Browse all practice questions for the Microsoft Administering Information Security (SC-401) Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Ace the Microsoft SC-401 in 2026 – Your Ultimate Admin Security Adventure! course image
All questions

These questions are part of the practice quiz. Start practicing

  • What is a sensitive information type (SIT)?
  • What does the Secure Score measure?
  • What type of violations does a DLP alert policy specifically address?
  • How does Safe Attachments enhance email security?
  • Why is user education important in cybersecurity?
  • What is typically necessary for longer audit log retention to meet compliance needs?
  • What function does Azure Key Vault serve?
  • What Microsoft 365 feature ensures only people in Finance can open a document, even if it's emailed outside the company?
  • What is the primary purpose of Communication Compliance in Purview?
  • What is a benefit of using secure sharing settings in Microsoft 365?
  • What does Conditional Access App Control provide?
  • What function does Entra Connect serve?
  • Why is it crucial to apply DLP policies across multiple platforms?
  • What does Microsoft Purview Information Protection (MIP) aim to achieve?
  • What aspect of security does Microsoft Teams focus on?
  • How does Microsoft Purview assist in compliance management?
  • What is the purpose of eDiscovery in Microsoft 365?
  • What security features does Microsoft Teams provide?
  • What does double-key encryption in Microsoft 365 require?
  • What effect does 'record' mode have when applied via retention labeling?
  • What is a key advantage of using Azure Key Vault?
  • Why might a data loss prevention (DLP) system fail to detect sensitive information in an email containing an image?
  • What is a risk policy?
  • What is the first step to prevent credit card numbers from being sent externally via email?
  • What is the function of Microsoft Defender for Office 365 Safe Attachments?
  • What provides watermarking and 'Do Not Forward' behavior on labeled emails?
  • What built-in practice supports privacy-by-design when monitoring insider risk?
  • What is Microsoft Information Protection (MIP)?
  • What is the purpose of the DLP simulation mode?
  • What is the primary goal of penetration testing?
  • What is the significance of security policies in an organization?
  • How can emails labeled as 'Confidential' have readable headers for third-party systems?
  • What is a key feature of sensitivity labels in Microsoft 365?
  • What is the purpose of sensitivity labels?
  • What does the Activity Explorer primarily monitor?
  • How can regular audits benefit data integrity?
  • What is the purpose of Azure AD B2C?
  • What does 'data loss prevention' (DLP) primarily focus on?
  • What is the purpose of a compliance center in Microsoft 365?
  • What role does auditing play in retention policies?
  • How do you conduct a risk assessment in Microsoft 365?
  • Which aspect does Insider Risk Management NOT focus on?
  • Which tool can help in assessing compliance status in Microsoft 365?
  • Which Endpoint DLP method is used to block 'Confidential' content from USB drives?
  • What is the function of Data Loss Prevention (DLP) policies?
  • What is the purpose of Azure AD Domain Services?
  • What is a legal hold in data management?
  • Which scenario best describes Conditional Access?
  • What is a common challenge of implementing DLP policies?
  • What is the function of a DLP policy tip?
  • What is the main functionality of Azure Security Center?
  • What is the function of Identity Protection?
  • How does a trainable classifier learn to detect content?
  • In Microsoft 365, what is the function of a legal hold?
  • What purpose does the Activity Explorer serve in a security context?
  • What is a primary benefit of applying a location-based retention policy?
  • Which Purview solution aids in finding all Teams chats for a custodian during an investigation?
  • Which of the following could prevent labels from appearing in Word?
  • What can administrators view using the Content Explorer?
  • What is the role of Microsoft Purview Information Protection?
  • What evidence is relevant to prove retention prevented deletion during an investigation?
  • What is the purpose of applying a sensitivity label to a SharePoint site?
  • Which feature requires approval before a document can be deleted after the retention period has ended?
  • How does encryption enhance data security?
  • How does Microsoft Defender for Cloud enhance security?
  • What is a key use of sensitivity labels in email communications?
  • What does the term 'insider threat' refer to?
  • How can organizations enforce data retention policies in Microsoft 365?
  • What does Zero-hour Auto Purge (ZAP) do?
  • What is a common strategy to improve accuracy when a DLP policy is matching too many false positives?
  • How can you prevent users from sharing files labeled 'Highly Confidential' with external users in SharePoint/OneDrive?
  • What method can be used to prevent users from improperly labeling data as 'Public'?
  • What is an effective approach to monitor for suspicious activities?
  • Why is data classification important for organizations?
  • What is the purpose of the Microsoft Purview portal?
  • What is Endpoint DLP designed to control?
  • What is required for auto-labeling to apply sensitivity labels to SharePoint files?
  • What is the primary function of Customer Lockbox in Microsoft services?
  • How does monitoring third-party vendor compliance aid in risk management?
  • What is the role of Microsoft Defender for Cloud?
  • What is the purpose of Microsoft Defender for Office 365 Safe Links?
  • What is a key purpose of a DLP policy?
  • Why are regular security assessments important?
  • What is the significance of compliance frameworks?
  • Which solution is designed to detect and manage potential data theft by trusted insiders?
  • What is the function of Safe Links?
  • What is the primary purpose of data classification?
  • What is an Anti-Phishing policy aimed at?
  • Which method is effective in retroactively applying labels to files in OneDrive?
  • What is the purpose of incident response planning?
  • What is the main function of document fingerprinting?
  • Which service provides advanced protective measures against cyber threats targeting devices?
  • What is the function of Microsoft Defender for Cloud Apps?
  • How does Microsoft Sentinel support organizations?
  • What capability does Defender for Endpoint provide?
  • When should regular audits for GDPR compliance ideally occur?
  • What is the method used to apply a retention period of 7 years to all emails, even if deleted by users?
  • What does Exact Data Match (EDM) primarily identify?
  • What function does Safe Links serve in Defender for Office 365?
  • What is the function of Microsoft 365 Compliance Manager?
  • What approach should be used to apply a label when a document includes specific keywords alongside sensitive information like employee IDs?
  • Why is integration of on-premises and cloud identities important?
  • What does the endpoint detection capability of Microsoft Defender for Endpoint help to identify?
  • What is the Threat Explorer used for?
  • What measures can help protect against phishing attacks?
  • What type of information does Microsoft Purview Risk Management primarily focus on?
  • What is the role of Microsoft Secure Score?
  • What should be done to mitigate risks associated with insider threats?
  • What is the primary purpose of Conditional Access?
  • How is user risk different from sign-in risk?
  • What is the main purpose of Information Barriers in Microsoft 365?
  • What is the primary focus of Data Loss Prevention (DLP)?
  • What is the difference between eDiscovery Standard and Premium?
  • What is the function of a security information and event management (SIEM) system?
  • What does the Audit log record?
  • What is the primary goal of Safe Attachments in Defender for Office 365?
  • What is auto-labeling?
  • What do you use to monitor potentially inappropriate language or harassment in Teams messages?
  • What does the Compliance Manager tool provide?
  • How can you prevent external sharing on a sensitive project site?
  • What is the primary role of firewalls in network security?
  • What is the primary purpose of Advanced Audit?
  • What does Microsoft Secure Score measure?
  • What capability does Microsoft Cloud App Security (Defender for Cloud Apps) provide?
  • What is the importance of monitoring communications for policy violations?
  • What is the purpose of an incident response plan?
  • What is the significance of logging and monitoring in information security?
  • Why might a file labeled Confidential still allow anyone to open it?
  • What is the purpose of security awareness training?
  • What is the significance of audit logs in Microsoft 365?
  • What does Microsoft Defender for Office 365 aim to protect users from?
  • What is the purpose of Microsoft 365 Data Loss Prevention?
  • What do DLP policies aim to prevent?
  • What is the main purpose of conducting vulnerability assessments?
  • What is the best method for alerting when a user downloads a significantly high number of files from SharePoint?
  • What function does the Audit log serve in Microsoft 365?
  • What role does risk assessment play in information security?
  • What does Insider Risk Management in Purview do?
  • How can data integrity be ensured in Microsoft 365?
  • Which of the following is a benefit of using Microsoft Defender for Office 365?
  • What is the purpose of Azure AD Conditional Access?
  • What is the role of Microsoft 365 Compliance Solutions?
  • What is a DLP alert policy?
  • What is the primary function of Content Search in Microsoft Purview?
  • What additional features does eDiscovery Premium offer compared to Standard?
  • What does the Microsoft 365 Security Center monitor?
  • What is the main distinction between eDiscovery Standard and Premium?
  • What does Microsoft Defender for Endpoint primarily provide?
  • Where can DLP policies be applied within Microsoft 365?
  • What is the function of Microsoft Defender for Endpoint?
  • What does Privileged Identity Management (PIM) provide?
  • Which feature helps to enhance overall security by granting access only under secure conditions?
  • What is a label policy?
  • What is the role of user training in information security?
  • How does Continuous Access Evaluation (CAE) enhance security?
  • What aspect of information security is highlighted by MFA?
  • What is one effective strategy for implementing password policies?
  • What feature prevents two groups from communicating in Teams/SharePoint during a deal?
  • What is the main function of Identity Protection in Microsoft Entra ID?
  • Which feature helps in analyzing the effectiveness of security protocols in your organization?
  • What additional step can be taken if a user is allowed to override a DLP block?
  • What control helps extend DLP policies to endpoints?
  • What is the purpose of Microsoft 365 Security Center?
  • What are sensitivity labels primarily used for?
  • Which tool provides detailed audit events with longer retention periods?
  • What is Multi-Factor Authentication (MFA)?
  • What does MFA stand for in the context of information security?
  • What does implementing DLP in test mode allow organizations to do?
  • What benefit does multi-factor authentication (MFA) provide to Microsoft 365 accounts?
  • What is Attack Simulation Training designed to achieve?
  • What is the purpose of sensitivity labels in Microsoft 365?
  • What is the primary function of a sensitive information type (SIT)?
  • How does Safe Links enhance security for users?
  • What is the safest way to roll out strict Data Loss Prevention (DLP) controls?
  • What type of sensitive information can trigger a DLP policy in Exchange?
  • What is the function of multi-factor authentication (MFA)?
  • What is a DLP override?
  • What is the main purpose of Microsoft Purview Compliance Manager?
  • What distinguishes auto-labeling from recommended labeling?
  • What is Double Key Encryption (DKE) designed to enhance?
  • Why is testing DLP policies important before full enforcement?
  • Which feature aims to block malicious links in emails and documents?
  • What are Conditional Access templates?
  • What is a trainable classifier used for in Microsoft Purview?
  • Where can you centrally manage sensitivity labels, DLP, and retention in modern Microsoft 365?
  • Why might a PDF not retain the same label protections as the original Word file after export?
  • What combination helps detect and block sharing of 'Confidential' files to unmanaged devices?
  • How can you retroactively apply labels to previously stored content in SharePoint?
  • What does the assessment of user risk typically involve?
  • What does Insider Risk Management primarily detect?
  • How can you implement a zero-trust security model in Microsoft 365?
  • Which action allows DLP to block messages while enabling users to override with justification?
  • What is the purpose of authentication strength policies?
  • What is the role of Microsoft Intune?
  • What is used to preserve content for a specific user under investigation?
  • What role do automated compliance solutions play?
  • Why is data backup and recovery essential for organizations?
  • What does the term 'data governance' refer to?
  • What is a key method for managing third-party risks in Microsoft 365?
  • What is Conditional Access in Microsoft Entra ID?
  • What benefit does implementing data validation processes provide?
  • What must be configured in Outlook to suggest applying a sensitivity label when an email contains a U.S. Social Security Number?
  • How can a security team be alerted when DLP blocks an email?
  • Compliance gaps can be identified and corrective actions can be taken using which Microsoft tool?
  • What is a trainable classifier in the context of information security?
  • What is a key benefit of using Communication Compliance?
  • What is the purpose of access controls in information security?
  • Where can Data Loss Prevention (DLP) policies be effectively applied?
  • What is the purpose of the Content Explorer tool?
  • What distinguishes EOP from Defender for Office 365?
  • What function does Microsoft Defender for Identity serve?
  • What is the role of retention policies in Microsoft 365?
  • What is the purpose of Microsoft Purview Risk Management?
  • What is the main objective of a security audit?
  • What action can be taken when users incorrectly apply sensitivity labels?
  • What is the primary function of the Submissions portal?
  • Which capability helps to track who accessed and downloaded a sensitive file?
  • What role does threat intelligence play in cybersecurity?
  • What type of actions are documented in a DLP incident report?
  • What is a crucial component of protecting data at rest?
  • Which of the following describes a sensitivity labeling policy?
  • For applying different retention rules based on the type of content, which solution should be utilized?
  • How can you protect sensitive data in transit?
  • What constitutes a DLP incident report?
  • What approach is used to detect a proprietary internal ID format?
  • What is the importance of logging and monitoring in security?
  • What is the benefit of utilizing Double Key Encryption (DKE)?
  • What is eDiscovery Standard primarily used for?
  • What type of retention policy applies to content based on location?
  • What does Azure AD Identity Protection aim to accomplish?
  • What is the outcome of using Zero-hour Auto Purge (ZAP)?
  • What is the function of Communication Compliance?
  • How do sensitivity labels differ from retention labels?
  • What is the importance of user training in information security?
  • How can a retention policy be applied to Teams channel messages to ensure they are stored for three years?
  • In terms of user risk, what does a risk policy provide?
  • How can organizations ensure secure collaboration in Microsoft 365?
  • What is the purpose of the Service Trust Portal?
  • Which solution provides protections specifically against email threats?
  • How can you manage insider threats in Microsoft 365?
  • How do you ensure compliance with GDPR in Microsoft 365?
  • What does Information Barriers feature accomplish?
  • What is the function of Microsoft Defender for Cloud?
  • Which of the following best describes Microsoft Defender for Office 365?
  • How can you ensure that only specific security group members can apply a 'Top Secret' label?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy