Microsoft

SC-400 Free Practice Questions

This is the free Microsoft SC-400 practice question bank — 160 of 316 total questions, each with a full explanation, free to read with no signup required. Updated 2026-04-24.

Every answer is verified against official Microsoft documentation — see our methodology.

Question 1

HOTSPOT - You have a Microsoft 365 E5 subscription. You plan to implement Microsoft Purview insider risk management. You need to recommend policy templates that meet the following requirements: • Contain risk indicators and scoring for when a user receives a poor performance review. • Contain risk indicators and scoring for when a user disables security features on a device. Which template should you use for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 1
Show Answer
Correct Answer: When a user receives a poor performance review: Security policy violations by risky users When a user disables security features: Security policy violations
Explanation:
Poor performance review is a user risk signal used by the **Security policy violations by risky users** template. Disabling security features (for example, tampering with protections) is monitored under the **Security policy violations** template.

Question 1

HOTSPOT - You have a Microsoft 365 E5 subscription that contains three users named User1, User2, and User3. The subscription contains the groups shown in the following table. The subscription contains the devices shown in the following table. All the devices are onboarded to Microsoft Purview. You have the data loss prevention (DLP) policies shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 1 Illustration for SC-400 question 1 Illustration for SC-400 question 1 Illustration for SC-400 question 1
Show Answer
Correct Answer: Yes No No
Explanation:
User1 is in Group1, which has a DLP policy restricting copying data to USB devices, and Device1 (Windows) supports this restriction. User2 is in Group2, but clipboard restrictions are not supported/enforced on Android devices. Although User3 is in Group3, endpoint DLP does not block access to Microsoft 365 (SharePoint Online) content on macOS in this scenario.

Question 2

You have a Microsoft 365 E5 subscription. Microsoft Purview Compliance Manager has the improvement actions shown in the following table. Automatic testing is disabled for all improvement actions. For which improvement actions can you update the Test status?

A. Action1 only
B. Action2 only
C. Action2 and Action3 only
D. Action1 and Action4 only
E. Action1, Action2, Action3 and Action4
Show Answer
Correct Answer: C
Explanation:
When Automatic testing is disabled, you can manually update the Test status only for improvement actions that are marked as Implemented or have an Alternative implementation. Action2 is Implemented, and Action3 uses an Alternative implementation. Action1 and Action4 do not meet these conditions, so their Test status cannot be updated.

Question 3

HOTSPOT - You have a Microsoft 365 subscription that has a retention label named Retention1. The subscription contains the files shown in the following table. You create an auto-labeling policy named Policy1 that will automatically apply Retention1 as shown in the Auto-labeling policy exhibit. (Click the Auto-labeling policy tab.) You configure Policy1 to apply Retention1 as shown in the Locations exhibit. (Click the Locations tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 3 Illustration for SC-400 question 3 Illustration for SC-400 question 3 Illustration for SC-400 question 3
Show Answer
Correct Answer: Retention1 is applied to File1: Yes Retention1 is applied to File2: Yes Retention1 is applied to File3: No
Explanation:
Auto-labeling applies if content matches (Group1: IP ≥1 AND SWIFT ≥3) OR (Group2: Azure SAS ≥2), and only in included locations. File1 (Exchange): Meets Group2 (SAS=4) → applied. File2 (SharePoint): Meets Group1 (IP=3, SWIFT=5) → applied. File3 (OneDrive): Location excluded → not applied.

Question 4

You have a Microsoft 365 E5 subscription. You plan to create an exact data match (EDM) classifier named EDM1. You need to grant permissions to hash and upload the sensitive information source table for EDM1. What should you create first?

A. a Microsoft Entra app registration named EDM_DataUploaders
B. a security group named EDM_DataUploaders
C. a Microsoft Entra enterprise application named EDM_DataUploaders
D. a Microsoft 365 group named EDM_DataUploaders
E. a Microsoft Purview role group named EDM_DataUploaders
Show Answer
Correct Answer: B
Explanation:
For Exact Data Match (EDM), permissions to hash and upload the source data are granted to a **security group**. Microsoft Purview requires you to create a security group (commonly named EDM_DataUploaders) first, then assign that group the appropriate EDM Data Upload role so its members can hash and upload the sensitive information table.

Question 5

You have a Microsoft 365 E5 subscription that uses retention label policies. You need to identify all the changes made to retention labels during the last 30 days. What should you use in the Microsoft Purview compliance portal?

A. User data search
B. Reports
C. Content search
D. Activity explorer
Show Answer
Correct Answer: D
Explanation:
Activity explorer in the Microsoft Purview compliance portal provides detailed auditing and visibility into compliance-related activities, including changes made to retention labels. It allows you to review and filter label modifications over a specific time range, such as the last 30 days.

Question 6

You have a Microsoft 365 E5 subscription. You have a Microsoft Entra tenant named contoso.com. Your company collaborates with a partner company that has a Microsoft Entra tenant named fabrikam.com. You need to ensure that email sent to fabrikam.com always uses TLS and is sent only if the email server certificate of fabrikam.com is validated. What should you do?

A. From the Exchange admin center, create a connector.
B. From the Microsoft Purview compliance portal, create a communication compliance policy.
C. From the Microsoft Purview compliance portal, create a sensitivity label policy.
D. From the Exchange admin center, create a remote domain.
E. From the Microsoft Defender portal, enable DomainKeys Identified Mail (DKIM).
Show Answer
Correct Answer: A
Explanation:
To ensure email to a specific external domain always uses TLS and is delivered only when the recipient server’s certificate is validated, you must configure an Exchange Online connector. An outbound connector in the Exchange admin center can be scoped to fabrikam.com and configured to require TLS with certificate validation. Other options (remote domains, Purview policies, DKIM) do not enforce mandatory TLS with certificate validation.

Question 7

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the resources shown in the following table. You are creating a retention label named Retention1. You configure the following stages and reviewers for Retention1: • Stage name: Stage1 • Reviewers for this stage: Group4 • Stage name: Stage2 • Reviewers for this stage: User1 Which resources can you add as additional Stage1 and Stage2 reviewers? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 7 Illustration for SC-400 question 7
Show Answer
Correct Answer: Stage1: User1 and Group3 only Stage2: Group3 and Group4 only
Explanation:
Disposition review stages support individual users and mail-enabled security groups only. Microsoft 365 groups and non-mail-enabled security groups aren’t supported. Reviewers also can’t be reused across different stages in conflicting ways, so only the listed combinations are valid.

Question 8

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You recently discovered that the developers at your company emailed Azure Storage keys in plain text to third parties. You need to ensure that when Azure Storage keys are emailed, the emails are encrypted. Solution: You create a data loss prevention (DLP) policy that has Exchange email, SharePoint sites, OneDrive accounts, and Teams chat and channel messages selected. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
No. Simply creating a DLP policy that includes Exchange, SharePoint, OneDrive, and Teams does not ensure email encryption. When multiple locations are selected, the DLP rule action to encrypt email is not available. Therefore, the policy would not guarantee that emails containing Azure Storage keys are encrypted, so the goal is not met.

Question 9

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1 and the data loss prevention (DLP) policies shown in the following table. The DLP rules are configured as shown in the following table. All the policies are assigned to Site1. You need to ensure that if a user uploads a document to Site1 that matches all the rules, the user will be shown the Tip 2 policy tip. What should you do?

A. Change the priority of DLP2 to 3.
B. Prevent additional processing of the policies if there is a match for Rule2.
C. Enable additional processing of the policies if there is a match for Rule1.
D. Change the priority of DLP2 to 0.
Show Answer
Correct Answer: D
Explanation:
When multiple DLP policies apply to the same location, SharePoint evaluates them by priority, with the lowest number having the highest priority. To ensure that Tip 2 is shown when all rules match, the policy that contains the rule generating Tip 2 (DLP2) must have the highest priority. Setting DLP2’s priority to 0 ensures it is evaluated first and its policy tip is displayed.

$19

Get all 316 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.