SC-401

SC-401 Cheat Sheet: Glossary and Decision Tables for Exam Week

Print-friendly•11 min read

Quick answer

This is a reference, not a tutorial: exam facts, the acronyms SC-401 assumes you already know, decision tables for the Purview features candidates most often confuse, and a task-to-portal-path table. Pair it with the full study guide for the reasoning behind each answer.

Exam Snapshot

Exam codeSC-401
CertificationMicrosoft Certified: Information Security Administrator Associate
StatusBeta (per Microsoft's exam catalog, checked Sept 7, 2026); retirement date: none
Domains3, each weighted 30–35%
Passing score700 / 1000 (scaled; scoring delayed while in beta)
Exam / seat time100 min / 120 min — Microsoft's general Associate/Expert (no-lab) allocation
Typical price$165 USD, priced by proctoring region
LanguagesEnglish only
PrerequisitesNone enforced; M365, PowerShell, Entra, Defender portal familiarity recommended
RenewalAnnual, free online assessment on Microsoft Learn

Source: Microsoft Learn SC-401 exam and study guide pages, checked September 7, 2026. Duration and question count are not published per-exam while SC-401 is in beta — the figures above are Microsoft's general policy for this exam tier, not an SC-401-specific number.

Acronym & Term Glossary

SC-401 questions use these terms interchangeably with their full names, without redefining them mid-question. Know the acronym cold before exam day — re-deriving what "EDM" or "DSPM for AI" stands for while reading a scenario costs time you don't have in a 100-minute exam.

TermMeans
SITSensitive information type — a pattern/rule used to detect sensitive data
EDMExact data match — detection against a specific, known dataset
OCROptical character recognition — reads text inside images for classification
DLPData loss prevention — policies that detect and act on sensitive content in motion or at rest
IRMInsider Risk Management — detects and investigates risky user activity patterns
DSPM for AIData Security Posture Management for AI — Purview controls governing data used by AI services and Copilot
XDRExtended detection and response — Microsoft Defender's unified security alert surface
JIT protectionJust-in-time protection — temporary Endpoint DLP access grant instead of a flat block
Adaptive ProtectionDynamically adjusts DLP enforcement based on a user's calculated insider risk level
MPIP clientMicrosoft Purview Information Protection client — applies labels on Windows endpoints

Drill this table into memory

Practice Terms in the Real Quiz Interface

40 free SC-401 questions, scored instantly. No credit card required.

Start Free Practice →

Decision Table: Which Classification Method?

These four look interchangeable on a first read. They are not.

If the exam says…Use
"We have the exact list of values to match"EDM
"Content varies in wording but follows a pattern"Trainable classifier
"Match this specific form/template"Document fingerprinting
"Detect a general pattern (SSNs, card numbers) org-wide"Built-in or custom SIT
"Content is inside a scanned image"OCR (as a SIT input)

Decision Table: Label or Policy Type?

GoalUse
Classify and protect one item permanentlyRetention label
Govern retention broadly across a workload/locationRetention policy
Preview matches before enforcementAuto-labeling in simulation mode
Resolve which retention setting wins on a specific itemPolicy Lookup
Grant a temporary exception to a blocked device actionJust-in-time protection
Vary DLP strictness by a user's risk level automaticallyAdaptive Protection

Decision Table: Which Risk or Alert Surface?

You need to…Go to
Investigate a DLP or insider risk case directlyMicrosoft Purview portal
See combined security + compliance signals in one feedMicrosoft Defender XDR
Respond to a cloud-app file-policy alertMicrosoft Defender for Cloud Apps
Run a broad activity search for legal/HRPurview eDiscovery
Track classification/label usage trends over timeData explorer / Content explorer

Role & Permission Quick Reference

Domain 1 calls out "roles and permissions for administering sensitivity labels" as its own exam skill, and Domain 3 does the same for Insider Risk Management. The exam expects you to know which role does what — not just that "an admin has access."

RoleCan do
Information Protection AdministratorCreate, configure, and publish sensitivity labels and auto-labeling policies
Compliance AdministratorBroad read/write access across most Purview compliance solutions
DLP Compliance ManagementCreate and manage DLP policies and rules
Insider Risk Management AdminFull configuration of Insider Risk policies, indicators, and settings
Insider Risk Management AnalystInvestigate alerts and cases without editing policy configuration
Insider Risk Management InvestigatorFull case management, including access to flagged user content
Records ManagementCreate and manage retention labels, file plans, and disposition
Global Reader (compliance)Read-only visibility across Purview solutions, no configuration rights

An exam scenario that says "an analyst should investigate but not change policy" is describing the Insider Risk Management Analyst role specifically, not the Admin role — a distinction the exam tests directly.

Task → Portal Path Reference

TaskWhere
Create/publish sensitivity labelsPurview portal → Information Protection
Create custom SIT / EDM schemaPurview portal → Data Classification
Build/edit a DLP policyPurview portal → Data Loss Prevention
Configure retention labels/policiesPurview portal → Data Lifecycle Management
Create/manage Insider Risk policiesPurview portal → Insider Risk Management
Configure DSPM for AIPurview portal → Data Security Posture Management
Bulk-classify on-prem file sharesPurview Information Protection scanner (installed agent)
Respond to a file-policy alertDefender for Cloud Apps → Policies → File policy
Assign Purview Audit (Premium) licensesMicrosoft 365 admin center → Licenses

Exam-day reminder:Microsoft Purview consolidated most compliance and information-protection admin centers into a single portal. If a question describes an old standalone "compliance center" URL or name, treat it as historical framing, not a different tool from what's listed above.

Common Cheat-Sheet Questions

Can I print this for exam-day review?

Yes — every table on this page uses plain borders with no interactive elements, so it prints cleanly from any browser's print dialog.

Is memorizing this glossary enough to pass SC-401?

No. SC-401 is scenario-based — this sheet is for fast recall of terms and decision points you've already studied, not a substitute for working through the full study guide or practicing full scenarios.

Why does this sheet mention "beta" status?

Microsoft's own exam catalog currently labels SC-401 as beta, which affects when you receive your score — worth knowing before you schedule, not just after.

Does this cover PowerShell cmdlets in depth?

No — this sheet maps tasks to portal locations, since most SC-401 scenarios are portal-driven. PowerShell familiarity is recommended background, not a cmdlet-syntax focus of the exam itself.

What's the difference between an Insider Risk Analyst and an Investigator?

An Analyst can review alerts and cases but cannot access flagged users' actual content; an Investigator can, along with full case management. The exam tests this distinction directly rather than treating both as interchangeable "insider risk staff."

Do I need a specific role to just view Purview data without changing anything?

Yes — Global Reader (compliance) gives read-only visibility across Purview solutions. It's the role to pick whenever a scenario needs oversight without configuration rights.

About This Reference

MSCertQuiz sells a 500-question SC-401 practice bank alongside this cheat sheet, built by the same team. Facts above trace to Microsoft's SC-401 exam page and Microsoft Purview documentation, checked September 7, 2026.