A, B, C, DThe default start of the retention period is when the content was created; For files in SharePoint, OneDrive, and Microsoft 365 Groups, the retention period can instead start from when the content was last modified; The retention period can be configured to start when the content is labeled, for SharePoint, OneDrive, and email items; The retention period can be configured to start when a defined event occurs, such as an employee leaving the organization

    • A. When content was created is documented as the default configuration for when the retention period begins, unless an alternative start condition is explicitly configured.
    • B. For files in SharePoint, OneDrive, and Microsoft 365 Groups locations, the retention period can be configured to start based on when the content was last modified instead of when it was created.
    • C. Starting the retention period from when the content was labeled is a supported option for documents in SharePoint sites and OneDrive accounts, and for email items.
    • D. Event-based retention lets the period start when a defined event occurs, such as an employee's departure or a contract's expiration, rather than from a fixed content date.
    • E. The retention period value itself is one of the few settings that remains editable after the label and policy are created and saved, so the start-of-period configuration is not permanently frozen in every case.

    Subdomain 2.3: Implement and manage retention

    21.An administrator configures a new retention policy and must decide between an adaptive scope and a static scope for targeting users. Which factors correctly describe advantages of choosing an adaptive scope over a static scope? (Select all that apply)(Select 3)

    1. A.New users matching the query criteria are picked up automatically without reconfiguring the policy
    2. B.There is no administrative overhead of creating and maintaining a group to represent the target population
    3. C.The policy scope updates in real time the moment a user's attribute changes
    4. D.Adaptive scopes support Preservation Lock so the scope itself can be locked from changes
    5. E.A single policy can more flexibly target users based on attributes like department or country without needing per-user configuration
    Show answer & explanation

    Correct answers: A, B, ENew users matching the query criteria are picked up automatically without reconfiguring the policy; There is no administrative overhead of creating and maintaining a group to represent the target population; A single policy can more flexibly target users based on attributes like department or country without needing per-user configuration

    • A. Because adaptive scopes use a dynamic query against Entra attributes, new users who match the criteria are automatically included without any policy reconfiguration, which is a genuine advantage.
    • B. Adaptive scopes remove the need to create and maintain a dedicated group just to represent the target population, reducing administrative overhead compared to a static scope.
    • C. The dynamic query underlying an adaptive scope runs once daily, not in real time, so changes to a user's attributes are not reflected immediately.
    • D. Adaptive scopes do not currently support Preservation Lock, so this is not an advantage; only statically scoped retention policies can be locked today.
    • E. Adaptive scopes let administrators target users flexibly by attributes such as department or country or region without configuring individual users or maintaining group membership, which is a core benefit.

    Subdomain 2.3: Implement and manage retention

    22.A compliance administrator is planning a phased rollout of an auto-apply retention label policy that uses a sensitive information type condition. Which statements about simulation mode for this scenario are accurate? (Select all that apply)(Select 3)

    1. A.Simulation results automatically expire within seven days after the simulation completes
    2. B.A maximum of 30 simulation jobs can be active across the tenant in a 12-hour period
    3. C.Simulation is mandatory and the policy cannot be turned on until simulation has been approved
    4. D.Simulation for Exchange runs against emails already stored in mailboxes even though auto-apply for sensitive information types normally only labels items in transit
    5. E.Simulation mode is only available for the trainable classifier condition, not for sensitive information types
    Show answer & explanation

    Correct answers: A, B, DSimulation results automatically expire within seven days after the simulation completes; A maximum of 30 simulation jobs can be active across the tenant in a 12-hour period; Simulation for Exchange runs against emails already stored in mailboxes even though auto-apply for sensitive information types normally only labels items in transit

    • A. Once a simulation completes, its results automatically expire within seven days, after which the administrator must restart the simulation to view samples again.
    • B. There is a documented maximum of 30 active simulation jobs permitted across the tenant within any 12-hour time period.
    • C. Simulation is optional for this scenario; an administrator can turn on the policy for production even while a simulation is still running, so it is not a mandatory gate.
    • D. Although sensitive information type auto-apply for Exchange normally only labels items sent or received rather than existing mail, simulation intentionally runs against historical emails already stored in mailboxes so administrators can quickly assess effectiveness using existing data.
    • E. Simulation mode is available for both the sensitive information type condition and the keyword or searchable property condition, not exclusively for trainable classifiers.

    Subdomain 2.3: Implement and manage retention

    23.A records manager is troubleshooting why several documents that should have received an auto-applied retention label have not been labeled after the policy was turned on three days ago. Which explanations are valid reasons the labels may not yet have appeared? (Select all that apply)(Select 3)

    1. A.It can take up to seven days for auto-applied retention labels to take effect after conditions are met
    2. B.The documents already have a different retention label applied, since only unlabeled content is eligible for auto-labeling
    3. C.The policy uses an adaptive scope whose dynamic query can take up to five days to fully populate membership
    4. D.Auto-apply retention label policies never label existing content, only content created after the policy is turned on
    5. E.The retention label referenced by the policy was deleted from the tenant after the policy was created
    Show answer & explanation

    Correct answers: A, B, CIt can take up to seven days for auto-applied retention labels to take effect after conditions are met; The documents already have a different retention label applied, since only unlabeled content is eligible for auto-labeling; The policy uses an adaptive scope whose dynamic query can take up to five days to fully populate membership

    • A. Microsoft documents that it can take up to seven days for auto-applied retention labels to appear on matching content after conditions such as sensitive information types or keywords are met, so three days may simply not be enough time yet.
    • B. Only content that isn't already labeled is eligible for auto-applying a retention label, so documents that already carry a different label from another source would correctly be skipped by this policy.
    • C. When an adaptive scope is used, its dynamic query can take up to five days to fully populate, so locations that haven't yet been added to the scope's resolved membership would not receive the label.
    • D. Depending on the condition type, auto-apply policies can label both newly created or modified items and existing items at rest, such as sensitive information types applied to existing SharePoint and OneDrive content already classified, so this blanket statement is incorrect.
    • E. A retention label cannot be deleted while it remains included in any retention label policy, so this scenario is not possible as a valid explanation for missing labels.

    Domain 3: Manage risks, alerts, and activities

    Subdomain 3.1: Implement and manage Microsoft Purview Insider Risk Management

    24.An Insider Risk Management administrator wants to detect data theft by departing users, but the organization has not configured a Microsoft 365 HR connector. Which triggering option lets the Data theft by departing users template still start scoring risk for a departing employee?

    1. A.Select the option to detect account deletion in Microsoft Entra ID
    2. B.Enable the Risky AI usage template as a substitute trigger
    3. C.Configure a Communication Compliance disgruntlement policy
    4. D.Turn on the physical badging connector
    Show answer & explanation

    Correct answer: ASelect the option to detect account deletion in Microsoft Entra ID

    • Select the option to detect account deletion in Microsoft Entra ID. This template supports account deletion in Microsoft Entra ID as an alternate triggering event when no HR connector is configured.
    • Enable the Risky AI usage template as a substitute trigger. This template detects risky AI prompts and browsing, not departure events, so it cannot substitute for the departing users trigger.
    • Configure a Communication Compliance disgruntlement policy. This integration surfaces threatening or discriminatory message content and is used by the risky-user templates, not the departing users template.
    • Turn on the physical badging connector. This connector correlates badge access with activity but does not provide the resignation or termination signal this template needs.

    Subdomain 3.1: Implement and manage Microsoft Purview Insider Risk Management

    25.An administrator creates a policy from the Security policy violations template, but no alerts appear even though users have disabled endpoint protection features. What is most likely missing?

    1. A.Defender for Endpoint integration with Microsoft Purview has not been enabled
    2. B.The HR connector has not imported termination dates
    3. C.The policy is missing a priority user group assignment
    4. D.The Communication Compliance integration has not been configured
    Show answer & explanation

    Correct answer: ADefender for Endpoint integration with Microsoft Purview has not been enabled

    • Defender for Endpoint integration with Microsoft Purview has not been enabled. This template requires an active Defender for Endpoint subscription with integration enabled so security alerts can be imported as triggering events.
    • The HR connector has not imported termination dates. Termination dates matter for the departing-users variant of this template, not the base Security policy violations template.
    • The policy is missing a priority user group assignment. Priority user groups are required only for the priority-users variant of this template, not the general Security policy violations template.
    • The Communication Compliance integration has not been configured. Communication Compliance integration is used for the risky-users variant of security policy templates, not the base template described here.

    Subdomain 3.1: Implement and manage Microsoft Purview Insider Risk Management

    26.An investigator wants to automatically post updates to a case's notes and retrieve user and alert information for stakeholders without manual data entry. Which Insider Risk Management setting supports this automation?

    1. A.Power Automate flows
    2. B.Detection groups
    3. C.Global exclusions
    4. D.Admin notifications
    Show answer & explanation

    Correct answer: APower Automate flows

    • Power Automate flows. This setting lets Insider Risk Management retrieve user, alert, and case information and automate tasks such as posting updates to case notes.
    • Detection groups. This setting creates variants of built-in indicators for different sets of users and has no relation to automating case updates.
    • Global exclusions. This setting excludes specific users, sites, or domains from scoring and does not automate case note updates.
    • Admin notifications. This setting sends email alerts to role groups about new or high-severity alerts, rather than automating case-level data retrieval.

    Subdomain 3.1: Implement and manage Microsoft Purview Insider Risk Management

    27.Which of the following actions can members of the Insider Risk Management Admins role group perform? (Select all that apply)(Select 3)

    1. A.Configure policies and global settings
    2. B.Create a forensic evidence capturing request
    3. C.Access and investigate alerts and cases
    4. D.Configure Adaptive Protection
    5. E.View and export audit logs
    Show answer & explanation

    Correct answers: A, B, DConfigure policies and global settings; Create a forensic evidence capturing request; Configure Adaptive Protection

    • Configure policies and global settings. This role group is responsible for configuring Insider Risk Management policies and the global settings that apply across them.
    • Create a forensic evidence capturing request. This role group can create a forensic evidence capturing request, although a separate Approver must approve it before capturing starts.
    • Access and investigate alerts and cases. This capability belongs to the Insider Risk Management, Analysts, and Investigators role groups, not the Admins role group.
    • Configure Adaptive Protection. This role group can configure Adaptive Protection and update its settings alongside the broader Insider Risk Management role group.
    • View and export audit logs. This capability is reserved for the Insider Risk Management Auditors role group, not the Admins role group.

    Subdomain 3.2: Manage information security alerts and activities

    28.An administrative unit restricted admin in Microsoft Purview can view DLP alerts for every administrative unit in the tenant, not just their own.

    1. A.True
    2. B.False
    Show answer & explanation

    Correct answer: BFalse

    • A. This would be incorrect, since administrative unit restrictions limit visibility to only the assigned unit, not the whole tenant.
    • B. This is accurate: administrative unit restrictions flow into DLP, so a restricted admin only sees alerts scoped to their own assigned unit.

    Subdomain 3.2: Manage information security alerts and activities

    29.A DLP policy protecting financial data generates alerts whenever a new email containing a match is sent, but never for old messages already sitting in mailboxes, while SharePoint and OneDrive alerts include both new and pre-existing files. What explains this difference?

    1. A.In Exchange, DLP only scans new email messages, while SharePoint and OneDrive DLP scans both existing and newly created items.
    2. B.Exchange DLP alerts are disabled by default and must be manually turned on for existing messages.
    3. C.SharePoint and OneDrive use a different DLP engine that ignores email entirely, so the comparison is invalid.
    4. D.The policy was scoped only to SharePoint and OneDrive, so any Exchange results are unexpected noise.
    Show answer & explanation

    Correct answer: AIn Exchange, DLP only scans new email messages, while SharePoint and OneDrive DLP scans both existing and newly created items.

    • A. Correct: Exchange DLP evaluates new mail as it flows through the service, while SharePoint and OneDrive DLP scans both existing stored items and newly created ones, which explains exactly this pattern.
    • B. Incorrect: Exchange DLP alerting isn't disabled by default; the behavior described is a documented scanning-scope difference, not a toggle left off.
    • C. Incorrect: SharePoint, OneDrive, and Exchange all use the same underlying DLP policy engine and sensitive information type detection, just applied to different content scanning models.
    • D. Incorrect: the scenario states the policy is generating alerts for new email too, so Exchange isn't out of scope; the difference is about scan timing, not location scope.

    Subdomain 3.2: Manage information security alerts and activities

    30.During an insider risk case review, an investigator concludes that a user accidentally violated policy by sharing a document with the wrong internal group, with no malicious intent. What is the most proportionate next action?

    1. A.Send the user a reminder notice from a customizable notice template.
    2. B.Escalate the case to eDiscovery (Premium) for legal hold and export.
    3. C.Immediately disable the user's account pending further review.
    4. D.Export the case to a SIEM for security incident response handling.
    Show answer & explanation

    Correct answer: ASend the user a reminder notice from a customizable notice template.

    • A. Correct: for accidental, non-malicious violations, sending a reminder notice from a notice template is the documented proportionate action to raise awareness without escalating.
    • B. Incorrect: escalating to eDiscovery (Premium) is reserved for more serious situations requiring legal case handling, not a minor accidental violation.
    • C. Incorrect: disabling the account is a disproportionate response to an inadvertent, non-malicious mistake and isn't the standard first action.
    • D. Incorrect: exporting to a SIEM is meant for broader security monitoring integration, not for addressing a single minor internal policy slip.

    Subdomain 3.2: Manage information security alerts and activities

    31.Which locations can a Microsoft Purview DLP policy for Enterprise applications & devices monitor? (Select all that apply.)(Select 3)

    1. A.Exchange Online email
    2. B.Teams chat and channel messages
    3. C.Windows and macOS endpoint devices
    4. D.On-premises network firewalls
    5. E.Domain controller security event logs
    Show answer & explanation

    Correct answers: A, B, CExchange Online email; Teams chat and channel messages; Windows and macOS endpoint devices

    • A. Correct: Exchange Online email is a documented location that Enterprise applications & devices DLP policies can monitor.
    • B. Correct: Teams chat and channel messages are also a supported monitored location for this policy type.
    • C. Correct: Windows 10, Windows 11, and the three most recent macOS versions are supported endpoint device locations for DLP.
    • D. Incorrect: network firewalls aren't a DLP-monitored location; DLP works at the application and endpoint layer, not on firewall infrastructure.
    • E. Incorrect: domain controller security logs are outside the set of DLP-monitored locations, which focus on Microsoft 365 services, devices, and connected apps.

    Subdomain 3.3: Protect data used by AI services

    32.Contoso applies a 'Highly Confidential' sensitivity label to its most sensitive files and wants Microsoft 365 Copilot and Copilot Chat to stop referencing the content of any file carrying that label when generating a response. Which DLP configuration meets this requirement?

    1. A.A policy scoped to the Microsoft 365 Copilot and Copilot Chat location with a content contains sensitivity labels condition and the prevent Copilot from processing content action
    2. B.A policy scoped to the SharePoint and OneDrive locations with a content contains sensitivity labels condition and a block external sharing action
    3. C.An auto-labeling policy that reapplies the Highly Confidential label to any file Copilot references during a session
    4. D.A retention policy that deletes Highly Confidential files after they have been referenced by Copilot
    Show answer & explanation

    Correct answer: AA policy scoped to the Microsoft 365 Copilot and Copilot Chat location with a content contains sensitivity labels condition and the prevent Copilot from processing content action

    • A. This is correct because the Microsoft 365 Copilot and Copilot Chat location is the only DLP location that can inspect an item's sensitivity label and prevent Copilot from using its content in a response.
    • B. This is incorrect because a SharePoint and OneDrive location policy governs external sharing of the file itself, not whether Copilot can reference its content when generating an answer.
    • C. This is incorrect because reapplying a label doesn't stop Copilot from reading the file's content; the label needs to be paired with a DLP action targeting the Copilot location.
    • D. This is incorrect because deleting the file removes it from the organization entirely and doesn't selectively control Copilot's use of its content beforehand.

    Subdomain 3.3: Protect data used by AI services

    33.A user pastes a credit card number directly into the Copilot chat pane in Word. The organization wants Copilot to refuse to answer any prompt containing that kind of data, rather than merely limiting where it searches for grounding information. Which DLP condition-and-action pair achieves this?

    1. A.Content contains sensitive information types, with the action set to prevent Copilot from processing prompts
    2. B.Content contains sensitive information types, with the action set to prevent performing web searches
    3. C.Content contains sensitivity labels, with the action set to prevent Copilot from processing content
    4. D.Email is received from external users, with the action set to prevent Copilot from processing content
    Show answer & explanation

    Correct answer: AContent contains sensitive information types, with the action set to prevent Copilot from processing prompts

    • A. This is correct because this pairing inspects the prompt text itself and stops Copilot from returning any response at all when the configured sensitive information types are present.
    • B. This is incorrect because this pairing still lets Copilot answer using internal sources; it only removes external web search as a grounding option.
    • C. This is incorrect because this pairing evaluates file and email classification, not text typed directly into a prompt, so a pasted credit card number wouldn't trigger it.
    • D. This is incorrect because this pairing is about excluding external email from grounding, not about scanning prompt text for sensitive data.

    Subdomain 3.3: Protect data used by AI services

    34.An admin has the Purview Data Security AI Admin role and needs to edit a DLP policy for the Microsoft 365 Copilot and Copilot Chat location. They also try to open Activity explorer to read the prompt and response text behind an AI interaction event. What happens?

    1. A.They can edit the DLP policy, but they cannot read the prompt and response text without an additional content-viewing role
    2. B.They can edit the DLP policy and automatically read all prompt and response text as part of the same role
    3. C.They cannot edit the DLP policy or read any prompt and response text with this role alone
    4. D.They can read the prompt and response text, but they cannot edit the DLP policy with this role
    Show answer & explanation

    Correct answer: AThey can edit the DLP policy, but they cannot read the prompt and response text without an additional content-viewing role

    • A. This is correct because this role is specifically documented as being able to edit DLP policies for Copilot and view AI content in DSPM for AI, but without access to read prompts and responses of AI interactions.
    • B. This is incorrect because reading prompt and response text is explicitly excluded from this role and requires a separate content-viewing role.
    • C. This is incorrect because this role does grant DLP policy editing rights for the Copilot location, so policy editing is not blocked.
    • D. This is incorrect because this role's documented strength is DLP policy editing, while prompt and response reading is the part that's excluded, not the other way around.

    Subdomain 3.3: Protect data used by AI services

    35.Which Microsoft Graph application permissions are part of the required set for the Entra app registration used in Microsoft 365 item-level scanning for data risk assessments? (Select all that apply.)(Select 3)

    1. A.Sites.ReadWrite.All
    2. B.Files.ReadWrite.All
    3. C.SensitivityLabels.Read.All
    4. D.Mail.ReadWrite
    5. E.Group.ReadWrite.All
    Show answer & explanation

    Correct answers: A, B, CSites.ReadWrite.All; Files.ReadWrite.All; SensitivityLabels.Read.All

    • A. This permission is part of the required set, giving the app read and write access to SharePoint sites for scanning and remediation.
    • B. This permission is part of the required set, giving the app read and write access to files during item-level scanning and remediation.
    • C. This permission is part of the required set, letting the app read sensitivity label assignments on scanned items.
    • D. This permission isn't part of the documented set for this app registration, since item-level scanning targets SharePoint sites and files rather than mailbox content.
    • E. This permission isn't part of the documented set for this app registration; the required directory-related permission is limited to read-only access instead.

    Want the full experience?

    These are just samples. Practice the full Microsoft Certified: Information Security Administrator Associate (SC-401) question bank in quiz mode — free, no signup, with domain practice and exam simulation.