Quick answer
This is a reference, not a tutorial: exam facts, the acronyms SC-401 assumes you already know, decision tables for the Purview features candidates most often confuse, and a task-to-portal-path table. Pair it with the full study guide for the reasoning behind each answer.
Exam Snapshot
| Exam code | SC-401 |
| Certification | Microsoft Certified: Information Security Administrator Associate |
| Status | Beta (per Microsoft's exam catalog, checked Sept 7, 2026); retirement date: none |
| Domains | 3, each weighted 30–35% |
| Passing score | 700 / 1000 (scaled; scoring delayed while in beta) |
| Exam / seat time | 100 min / 120 min — Microsoft's general Associate/Expert (no-lab) allocation |
| Typical price | $165 USD, priced by proctoring region |
| Languages | English only |
| Prerequisites | None enforced; M365, PowerShell, Entra, Defender portal familiarity recommended |
| Renewal | Annual, free online assessment on Microsoft Learn |
Source: Microsoft Learn SC-401 exam and study guide pages, checked September 7, 2026. Duration and question count are not published per-exam while SC-401 is in beta — the figures above are Microsoft's general policy for this exam tier, not an SC-401-specific number.
Acronym & Term Glossary
SC-401 questions use these terms interchangeably with their full names, without redefining them mid-question. Know the acronym cold before exam day — re-deriving what "EDM" or "DSPM for AI" stands for while reading a scenario costs time you don't have in a 100-minute exam.
| Term | Means |
|---|---|
| SIT | Sensitive information type — a pattern/rule used to detect sensitive data |
| EDM | Exact data match — detection against a specific, known dataset |
| OCR | Optical character recognition — reads text inside images for classification |
| DLP | Data loss prevention — policies that detect and act on sensitive content in motion or at rest |
| IRM | Insider Risk Management — detects and investigates risky user activity patterns |
| DSPM for AI | Data Security Posture Management for AI — Purview controls governing data used by AI services and Copilot |
| XDR | Extended detection and response — Microsoft Defender's unified security alert surface |
| JIT protection | Just-in-time protection — temporary Endpoint DLP access grant instead of a flat block |
| Adaptive Protection | Dynamically adjusts DLP enforcement based on a user's calculated insider risk level |
| MPIP client | Microsoft Purview Information Protection client — applies labels on Windows endpoints |
Drill this table into memory
Practice Terms in the Real Quiz Interface
40 free SC-401 questions, scored instantly. No credit card required.
Start Free Practice →Decision Table: Which Classification Method?
These four look interchangeable on a first read. They are not.
| If the exam says… | Use |
|---|---|
| "We have the exact list of values to match" | EDM |
| "Content varies in wording but follows a pattern" | Trainable classifier |
| "Match this specific form/template" | Document fingerprinting |
| "Detect a general pattern (SSNs, card numbers) org-wide" | Built-in or custom SIT |
| "Content is inside a scanned image" | OCR (as a SIT input) |
Decision Table: Label or Policy Type?
| Goal | Use |
|---|---|
| Classify and protect one item permanently | Retention label |
| Govern retention broadly across a workload/location | Retention policy |
| Preview matches before enforcement | Auto-labeling in simulation mode |
| Resolve which retention setting wins on a specific item | Policy Lookup |
| Grant a temporary exception to a blocked device action | Just-in-time protection |
| Vary DLP strictness by a user's risk level automatically | Adaptive Protection |
Decision Table: Which Risk or Alert Surface?
| You need to… | Go to |
|---|---|
| Investigate a DLP or insider risk case directly | Microsoft Purview portal |
| See combined security + compliance signals in one feed | Microsoft Defender XDR |
| Respond to a cloud-app file-policy alert | Microsoft Defender for Cloud Apps |
| Run a broad activity search for legal/HR | Purview eDiscovery |
| Track classification/label usage trends over time | Data explorer / Content explorer |
Role & Permission Quick Reference
Domain 1 calls out "roles and permissions for administering sensitivity labels" as its own exam skill, and Domain 3 does the same for Insider Risk Management. The exam expects you to know which role does what — not just that "an admin has access."
| Role | Can do |
|---|---|
| Information Protection Administrator | Create, configure, and publish sensitivity labels and auto-labeling policies |
| Compliance Administrator | Broad read/write access across most Purview compliance solutions |
| DLP Compliance Management | Create and manage DLP policies and rules |
| Insider Risk Management Admin | Full configuration of Insider Risk policies, indicators, and settings |
| Insider Risk Management Analyst | Investigate alerts and cases without editing policy configuration |
| Insider Risk Management Investigator | Full case management, including access to flagged user content |
| Records Management | Create and manage retention labels, file plans, and disposition |
| Global Reader (compliance) | Read-only visibility across Purview solutions, no configuration rights |
An exam scenario that says "an analyst should investigate but not change policy" is describing the Insider Risk Management Analyst role specifically, not the Admin role — a distinction the exam tests directly.
Task → Portal Path Reference
| Task | Where |
|---|---|
| Create/publish sensitivity labels | Purview portal → Information Protection |
| Create custom SIT / EDM schema | Purview portal → Data Classification |
| Build/edit a DLP policy | Purview portal → Data Loss Prevention |
| Configure retention labels/policies | Purview portal → Data Lifecycle Management |
| Create/manage Insider Risk policies | Purview portal → Insider Risk Management |
| Configure DSPM for AI | Purview portal → Data Security Posture Management |
| Bulk-classify on-prem file shares | Purview Information Protection scanner (installed agent) |
| Respond to a file-policy alert | Defender for Cloud Apps → Policies → File policy |
| Assign Purview Audit (Premium) licenses | Microsoft 365 admin center → Licenses |
Exam-day reminder:Microsoft Purview consolidated most compliance and information-protection admin centers into a single portal. If a question describes an old standalone "compliance center" URL or name, treat it as historical framing, not a different tool from what's listed above.
Common Cheat-Sheet Questions
Can I print this for exam-day review?
Yes — every table on this page uses plain borders with no interactive elements, so it prints cleanly from any browser's print dialog.
Is memorizing this glossary enough to pass SC-401?
No. SC-401 is scenario-based — this sheet is for fast recall of terms and decision points you've already studied, not a substitute for working through the full study guide or practicing full scenarios.
Why does this sheet mention "beta" status?
Microsoft's own exam catalog currently labels SC-401 as beta, which affects when you receive your score — worth knowing before you schedule, not just after.
Does this cover PowerShell cmdlets in depth?
No — this sheet maps tasks to portal locations, since most SC-401 scenarios are portal-driven. PowerShell familiarity is recommended background, not a cmdlet-syntax focus of the exam itself.
What's the difference between an Insider Risk Analyst and an Investigator?
An Analyst can review alerts and cases but cannot access flagged users' actual content; an Investigator can, along with full case management. The exam tests this distinction directly rather than treating both as interchangeable "insider risk staff."
Do I need a specific role to just view Purview data without changing anything?
Yes — Global Reader (compliance) gives read-only visibility across Purview solutions. It's the role to pick whenever a scenario needs oversight without configuration rights.
About This Reference
MSCertQuiz sells a 500-question SC-401 practice bank alongside this cheat sheet, built by the same team. Facts above trace to Microsoft's SC-401 exam page and Microsoft Purview documentation, checked September 7, 2026.