Free SC-401 Practice Test Questions and Answers (2026)
DRAG DROP You have a Microsoft 365 E5 subscription that has data loss prevention (DLP) implemented. You need to create a custom sensitive info type. The solution must meet the following requirements: ● Match product serial numbers that contain a 10-character alphanumeric string. ● Ensure that the abbreviation of SN appears within six characters of each product serial number. ● Exclude a test serial number of 1111111111 from a match. Which pattern settings should you configure for each requirement? To answer, drag the appropriate settings to the correct requirements. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.
DRAG DROP You have a Microsoft 365 tenant. A new regulatory requirement states that all documents containing a patent ID be labeled, retained for 10 years, and then deleted. The policy used to apply the retention settings must never be disabled or deleted by anyone. You need to implement the regulatory requirement. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
DRAG DROP You need to create a trainable classifier that can be used as a condition in an auto-apply retention label policy. Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
DRAG DROP You have a Microsoft 365 E5 subscription that uses Microsoft Purview insider risk management and contains three users named User1, User2, and User3. All insider risk management policies have adaptive protection enabled and the default conditions for insider risk levels configured. The users perform the following activities, which trigger insider risk policy alerts: User1 performs at least one data exfiltration activity that results in a high severity risk score. User2 performs at least three risky user activities within seven days, that each results in a high severity risk score. User3 performs at least bwo data exfiltration activities within seven days, that each results in a high severity risk score. Which insider risk level is assigned to each user? To answer, drag the appropriate levels to the correct users. Each level may be used once, more than once, or not at all. You may need to drag the split bar between panes or seroll to view content. NOTE: Each correct selection is worth one point.
You configure a retention policy as shown >n the exhibit. (Click the Exhibit lab.)
The start of the retention period is based on when items are created. The current date is January 01.
207S.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.

HOTSPOT You are reviewing policies for the SharePoint Online environment. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
HOTSPOT You need to meet the technical requirements for the confidential documents. What should you create first, and what should you use for the detection method? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.
HOTSPOT You have a Microsoft 365 tenant You need to create a new sensitive into type for items that contain the following: • An employee ID number that consists of the hire date of the employee followed by a three digit number • The words "Employee", "ID", or "Identification" within 300 characters of the employee ID number What should you use for the primary and secondary elements? To answer, select the appropriate options m the answer area NOTE: Each correct selection is worth one point
You have a Microsoft 365 E5 subscription that contains four users named User1. User2, User3, and User4 and a file named File1.docx. File1 has a sensitivity label applied. The label is configured as shown in the following table. 
HOTSPOT You have a Microsoft 365 subscription. Auditing is enabled. A user named User1 is a member of a dynamic security group named Group1. You discover that User1 is no longer a member of Group1. You need to search the audit log to identify why User1 was removed from Group1. Which two activities should you use in the search? To answer, select the appropriate activities in the answer area. NOTE: Each correct selection is worth one point.
What's covered in this practice questions set
1: Implement information protection · 8 questions
📖 About this Domain
This domain covers the configuration of data classification and protection capabilities in Microsoft Purview. You will learn to implement sensitivity labels and policies to protect data across Microsoft 365 workloads and endpoints.
🎓 What You Will Learn
- You will learn to create and manage sensitive information types (SITs), including custom SITs, Exact Data Match (EDM), and document fingerprinting.
- You will learn to implement and manage trainable classifiers to identify specific categories of content.
- You will learn to create, configure, and publish sensitivity labels to apply encryption, content marking, and access controls.
- You will learn to apply information protection in Microsoft 365 services, including SharePoint Online, and with Microsoft Defender for Cloud Apps.
🛠️ Skills You Will Build
- You will build the skill to design and implement a data classification schema using built-in and custom classifiers.
- You will gain proficiency in configuring sensitivity label policies, including client-side and service-side auto-labeling.
- You will master the deployment and management of the Microsoft Purview Information Protection client and scanner.
- You will develop the ability to enforce data protection policies for data at rest and data in transit across the M365 ecosystem.
💡 Top Tips to Prepare
- Gain hands-on experience in the Microsoft Purview compliance portal creating custom SITs with regular expressions and keyword dictionaries.
- Practice the end-to-end process of creating, publishing, and applying sensitivity labels to documents and emails.
- Understand the specific use cases and prerequisites for implementing Exact Data Match and trainable classifiers.
- Review the differences between protection settings within a sensitivity label, such as encryption, content marking, and permissions.
2: Implement data loss prevention · 8 questions
📖 About this Domain
This domain covers configuring Microsoft Purview Data Loss Prevention policies to protect sensitive information. You will create and manage policies to identify, monitor, and prevent data exfiltration across Microsoft 365 workloads. The focus is on implementing granular controls to enforce data handling requirements.
🎓 What You Will Learn
- You will learn to create and manage unified DLP policies for locations including Exchange, SharePoint, OneDrive, Teams, and on-premises repositories.
- You will learn to configure DLP rules using conditions, exceptions, and actions to control the flow of sensitive data.
- You will learn to implement Endpoint DLP to monitor and control user activities on Windows devices.
- You will learn to manage DLP alerts, view reports, and use activity explorer to investigate policy matches.
🛠️ Skills You Will Build
- You will build the skill to deploy custom DLP policies using sensitive information types, sensitivity labels, and trainable classifiers.
- You will build the ability to fine-tune policy behavior with user notifications, policy tips, and user override options.
- You will build competence in configuring advanced DLP settings, including incident reports and alert aggregation.
- You will build proficiency in scoping policies to specific users, groups, or sites to minimize business disruption.
💡 Top Tips to Prepare
- Practice configuring DLP policies in test mode first to understand their impact before enforcing them.
- Understand the precedence and priority of DLP policies and rules, as this determines which rule is applied.
- Focus on the specific capabilities and limitations of Endpoint DLP, including onboarding methods and monitored activities.
- Memorize the different actions available within a DLP rule, such as restricting access or encrypting content.
3: Implement information governance · 4 questions
📖 About this Domain
This domain covers data lifecycle management and records management within the Microsoft Purview compliance portal. You will configure retention policies and retention labels to govern data across Microsoft 365 workloads. The focus is on meeting compliance requirements and managing organizational data risk.
🎓 What You Will Learn
- Learn to configure and manage retention policies and retention labels for content in Exchange, SharePoint, and Teams.
- Learn to implement a records management solution using file plans and event-based retention triggers.
- Learn to manage inactive mailboxes and apply retention for Microsoft Teams messages and private channels.
- Learn to configure policy scopes, including adaptive scopes and static scopes, for targeted policy application.
🛠️ Skills You Will Build
- You will build skills to implement data lifecycle management by configuring retention policies that automatically retain or delete content.
- You will build skills to deploy records management solutions, including configuring disposition reviews and proof of disposal.
- You will build skills to manage retention settings for specific Microsoft 365 workloads like SharePoint Online and Exchange Online.
- You will build skills to troubleshoot retention policy application using tools like Policy Lookup in the compliance portal.
💡 Top Tips to Prepare
- Master the principles of retention, understanding the hierarchy of which policy action wins in conflict scenarios.
- Get hands-on practice creating and applying adaptive scopes for dynamic policy targeting.
- Clearly differentiate the functionality and application of retention labels versus retention policies.
- Focus on records management specifics like immutability, disposition review processes, and file plan configuration.







