Microsoft

SC-400 Free Practice Questions

This is the free Microsoft SC-400 practice question bank — 160 of 318 total questions, each with a full explanation, free to read with no signup required. Updated 2026-08-06.

Every answer is verified against official Microsoft documentation — see our methodology.

Question 1

HOTSPOT - You have a Microsoft 365 E5 subscription that contains three users named User1, User2, and User3. The subscription contains the groups shown in the following table. The subscription contains the devices shown in the following table. All the devices are onboarded to Microsoft Purview. You have the data loss prevention (DLP) policies shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 1 Illustration for SC-400 question 1 Illustration for SC-400 question 1 Illustration for SC-400 question 1
Show Answer
Correct Answer: Yes No No
Explanation:
USB device restrictions apply on supported Windows endpoints for the assigned user. Clipboard restriction is not enforced on Android endpoint DLP in this scenario. Restricting access to Microsoft 365 locations is not applicable as stated for macOS SharePoint Online access here.

Question 2

HOTSPOT - You have a Microsoft 365 E5 subscription. You plan to implement Microsoft Purview insider risk management. You need to recommend policy templates that meet the following requirements: • Contain risk indicators and scoring for when a user receives a poor performance review. • Contain risk indicators and scoring for when a user disables security features on a device. Which template should you use for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 2
Show Answer
Correct Answer: When a user receives a poor performance review: Security policy violations by risky users When a user disables security features: Security policy violations by risky users
Explanation:
The 'Security policy violations by risky users' template uses HR risk signals (such as poor performance review) together with security policy violation indicators, including actions like disabling security features on devices.

Question 3

You have a Microsoft 365 E5 subscription. Microsoft Purview Compliance Manager has the improvement actions shown in the following table. Automatic testing is disabled for all improvement actions. For which improvement actions can you update the Test status?

A. Action1 only
B. Action2 only
C. Action2 and Action3 only
D. Action1 and Action4 only
E. Action1, Action2, Action3 and Action4
Show Answer
Correct Answer: C
Explanation:
In Microsoft Purview Compliance Manager, when automatic testing is disabled, the Test status can be manually updated only for improvement actions that have been implemented or use an alternative implementation. It cannot be updated for actions that are not implemented or are otherwise ineligible for testing. Therefore, the applicable actions are Action2 and Action3.

Question 4

HOTSPOT - You have a Microsoft 365 subscription that has a retention label named Retention1. The subscription contains the files shown in the following table. You create an auto-labeling policy named Policy1 that will automatically apply Retention1 as shown in the Auto-labeling policy exhibit. (Click the Auto-labeling policy tab.) You configure Policy1 to apply Retention1 as shown in the Locations exhibit. (Click the Locations tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 4 Illustration for SC-400 question 4 Illustration for SC-400 question 4 Illustration for SC-400 question 4
Show Answer
Correct Answer: File1: No File2: Yes File3: No
Explanation:
The policy applies if either group matches. Group1 requires at least 1 IP Address AND at least 3 SWIFT codes. Group2 requires at least 2 Azure SAS instances. The policy is enabled for Exchange and SharePoint, but not OneDrive. File1 (Exchange) fails Group1 but meets Group2 (SAS=4). File2 (SharePoint) meets Group1 (IP=3, SWIFT=5). File3 is in OneDrive, which is excluded.

Question 5

You have a Microsoft 365 E5 subscription. You plan to create an exact data match (EDM) classifier named EDM1. You need to grant permissions to hash and upload the sensitive information source table for EDM1. What should you create first?

A. a Microsoft Entra app registration named EDM_DataUploaders
B. a security group named EDM_DataUploaders
C. a Microsoft Entra enterprise application named EDM_DataUploaders
D. a Microsoft 365 group named EDM_DataUploaders
E. a Microsoft Purview role group named EDM_DataUploaders
Show Answer
Correct Answer: B
Explanation:
For Exact Data Match (EDM), before hashing and uploading the sensitive information source table, you create a Microsoft Entra security group to designate the data uploaders. Members of this security group are granted permission to use the EDM hashing and upload tools. This is a prerequisite in the EDM setup workflow.

Question 6

You have a Microsoft 365 E5 subscription that uses retention label policies. You need to identify all the changes made to retention labels during the last 30 days. What should you use in the Microsoft Purview compliance portal?

A. User data search
B. Reports
C. Content search
D. Activity explorer
Show Answer
Correct Answer: D
Explanation:
Activity explorer in the Microsoft Purview compliance portal provides visibility into compliance-related user and system activities, including retention label events and changes over a selected time period. User data search and Content search are for locating content, while Reports provides aggregated reporting rather than detailed activity logs of label changes.

Question 7

You have a Microsoft 365 E5 subscription. You have a Microsoft Entra tenant named contoso.com. Your company collaborates with a partner company that has a Microsoft Entra tenant named fabrikam.com. You need to ensure that email sent to fabrikam.com always uses TLS and is sent only if the email server certificate of fabrikam.com is validated. What should you do?

A. From the Exchange admin center, create a connector.
B. From the Microsoft Purview compliance portal, create a communication compliance policy.
C. From the Microsoft Purview compliance portal, create a sensitivity label policy.
D. From the Exchange admin center, create a remote domain.
E. From the Microsoft Defender portal, enable DomainKeys Identified Mail (DKIM).
Show Answer
Correct Answer: A
Explanation:
An Exchange Online mail flow connector can require TLS for messages sent to a specific partner domain and validate the partner's TLS certificate (for example, by matching the certificate subject or domain). Remote domains do not enforce TLS or certificate validation, and the Purview and DKIM options are unrelated to mandatory partner TLS transport.

Question 8

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the resources shown in the following table. You are creating a retention label named Retention1. You configure the following stages and reviewers for Retention1: • Stage name: Stage1 • Reviewers for this stage: Group4 • Stage name: Stage2 • Reviewers for this stage: User1 Which resources can you add as additional Stage1 and Stage2 reviewers? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 8 Illustration for SC-400 question 8
Show Answer
Correct Answer: Stage1: User1 and Group3 only Stage2: Group3 and Group4 only
Explanation:
Disposition review reviewers can be individual users or mail-enabled security groups. Microsoft 365 groups and non-mail-enabled security groups aren't supported. Additional reviewers can be added, but the same reviewer can't be assigned across different stages.

Question 9

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You recently discovered that the developers at your company emailed Azure Storage keys in plain text to third parties. You need to ensure that when Azure Storage keys are emailed, the emails are encrypted. Solution: You create a data loss prevention (DLP) policy that has Exchange email, SharePoint sites, OneDrive accounts, and Teams chat and channel messages selected. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
No. A DLP policy can encrypt Exchange email only when the appropriate Exchange-specific encryption action is configured. If the policy scope includes SharePoint, OneDrive, and Teams together, the email encryption action is not available for the rule, so simply creating a DLP policy covering all those locations does not ensure emailed Azure Storage keys are encrypted.

Question 10

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1 and the data loss prevention (DLP) policies shown in the following table. The DLP rules are configured as shown in the following table. All the policies are assigned to Site1. You need to ensure that if a user uploads a document to Site1 that matches all the rules, the user will be shown the Tip 2 policy tip. What should you do?

A. Change the priority of DLP2 to 3.
B. Prevent additional processing of the policies if there is a match for Rule2.
C. Enable additional processing of the policies if there is a match for Rule1.
D. Change the priority of DLP2 to 0.
Show Answer
Correct Answer: D
Explanation:
When multiple DLP policies apply to the same content, policy priority determines which policy tip is shown. To ensure the user sees Tip 2 from DLP2 when all rules match, DLP2 must have the highest priority. Setting its priority to 0 makes it the highest-priority policy. The other options either lower its priority or change rule-processing behavior rather than ensuring Tip 2 is displayed.

$19

Get all 318 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.