SC-401

Free SC-401 Practice Questions: Three Scenarios, Twelve Decisions

12 questions•16 min read

Quick answer

These 12 free questions are built around three fictional companies — one per SC-401 domain — with four connected decisions each, the way Microsoft's real case-study-style questions work. Every option, right or wrong, gets a rationale, so getting an answer right for the wrong reason still gets corrected.

Most SC-401 practice sets rewrite the same isolated definition question three ways. Real Microsoft Purview administration doesn't work in isolation — one decision about a sensitivity label affects DLP, which affects retention, which affects what an insider risk investigator sees later. These questions follow that chain within a single scenario instead of jumping between unrelated companies every time. For a domain-by-domain walkthrough before you attempt these, see the SC-401 study guide.

How to use this set

  • • Read the scenario once, fully, before looking at question 1 — the later questions in each scenario build on earlier facts.
  • • Pick an answer, then read every rationale, including the ones for options you didn't choose.
  • • If you miss two or more questions in a scenario, re-read that domain in the study guide before moving on.

Scenario 1: Meridian Health — Implement Information Protection

Questions 1–4 · Domain 1 (30–35%)

Meridian Health, a regional healthcare provider, is rolling out Microsoft Purview to protect patient records across Exchange, SharePoint, and an aging on-premises file server. The compliance team has an exact spreadsheet of 2.3 million active patient record numbers and wants matches against that specific list to trigger the strictest handling. Separately, Priya, an information protection admin, is preparing a new sensitivity label for finance contracts and wants to see how it would behave before anyone's files are actually re-labeled.

1

Which classification method should Meridian Health use to detect its 2.3 million patient record numbers with the lowest false-positive rate?

  • A. A custom sensitive information type built from a regex pattern
  • B. Exact data match (EDM) based on the existing record list
  • C. A trainable classifier trained on sample patient documents
  • D. Document fingerprinting against a blank patient-intake template

Correct: B

EDM matches against a known, structured dataset — exactly what an existing list of 2.3 million specific record numbers is — with near-zero false positives. A is wrong because a regex-based SIT can only approximate a pattern and will misfire on record numbers that happen to match the format without being real. C is wrong because trainable classifiers are for unstructured content that varies in wording, not a fixed list of values. D is wrong because fingerprinting matches a specific document template, not a list of discrete data values.

2

Priya wants to preview how her new auto-labeling policy would classify finance contracts before it changes anything for users. What should she do?

  • A. Publish the label with the lowest possible priority
  • B. Run the auto-labeling policy in simulation mode
  • C. Apply the label manually to a handful of test files
  • D. Enable the policy and monitor Activity explorer for a week

Correct: B

Simulation mode shows exactly what an auto-labeling policy would match without actually applying labels or affecting users. A is wrong because priority only affects which of several policies wins a conflict — it does not preview matches. C is wrong because manual labeling on a handful of files tells Priya nothing about how the automated policy's conditions will behave at scale. D is wrong because that means going live first and finding problems after users are already affected, which is the opposite of what she wants.

3

Before Meridian Health can publish any sensitivity label at all, what is the first requirement?

  • A. At least one auto-labeling policy must already exist
  • B. An administrator must hold the appropriate Purview role for administering sensitivity labels
  • C. A trainable classifier must be trained and approved
  • D. Endpoint DLP must be enabled organization-wide

Correct: B

Roles and permissions for administering sensitivity labels are a distinct, prerequisite exam objective — without the right role assignment, an admin cannot create or publish labels at all. A is wrong because auto-labeling policies come after labels exist, not before. C is wrong because a trainable classifier is only needed if a label's auto-labeling logic depends on one, not for publishing labels in general. D is wrong because Endpoint DLP is a separate feature entirely unrelated to label publishing rights.

4

Meridian Health has years of unlabeled scanned patient forms sitting on an on-premises file server that has never connected to Microsoft 365 cloud services. What should classify this content?

  • A. Microsoft Defender for Cloud Apps file policies
  • B. Endpoint DLP device policies
  • C. The Microsoft Purview Information Protection scanner
  • D. Microsoft Purview eDiscovery search

Correct: C

The Information Protection scanner is purpose-built for bulk classification of on-premises data, including file shares that have no direct cloud connection. A is wrong because Defender for Cloud Apps file policies act on content already flowing through a monitored cloud app, not an isolated on-prem server. B is wrong because Endpoint DLP governs actions on managed devices, not bulk classification of a file share. D is wrong because eDiscovery is a search and legal-hold tool, not a classification engine.

Want the full timed experience?

Take the SC-401 Readiness Quiz

A short, free diagnostic across all three domains with a personalized study plan. No signup required.

Check My Readiness →

Scenario 2: Northwind Finance — Implement DLP and Retention

Questions 5–8 · Domain 2 (30–35%)

Northwind Finance has two DLP policies that can both match outgoing email containing account numbers — a broad company-wide policy and a narrower one scoped to the wire-transfer team. An analyst on that team needs to move one labeled spreadsheet to a personal USB drive for a single legitimate audit request. Separately, a contract sits under both a manually applied retention label and a department-wide retention policy with different retention periods, and one employee's DLP restrictions tightened automatically overnight without any admin touching a policy.

5

An email matches both the company-wide policy (priority 5) and the wire-transfer team policy (priority 1). Which rule's action applies?

  • A. Both policies' actions apply simultaneously, in full
  • B. The wire-transfer team policy (priority 1) takes effect first
  • C. The company-wide policy (priority 5) takes effect first, since it was created first
  • D. Whichever policy has more rules configured wins

Correct: B

DLP policies are evaluated in priority order with the lowest number evaluated first, so priority 1 takes precedence over priority 5. A is wrong because precedence exists precisely to prevent both policies' actions from stacking unpredictably. C is wrong because creation date has no bearing on precedence — priority number does. D is wrong because rule count within a policy is irrelevant to which policy is evaluated first.

6

The wire-transfer analyst has a legitimate, one-time reason to copy a labeled file to a personal USB drive. Which Endpoint DLP feature lets an admin grant this without disabling the policy?

  • A. Adaptive Protection
  • B. Just-in-time protection
  • C. Policy Lookup
  • D. Insider Risk Management forensic evidence

Correct: B

Just-in-time protection grants temporary, scoped access to a device action that a policy would otherwise block, without turning the policy off. A is wrong because Adaptive Protection changes ongoing enforcement based on insider risk level, it doesn't grant a one-time exception. C is wrong because Policy Lookup is a retention tool, unrelated to Endpoint DLP exceptions. D is wrong because forensic evidence is about capturing activity for review, not granting access.

7

A contract has both a manually applied retention label and a conflicting department-wide retention policy. What should the admin use to determine which setting actually governs this specific document?

  • A. Policy Lookup
  • B. Content explorer
  • C. Data explorer
  • D. Activity explorer

Correct: A

Policy Lookup is the named tool for interpreting exactly which retention setting wins on a specific item when multiple could apply. B is wrong because Content explorer shows where labeled content lives, not precedence outcomes. C is wrong because Data explorer tracks classification and label usage trends, not per-item precedence. D is wrong because Activity explorer logs user and policy actions, not precedence resolution.

8

One employee's DLP restrictions tightened automatically overnight with no admin editing any policy. What is the most likely explanation?

  • A. Adaptive Protection raised enforcement based on the employee's calculated insider risk level
  • B. A DLP policy update was scheduled and applied automatically
  • C. The employee's sensitivity label expired
  • D. Just-in-time protection reached its time limit

Correct: A

Adaptive Protection dynamically tightens or loosens DLP enforcement as a user's insider risk level changes, without requiring a manual policy edit. B is wrong because DLP policies don't silently self-schedule changes to enforcement scope. C is wrong because sensitivity labels don't expire in a way that changes DLP enforcement. D is wrong because just-in-time protection expiring would remove a temporary grant, not tighten baseline enforcement.

Scenario 3: Vantage Robotics — Manage Risks, Alerts, and Activities

Questions 9–12 · Domain 3 (30–35%)

Vantage Robotics just rolled out Microsoft 365 Copilot to its finance team and is worried about two things: an engineer who gave notice last week and has been downloading unusual volumes of design files, and making sure Copilot itself doesn't surface restricted financial data to users who shouldn't see it. The SOC also wants one place to watch DLP and insider risk signals alongside its broader security alert feed, and wants optional screen-capture evidence if the departing engineer's activity is flagged.

9

Which Insider Risk Management policy template best fits the departing engineer's unusual download activity?

  • A. A fully custom policy built from scratch
  • B. The data theft by departing employees template
  • C. The security policy violations template
  • D. A DLP policy scoped to the engineer's account

Correct: B

Microsoft provides a named template specifically for detecting data exfiltration risk from employees who have given notice or resigned. A is wrong because a purpose-built template already exists — building custom logic here is unnecessary effort the exam expects you to avoid. C is wrong because that template targets policy-violation behavior generally, not the departure-linked pattern described. D is wrong because a DLP policy governs data movement rules, not insider risk scoring and case management.

10

Where should Vantage's SOC monitor DLP and insider risk signals alongside its broader security alert feed in one place?

  • A. Microsoft Purview portal only
  • B. Microsoft Defender for Cloud Apps only
  • C. Microsoft Defender XDR
  • D. Microsoft Entra sign-in logs

Correct: C

Defender XDR is the surface where Purview-originated alerts converge with the rest of an organization's security signal, matching the "one place, broader feed" requirement. A is wrong because Purview alone doesn't include the wider security alert feed the SOC also wants. B is wrong because that surface is scoped to cloud app file-policy alerts, not the combined view requested. D is wrong because sign-in logs cover authentication events, not DLP or insider risk alerts.

11

Before Vantage can restrict what financial data reaches Copilot for finance users, what must be completed first?

  • A. Publish a new sensitivity label scheme for Copilot only
  • B. Complete DSPM for AI prerequisites and role/permission setup
  • C. Disable Copilot for the finance team entirely
  • D. Create a custom trainable classifier for financial documents

Correct: B

DSPM for AI has its own listed prerequisites and role/permission configuration that must be in place before its policies can be configured to govern what Copilot can access. A is wrong because a new label scheme alone doesn't configure the AI-specific controls the scenario needs. C is wrong because disabling Copilot defeats the purpose of the rollout rather than protecting data within it. D is wrong because a trainable classifier is one possible input to labeling, not the DSPM for AI setup process itself.

12

The SOC wants optional screen-capture evidence if the departing engineer's activity triggers an insider risk alert. How is this enabled?

  • A. It is on by default for every Insider Risk Management policy
  • B. Through a separate forensic evidence setting with its own permissions
  • C. By enabling Endpoint DLP device monitoring
  • D. Through Microsoft Purview Audit (Premium) licensing alone

Correct: B

Forensic evidence capture is a distinct capability with its own configuration and permission requirements, separate from the base policy template. A is wrong because it is not on by default — it requires deliberate setup. C is wrong because Endpoint DLP governs data-loss actions on devices, not insider risk screen capture. D is wrong because Audit (Premium) licensing supports activity investigation broadly, but doesn't by itself turn on forensic screen capture.

Questions About This Practice Set

Are these questions as hard as the real SC-401 exam?

Roughly comparable in structure — connected, scenario-driven decisions rather than isolated recall — though the real exam draws from a much larger pool across all three domains.

Why are the questions grouped by scenario instead of by domain heading?

Microsoft's own exam uses case-study-style questions where one company scenario supports several related decisions — grouping this way tests whether you can carry context forward, not just recall a term.

Where can I get more than 12 questions?

MSCertQuiz maintains a 500-question SC-401 bank (40 free) covering every sub-objective across all three domains, available on the SC-401 certification page.

Do I need to know PowerShell for SC-401?

Microsoft lists PowerShell familiarity as recommended background, not a separately tested skill on its own — most SC-401 questions focus on portal-based configuration and decision-making.

Is Domain 3's AI-protection material covered here?

Yes — question 11 covers DSPM for AI prerequisites, which is the newest objective on the exam and the one with the least third-party coverage elsewhere.

About This Practice Set

MSCertQuiz sells a 500-question SC-401 practice bank alongside this free sample, written by the same team. Domain names, weightings, and objective terminology above trace to Microsoft's official SC-401 study guide (checked September 7, 2026). Company names and scenarios are fictional; only the exam concepts they illustrate are real.