SC-400: Microsoft Certified: Information Protection and Compliance Administrator Associate — Questions and Answers
Question 1: A user permanently deletes a file from OneDrive that is subject to an active retention policy. Where is the file preserved?
- In a centralized compliance archive in SharePoint
- In the Preservation Hold library within the user's OneDrive (Correct answer)
- In the user's archive folder
- In Azure Blob Storage
Correct answer: In the Preservation Hold library within the user's OneDrive
OneDrive uses a Preservation Hold library (a hidden library within the user's OneDrive) to retain content deleted by users when a retention policy applies.
Question 2: Which Insider Risk Management feature allows an investigator to send a reminder or warning directly to a user whose behavior triggered an alert, without escalating to HR?
- User activity report
- Notice templates (Correct answer)
- Alert feedback
- Case notes
Correct answer: Notice templates
Notice templates allow investigators to send pre-written email notifications to users as a corrective action option directly from within a case.
Question 3: What is the effect of enabling the 'delete content older than' action without enabling 'retain content' in a Microsoft Purview retention policy?
- An error occurs because both settings must be enabled together
- Content is only deleted when older than the specified age, with no protection during the period (Correct answer)
- Content is retained and then deleted after the specified period
- Content is moved to an archive and deleted after expiration
Correct answer: Content is only deleted when older than the specified age, with no protection during the period
A delete-only action removes content older than the specified age but does not protect content from early deletion during that period.
Question 4: Which of the following actions allows an administrator to test the impact of a retention policy before it actively retains or deletes content?
- Apply the policy to a test Microsoft 365 Group
- Enable Preservation Lock on the policy
- Set the policy to simulation mode (Correct answer)
- Use Content Explorer to preview affected items before publishing
Correct answer: Set the policy to simulation mode
Simulation mode (available for adaptive scopes) lets administrators preview which content and locations would be affected by a retention policy before it goes live.
Question 5: What is the minimum retention duration that can be configured in a Microsoft Purview retention policy?
- 30 days
- 1 year
- 1 day (Correct answer)
- 7 days
Correct answer: 1 day
Microsoft Purview retention policies support a minimum retention period of 1 day.
Question 6: An organization wants to quantify the potential financial impact of a data breach to prioritize remediation. Which approach aligns with risk assessment best practices for SC-400?
- Use only qualitative risk ratings (high/medium/low)
- Run Microsoft Secure Score and use it as the financial risk figure
- Combine asset sensitivity classification with likelihood and impact scoring (Correct answer)
- Rely solely on Compliance Manager scores for financial impact
Correct answer: Combine asset sensitivity classification with likelihood and impact scoring
Effective data risk assessment combines sensitivity classification with likelihood and impact scoring to quantify potential financial exposure.
Question 7: Which Microsoft Defender for Office 365 plan (Plan 1 vs Plan 2) includes Threat Trackers and Attack Simulator?
- Both Plan 1 and Plan 2
- Plan 2 only (Correct answer)
- Neither; these require Microsoft 365 Defender
- Plan 1 only
Correct answer: Plan 2 only
Threat Trackers, Attack Simulator, and automated investigation and response (AIR) are Plan 2 features not included in Plan 1.
Question 8: How can compliance risks be monitored in real-time?
- By monitoring compliance status using automated tools. (Correct answer)
- By checking reports annually.
- By outsourcing risk management.
- By allowing employees to handle compliance on their own.
Correct answer: By monitoring compliance status using automated tools.
Compliance risks can be monitored in real-time by utilizing automated tools and systems that continuously track activities, configurations, and data flows against defined policies and regulations. These tools can detect deviations or suspicious behaviors instantly, providing immediate alerts to compliance officers. This proactive approach allows for rapid response to potential non-compliance issues, significantly reducing exposure and impact.
Question 9: An organization needs to retain Yammer community messages for 5 years. Which location should be configured in the retention policy?
- Yammer community messages (Correct answer)
- SharePoint sites
- Microsoft Teams channel messages
- Exchange email
Correct answer: Yammer community messages
Yammer community messages are a distinct location type in Microsoft Purview retention policies and must be explicitly selected.
Question 10: When configuring an audit log search, which date/time zone do the start and end times correspond to?
- The administrator's local time zone
- The tenant's registered country time zone
- UTC (Coordinated Universal Time) (Correct answer)
- Pacific Standard Time (PST)
Correct answer: UTC (Coordinated Universal Time)
All audit log timestamps in Microsoft Purview use UTC, so search date/time parameters must be specified in UTC.
Question 11: A company needs to ensure that all email sent by financial advisors containing the word 'guarantee' is captured for review. Which condition type in Communication Compliance best addresses this requirement?
- Threat condition
- Profanity condition
- Sensitive information type condition
- Keyword condition (Correct answer)
Correct answer: Keyword condition
The keyword condition in Communication Compliance policies captures messages containing specific words or phrases, such as 'guarantee,' for review.
Question 12: When a SC-400 professional identifies a potential regulatory violation, the CORRECT first step is to:
- Discuss it casually with coworkers
- Address it only if directly affected
- Document the violation and report it through proper channels (Correct answer)
- Wait to see if it resolves on its own
Correct answer: Document the violation and report it through proper channels
Proper documentation and reporting through established channels is the correct first step when identifying a potential violation. This ensures accountability, creates a paper trail, and allows appropriate parties to investigate and resolve the issue.
Question 13: An organization wants to classify email attachments containing financial data in Exchange Online using auto-labeling. Which condition type should be configured in the auto-labeling policy?
- Label conditions based on content type
- Message classification headers
- Sender domain rules
- Sensitive information types detected in attachment content (Correct answer)
Correct answer: Sensitive information types detected in attachment content
Auto-labeling policies for Exchange can be configured to detect sensitive information types within email body and attachment content to trigger label application.
Question 14: In SC-400 certification, what is the primary purpose of regulatory compliance programs?
- To ensure adherence to laws and standards (Correct answer)
- To eliminate competition
- To increase revenue
- To reduce staffing needs
Correct answer: To ensure adherence to laws and standards
Regulatory compliance programs are designed to ensure organizations follow applicable laws, regulations, and standards.
Question 15: What is the maximum number of custom sensitive information types that can be created per Microsoft 365 tenant?
- 500 (Correct answer)
- 50
- 100
- 1000
Correct answer: 500
Each Microsoft 365 tenant can have up to 500 custom sensitive information types in addition to the built-in types provided by Microsoft.
Question 16: A compliance team wants to use Communication Compliance to detect potential collusion between traders at different firms. Which condition type is specifically designed to help identify this risk?
- Regulatory collusion trainable classifier (Correct answer)
- Profanity condition
- Threat condition
- Sensitive information type condition for financial data
Correct answer: Regulatory collusion trainable classifier
Microsoft Purview's 'Regulatory Collusion' trainable classifier is designed to detect language indicative of potential collusion, such as market manipulation discussions.
Question 17: What is the primary benefit of high-value audit events available in Microsoft Purview Audit (Premium)?
- They provide granular mail access events like MailItemsAccessed for forensic investigation (Correct answer)
- They extend retention to 10 years automatically
- They allow real-time streaming to Azure Event Hub
- They replace the need for Microsoft Sentinel integration
Correct answer: They provide granular mail access events like MailItemsAccessed for forensic investigation
Audit (Premium) includes high-value events such as MailItemsAccessed, which provide detailed forensic data for investigating email compromise.
Question 18: An admin configures a retention label with 'Start the retention period based on: When items were labeled.' Which scenario best illustrates the use of this trigger?
- Retention begins when the document was last modified by any user
- The label's retention period starts when the document is first shared externally
- A project file's retention clock starts from when the project was created
- A contract is scanned and labeled on receipt, starting a 10-year retention clock immediately (Correct answer)
Correct answer: A contract is scanned and labeled on receipt, starting a 10-year retention clock immediately
Using the label application date as the trigger is ideal when the clock should begin at the moment of classification, such as when a document enters the records system.
Question 19: Which skill is most critical for effective records management?
- Speed of decision-making
- Technical expertise alone
- Communication and stakeholder engagement (Correct answer)
- Individual work preferences
Correct answer: Communication and stakeholder engagement
Communication and stakeholder engagement are essential because management success depends on effectively coordinating with and influencing others.
Question 20: Which regulatory requirement is UNIVERSAL across all Microsoft Certified Information Protection and Compliance Administrator Associate practice settings?
- Limiting services to local jurisdictions only
- Maintaining current certification and meeting continuing education requirements (Correct answer)
- Using specific proprietary software systems
- Working exclusively during business hours
Correct answer: Maintaining current certification and meeting continuing education requirements
Maintaining current certification and meeting continuing education requirements is a universal regulatory requirement. Regardless of practice setting, professionals must keep their credentials current and demonstrate ongoing competency through continuing education.
Question 21: Why is auditing important for information governance?
- It reduces the amount of data stored.
- It only records data storage locations.
- It ensures compliance and identifies security risks. (Correct answer)
- It helps to track only user activity.
Correct answer: It ensures compliance and identifies security risks.
Auditing is crucial for information governance because it provides a verifiable record of data access, modification, and deletion activities. This record helps organizations ensure compliance with internal policies and external regulations by demonstrating how data is handled. Furthermore, auditing helps identify potential security risks, unauthorized access attempts, or policy violations, allowing for timely investigation and remediation.
Question 22: A company needs to classify files based on the exact employee IDs stored in their HR database. Which sensitive information type approach provides the most accurate matching for this scenario?
- Exact Data Match (EDM) sensitive information types (Correct answer)
- Custom regex-based sensitive information types
- Built-in sensitive information types
- Trainable classifiers
Correct answer: Exact Data Match (EDM) sensitive information types
EDM sensitive information types match content against an uploaded table of exact values, making them ideal for matching against specific organizational data like employee IDs.
Question 23: Which action in Compliance Manager allows an organization to document that a recommended action is handled through an alternative control not listed?
- Mark the action as 'Resolved through alternate implementation'
- Mark the action as 'Not in scope'
- Delete the improvement action from the assessment
- Set the implementation status to 'Third party' (Correct answer)
Correct answer: Set the implementation status to 'Third party'
Setting the implementation status to 'Third party' in Compliance Manager indicates that an alternative or compensating control handles the requirement.
Question 24: A company's file plan includes a reference code that maps to its internal classification taxonomy. Where in a retention label can this reference code be stored?
- Keyword metadata tag
- Sensitivity sublabel
- Label description field
- File plan descriptor — Reference ID (Correct answer)
Correct answer: File plan descriptor — Reference ID
File plan descriptors, including Reference ID, Function/Department, and Citation, let organizations map retention labels to their internal classification systems.
Question 25: An organization wants to trigger a retention period based on when an employee leaves the company. Which retention trigger type should be configured?
- Modification-based retention
- Creation-based retention
- Date-based retention
- Event-based retention (Correct answer)
Correct answer: Event-based retention
Event-based retention starts the retention clock when a specific event occurs, such as an employee departure, rather than on a fixed date.
Question 26: A records manager needs to prove that a SharePoint document has not been altered since it was declared a record. Which Microsoft Purview capability supports this requirement?
- eDiscovery hold confirmation
- Audit log search for label application events (Correct answer)
- Content search with hash comparison
- Retention lock verification report
Correct answer: Audit log search for label application events
Audit logs in Microsoft Purview record label application and modification events, providing evidence that an item was declared a record at a specific time.
Question 27: A financial services firm must demonstrate to auditors that all flagged communications were reviewed within 48 hours. Which Communication Compliance feature supports this audit requirement?
- Communication Compliance audit log reports
- Sensitivity label audit reports
- Alert aging reports showing review timestamps (Correct answer)
- DLP incident reports
Correct answer: Alert aging reports showing review timestamps
Communication Compliance provides reports including alert aging information with timestamps, allowing organizations to demonstrate timely review of flagged communications.
Question 28: An SC-400 administrator needs to ensure that sensitivity labels created in Microsoft Purview are also visible in Azure Information Protection (AIP) unified labeling clients. What is required?
- Enable the AIP add-in for Office via Group Policy
- Labels published in Microsoft Purview automatically sync to the AIP unified labeling store (Correct answer)
- Install the AIP scanner and configure a separate label taxonomy
- Export labels from Purview and import them into AIP
Correct answer: Labels published in Microsoft Purview automatically sync to the AIP unified labeling store
Microsoft Purview sensitivity labels are stored in the unified labeling store and automatically available to AIP unified labeling clients without additional export or import steps.
Question 29: Which of the following workloads is NOT currently supported as a location in Microsoft Purview retention policies?
- Exchange email
- Microsoft Forms responses (Correct answer)
- Teams private chats
- SharePoint sites
Correct answer: Microsoft Forms responses
Microsoft Forms responses are not a supported location in Microsoft Purview retention policies; supported locations include Exchange, SharePoint, OneDrive, and Teams.
Question 30: An administrator wants to ensure that only specific users can view the actual content of files in Insider Risk Management cases. Which role group should these users be assigned to?
- Insider Risk Management Investigators (Correct answer)
- Insider Risk Management Analysts
- Security Administrators
- Compliance Administrators
Correct answer: Insider Risk Management Investigators
The Insider Risk Management Investigators role group grants access to all case management features including viewing file and email content in the content explorer.
Question 31: What is the purpose of the 'Review Set' feature in Microsoft Purview eDiscovery (Premium)?
- To automatically classify documents using sensitivity labels
- To automatically delete irrelevant documents from a case
- To provide a static, curated collection of documents for attorney review and analysis (Correct answer)
- To publish search results to SharePoint for collaboration
Correct answer: To provide a static, curated collection of documents for attorney review and analysis
A review set in eDiscovery Premium is a static snapshot of collected content that attorneys can annotate, tag, and analyze without affecting original data.
Question 32: A sensitivity label policy has a default label set to 'General'. A user applies the 'Confidential' label to a document. What happens when the user tries to downgrade to 'Public'?
- The user must provide a justification (Correct answer)
- An admin alert is triggered automatically
- The label changes silently
- The action is blocked entirely
Correct answer: The user must provide a justification
When label downgrade protection is enabled, users must provide a business justification before they can apply a lower-priority sensitivity label.
Question 33: Which DLP condition allows a policy to detect when a document contains both a Social Security Number AND a keyword like 'confidential'?
- Content matches all conditions using AND logic (Correct answer)
- Content matches any condition using OR logic
- Content contains sensitive info type with high confidence
- Simple content match
Correct answer: Content matches all conditions using AND logic
Combining multiple conditions with AND logic requires all specified conditions to be true simultaneously for the rule to trigger.
Question 34: Which Microsoft 365 plan is required to use Advanced Message Encryption?
- Microsoft 365 E3 or Office 365 E3
- Microsoft 365 E1 or Office 365 E1
- Microsoft 365 Business Basic
- Microsoft 365 E5 or Office 365 E5 (Correct answer)
Correct answer: Microsoft 365 E5 or Office 365 E5
Advanced Message Encryption requires Microsoft 365 E5 or Office 365 E5 (or the equivalent add-on), whereas basic OME is included in E3 plans.
Question 35: A legal team wants to run eDiscovery searches but the compliance admin notices that many documents are showing as 'partially indexed.' What is the primary cause of partially indexed items in Exchange Online?
- The documents exceed the 150 MB attachment size limit for indexing (Correct answer)
- The items have sensitivity labels that block indexing
- Items in the Junk Email folder are never indexed
- The items are in shared mailboxes which are excluded from indexing
Correct answer: The documents exceed the 150 MB attachment size limit for indexing
Items with attachments exceeding the indexing size limit (150 MB) or in unsupported file formats are classified as partially indexed and may be missed in keyword searches.
Question 36: Which documentation practice BEST demonstrates regulatory compliance for SC-400 certified professionals?
- Maintaining organized, dated, and signed records of all activities, training, and incidents (Correct answer)
- Keeping informal handwritten notes
- Relying on memory for routine procedures
- Filing documents only when audited
Correct answer: Maintaining organized, dated, and signed records of all activities, training, and incidents
Organized, dated, and signed records demonstrate systematic compliance with regulatory requirements. Proper documentation serves as evidence during audits, protects against liability, and shows a pattern of consistent adherence to standards.
Question 37: Which sensitivity label encryption configuration allows the label to expire access to content after a specific number of days?
- Apply encryption with AIP scanner
- Assign permissions now — Content expiration (Correct answer)
- Set user-defined permissions
- Let users assign permissions
Correct answer: Assign permissions now — Content expiration
When assigning permissions in a sensitivity label's encryption settings, administrators can set a content expiration date or number of days after which access is revoked.
Question 38: Why is IAM integration with Active Directory crucial for security?
- It manages only user passwords.
- It centralizes user identity and access management. (Correct answer)
- It limits access to physical systems.
- It limits user access to specific IP addresses.
Correct answer: It centralizes user identity and access management.
IAM integration with Active Directory is crucial for security because Active Directory often serves as the centralized repository for user identities and network resources in many organizations. This integration allows for unified management of user accounts, groups, and permissions across the entire IT infrastructure. It streamlines provisioning, de-provisioning, and access control, enhancing security and operational efficiency by providing a single source of truth for identities.
Question 39: What is an example of a data loss prevention technology?
- Password complexity enforcement.
- Network traffic analysis tools. (Correct answer)
- Firewall blocking.
- Email encryption.
Correct answer: Network traffic analysis tools.
Network traffic analysis tools are a prime example of Data Loss Prevention (DLP) technology. These tools monitor network communications, including emails, web traffic, and file transfers, for sensitive information attempting to leave the organization's control. By identifying patterns or specific data types that violate DLP policies, these tools can block transmissions, alert administrators, or encrypt data to prevent unauthorized disclosure.
Question 40: What are examples of DLP enforcement methods?
- Blocking or encrypting data based on predefined policies (Correct answer)
- Content filtering.
- Authentication of users.
- Access control management.
Correct answer: Blocking or encrypting data based on predefined policies
Examples of Data Loss Prevention (DLP) enforcement methods include blocking or encrypting data based on predefined policies. When sensitive content is detected attempting to be shared or moved in a way that violates policy, DLP can automatically block the action, preventing the data from leaving secure boundaries. Alternatively, it can encrypt the data, ensuring that even if it is exfiltrated, it remains unreadable and protected from unauthorized access.
SC-400: Microsoft Certified: Information Protection and Compliance Administrator Associate
This certification validates the skills to implement and manage information protection and compliance solutions across Microsoft 365.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds