Free Microsoft SC-401 practice questions

10 free Microsoft SC-401 practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 280 questions. Work through them, then open each answer to check your reasoning.

Question 1

Show the case study this question is based on

CASE STUDY

INSTRUCTIONS

This is a case study. Case studies are not timed separately from other exam sections. You can use as much exam time as you would like to complete each case study. However, there might be additional case studies or other exam sections. Manage your time to ensure that you can complete all the exam sections in the time provided. Pay attention to the Exam Progress at the top of the screen so you have sufficient time to complete any exam sections that follow this case study.

To answer the case study questions, you will need to reference information that is provided in the case. Case studies and associated questions might contain exhibits or other resources that provide more information about the scenario described in the case. Information provided in an individual question does not apply to the other questions in the case study.

A Review Screen will appear at the end of this case study. From the Review Screen, you can review and change your answers before you move to the next exam section. After you leave this case study, you will NOT be able to return to it.

To start the case study -To display the first question in this case study, select the "Next" button. To the left of the question, a menu provides links to information such as business requirements, the existing environment, and problem statements. Please read through all this information before answering any questions.

When you are ready to answer a question, select the "Question" button to return to the question.

Overview

Contoso, Ltd. is a consulting company that has a main office in Montreal and three branch offices in Seattle, Boston, and Johannesburg.

Existing Environment

Microsoft 365 Environment -Contoso has a Microsoft 365 E5 tenant. The tenant contains the administrative user accounts shown in the following table.

Users store data in the following locations:

• SharePoint sites

• OneDrive accounts

• Exchange email

• Exchange public folders

• Teams chats

• Teams channel messages

When users in the research department create documents, they must add a 10-digit project code to each document. Project codes that start with the digits 999 are confidential.

SharePoint Online Environment

Contoso has four Microsoft SharePoint Online sites named Site1, Site2, Site3, and Site4.

Site2 contains the files shown in the following table.

Two users named User1 and User2 are assigned roles for Site2 as shown in the following table.

Site3 stores documents related to the company's projects. The documents are organized in a folder hierarchy based on the project.

Site4 has the following two retention policies applied:

Name: Site4RetentionPolicy1 -Locations to apply the policy: Site4 Delete items older than: 2 years Delete content based on: When items were created Name: Site4RetentionPolicy2 -Locations to apply the policy: Site4 Retain items for a specific period: 4 years Start the retention period based on: When items were created At the end of the retention period: Do nothing

Problem Statements

Management at Contoso is concerned about data leaks. On several occasions, confidential research department documents were leaked.

Requirements

Planned Changes

Contoso plans to create the following data loss prevention (DLP) policy:

Name: DLPpolicy1 -Locations to apply the policy: Site2 Conditions:

Content contains any of these sensitive info types: SWIFT Code Instance count: 2 to any -Actions: Restrict access to the content

Technical Requirements

Contoso must meet the following technical requirements:

All administrative users must be able to review DLP reports.

Whenever possible, the principle of least privilege must be used.

For all users, all Microsoft 365 data must be retained for at least one year.

Confidential documents must be detected and protected by using Microsoft 365.

Site1 documents that include credit card numbers must be labeled automatically.

All administrative users must be able to create Microsoft 365 sensitivity labels.

After a project is complete, the documents in Site3 that relate to the project must be retained for 10 years.

You need to meet the technical requirements for the creation of the sensitivity labels.

To which user or users must you assign the Sensitivity Label Administrator role?

Exhibit for question 1

Exhibit for question 1

Exhibit for question 1

  1. Admin1 only
  2. Admin1 and Admin4 only
  3. Admin1 and Admin5 only
  4. Admin1, Admin2, and Admin3 only
Show answer and explanation

Correct answer: B. Admin1 and Admin4 only

Creating and managing sensitivity labels is already included in the Compliance Administrator, Compliance Data Administrator, and Security Administrator roles, so Admin2, Admin3, and Admin5 need no additional assignment. Global Reader is read-only and Security Operator carries no label management rights, so Admin1 and Admin4 are the only accounts that need the Sensitivity Label Administrator role. Assigning that single, narrowly scoped role to just those two accounts satisfies the requirement that all administrative users can create labels while keeping permissions minimal.

Why the other options are wrong

  • A. Admin1 alone leaves Admin4 without any ability to create sensitivity labels, so the requirement is not met.
  • C. Admin5 holds the Security Administrator role, which already permits creating and managing sensitivity labels, so granting an extra role there is unnecessary.
  • D. Admin2 and Admin3 hold compliance roles that already allow sensitivity label creation, and this option leaves Admin4 unable to create labels.

Question 2

You have a Microsoft 365 E5 subscription that contains a Microsoft Teams channel named Channel1. Channel1 contains research and development documents.

You plan to implement Microsoft 365 Copilot for the subscription.

You need to prevent the contents of files stored in Channel1 from being included in answers generated by Copilot and shown to unauthorized users.

What should you use?

  1. data loss prevention (DLP)
  2. Microsoft Purview insider risk management
  3. Microsoft Purview Information Barriers (IBs)
  4. sensitivity labels
Show answer and explanation

Correct answer: D. sensitivity labels

Sensitivity labels are the correct mechanism to prevent unauthorized access to Copilo-enerated content. When a sensitivity label is applied to files in Channel1, it enforces encryption and access controls that prevent Copilot from including that content in responses shown to users without the appropriate permissions. This directly addresses the requirement to prevent unauthorized users from seeing Channel1 contents in Copilot answers.

Why the other options are wrong

  • A. DLP policies prevent data exfiltration but don't control Copilot's inclusion of content in generated responses.
  • B. Insider risk management focuses on detecting risky user behavior, not controlling Copilot access to sensitive content.
  • C. Information Barriers restrict communication between users but don't control how Copilot processes or displays content.

Question 3

You have a Microsoft 365 E5 subscription.

You need to create a sensitivity label named Label1. The solution must ensure that users can use Microsoft 365 Copilot to summarize files that have Label1 applied.

Which permission should you select for Label1?

  1. Export content(EXPORT)
  2. Copy and extract content(EXTRACT)
  3. Edit content(DOCEDIT)
  4. View rights(VIEW)
Show answer and explanation

Correct answer: B. Copy and extract content(EXTRACT)

The Copy and extract content (EXTRACT) permission is required for Copilot to summarize files. Copilot needs the ability to extract content from documents to process and summarize them. Without this permission, Copilot cannot access the underlying content of labeled files to generate summaries.

Why the other options are wrong

  • A. Export content permission controls exporting files but is not required for Copilot summarization.
  • C. Edit content permission allows document editing, which is not necessary for rea-nly summarization operations.
  • D. View rights permission allows users to see files but doesn't grant the extraction capability Copilot needs to process content.

Question 4

You have a Microsoft 365 E5 subscription.

You need to enable support for sensitivity labels in Microsoft SharePoint Online.

What should you use?

  1. the Microsoft Purview portal
  2. the Microsoft Entra admin center
  3. the SharePoint admin center
  4. the Microsoft 365 admin center
Show answer and explanation

Correct answer: A. the Microsoft Purview portal

Support for sensitivity labels on Office files in SharePoint and OneDrive is turned on from the Microsoft Purview portal, on the Information Protection labels page, by selecting Turn on now. The equivalent action can also be performed with Set-SPOTenant -EnableAIPIntegration $true in PowerShell. Once enabled, SharePoint can process labeled and encrypted files for search, coauthoring, and eDiscovery.

Why the other options are wrong

  • B. The Microsoft Entra admin center manages identities, groups, and access policies, and has no control for sensitivity label support in SharePoint.
  • C. The SharePoint admin center manages sites, sharing, and storage settings, but it does not contain the option that enables sensitivity label support for Office files.
  • D. The Microsoft 365 admin center handles subscriptions, users, and service-wide settings, not information protection enablement.

Question 5

You have a Microsoft 365 subscription.

You need to customize encrypted email for the subscription. The solution must meet the following requirements.

Ensure that when an encrypted email is sent, the email includes the company logo.

Minimize administrative effort.

Which PowerShell cmdlet should you run?

  1. Set-IRMConfiguration
  2. Set-OMEConfiguration
  3. Set-RMSTemplate
  4. New-OMEConfiguration
Show answer and explanation

Correct answer: B. Set-OMEConfiguration

Set-OMEConfiguration is the PowerShell cmdlet used to customize Office Message Encryption (OME) settings, including adding company logos to encrypted emails. This cmdlet allows customization of the encrypted email experience without requiring extensive manual administrative configuration for each email.

Why the other options are wrong

  • A. Set-IRMConfiguration manages Information Rights Management templates and policies, not OME portal customization.
  • C. Set-RMSTemplate configures Rights Management Service templates but doesn't customize the OME email portal branding.
  • D. New-OMEConfiguration creates new configurations but doesn't modify existing OME settings for branding purposes.

Question 6

You have a Microsoft 365 E5 subscription.

You need to ensure that encrypted email messages sent to an external recipient can be revoked or will expire within seven days.

What should you configure first?

  1. a custom branding template
  2. a mail flow rule
  3. a sensitivity label
  4. a Conditional Access policy
Show answer and explanation

Correct answer: A. a custom branding template

Revocation and message expiration for encrypted mail sent to external recipients are features of Advanced Message Encryption, and both settings live in a custom branding template created with New-OMEConfiguration or Set-OMEConfiguration. You configure that template first, setting the expiration to seven days, and then apply it to messages. Without the template in place there is nothing that defines the expiration or enables revocation.

Why the other options are wrong

  • B. A mail flow rule applies the encryption template to messages, but it can only reference a branding template that has already been created.
  • C. Sensitivity label encryption controls access and permissions on content, it does not provide the external message expiration and revocation offered by Advanced Message Encryption.
  • D. Conditional Access governs sign-in and device conditions, and has no effect on encrypted email expiration or revocation.

Question 7

You have a Microsoft SharePoint Online site named Site1 that contains a document library. The library contains more than 1,000 documents.

Some of the documents are job applicant resumes. All the documents are in the English language.

You plan to apply a sensitivity label automatically to any document identified as a resume. Only documents that contain work experience, education, and accomplishments must be labeled automatically.

You need to identify and categorize the resumes. The solution must minimize administrative effort.

What should you include in the solution?

  1. a trainable classifier
  2. a keyword dictionary
  3. a function
  4. an exact data match (EDM) classifier
Show answer and explanation

Correct answer: A. a trainable classifier

A trainable classifier is the optimal solution for identifying resumes based on multiple content characteristics like work experience, education, and accomplishments. Trainable classifiers use machine learning to recognize complex patterns across documents without requiring predefined keyword lists or exact data matches, minimizing administrative effort while achieving accurate identification of documents with multiple required content elements.

Why the other options are wrong

  • B. A keyword dictionary is too simplistic for identifying resumes with multiple required content elements and would generate false positives.
  • C. Creating a custom function requires significant development and ongoing maintenance, increasing administrative effort.
  • D. EDM classifiers require a database of exact values to match, which is impractical for diverse resume content that varies across documents.

Question 8

You have a Microsoft 365 E5 subscription that contains a Windows 11 device named Device1 and three users named User1, User2, and User3.

You plan to deploy Azure information Protection (AIP) and the Microsoft Purview information Protection client to Device1.

You need to ensure that the users can perform the following actions on Device1 as part of the planned deployment:

• User1 will test the functionality of the client.

• User2 will install and configure the Microsoft Rights Management connector.

• User3 will be configured as the service account for the information protection scanner.

The solution must maximize the security of the sign-in process for the users.

What should you do?

  1. Exclude User1 and User2 from multifactor authentication (MFA).
  2. Enable User2 and User3 for passwordless authentication.
  3. Exclude User2 and User3 from multifactor authentication (MFA).
  4. Enable User1, User2, and User3 for passkey (FIDO2) authentication.
Show answer and explanation

Correct answer: C. Exclude User2 and User3 from multifactor authentication (MFA).

Excluding User2 and User3 from MFA is the correct answer because User2 needs to install and configure the Rights Management connector (a service account function requiring uninterrupted authentication) and User3 is the service account for the information protection scanner. Service accounts require exclusion from MFA to function properly. User1 testing the client should still use MFA for security. This balances operational requirements with security maximization.

Why the other options are wrong

  • A. Excluding User1 from MFA is unnecessary since User1 is only testing functionality and should maintain full security protections.
  • B. Passwordless authentication alone doesn't address the service account requirements, and both users wouldn't necessarily benefit from this approach.
  • D. Passkey authentication, while secure, is not the standard or practical solution for service account sign-in scenarios in this context.

Question 9

You have a Microsoft 365 alert named Alert2 as shown in the following exhibit.

You need to manage the status of Alert2.

To which status can you change Alert2?

Exhibit for question 9

  1. The status cannot be changed.
  2. Dismissed only
  3. Investigating only
  4. Active or Investigating only
  5. Investigating, Active, or Dismissed
Show answer and explanation

Correct answer: E. Investigating, Active, or Dismissed

In Microsoft 365 security alert management systems, alerts can transition between multiple statuses regardless of their current state. An alert with a current status of 'Resolved' can be changed to Active (to reopen it), Investigating (to indicate ongoing review), or Dismissed (to close it without resolution). The status management system allows flexibility in alert lifecycle management to accommodate changing circumstances, new findings, or organizational workflow requirements. All three status options are available for modification at any time.

Why the other options are wrong

  • A. Alert statuses in Microsoft 365 can be changed; the system allows status transitions for alert management.
  • B. While Dismissed is an option, Investigating and Active are also available status transitions.
  • C. While Investigating is an option, Active and Dismissed are also available status transitions.
  • D. This option is incomplete; Dismissed is also a valid status option in addition to Active and Investigating.

Question 10

You have a Microsoft 365 subscription that uses retention label policies.

You need to identify all the changes made to retention labels during the last 30 days.

What should you use in the Microsoft Purview portal?

  1. Reports
  2. Activity explorer
  3. Content search
  4. Use data search
Show answer and explanation

Correct answer: B. Activity explorer

Activity explorer in the Microsoft Purview portal keeps 30 days of label activity for the tenant, including retention labels that were applied, changed, or removed, along with the user, file, and location involved. You can filter by activity type and label name to isolate exactly which retention label changes occurred. This is the built-in view for reviewing recent labeling activity.

Why the other options are wrong

  • A. Reports give aggregated dashboards and trends rather than the per-item label activity records needed here.
  • C. Content search locates content that matches query criteria, it does not report on labeling activity.
  • D. Data search is not a Purview tool for reviewing retention label activity.

That was 10 of 280.

The full Microsoft SC-401 pack has all 280 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.

Get the full pack