SC-400 Study Guide 2026

Everything you need to pass the SC-400 exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.

📋 SC-400 Exam Format at a Glance

40
Questions
120 min
Time Limit
70%
Passing Score

📚 SC-400 Topics to Study (66)

✍️ Sample SC-400 Questions & Answers

1. When using Search-UnifiedAuditLog in PowerShell, what is the maximum number of records returned per call?
50000

Search-UnifiedAuditLog returns up to 5,000 results per call; pagination using the SessionId and SessionCommand parameters is needed for larger result sets.

2. Which Microsoft Defender for Office 365 plan (Plan 1 vs Plan 2) includes Threat Trackers and Attack Simulator?
Plan 2 only

Threat Trackers, Attack Simulator, and automated investigation and response (AIR) are Plan 2 features not included in Plan 1.

3. How does encryption help in data loss prevention?
It allows data access only with a valid encryption key.

Encryption significantly aids in data loss prevention by transforming data into an unreadable format, making it inaccessible without the correct decryption key. This means that even if sensitive data is accidentally or maliciously exfiltrated, it remains protected and unusable to unauthorized individuals. Therefore, encryption ensures that only authorized users possessing the key can access and understand the information, effectively preventing data loss in terms of confidentiality.

4. An investigator needs to collaborate on an Insider Risk Management case with a colleague who does not have access to the compliance portal. What is the best approach?
Add the colleague to the appropriate Insider Risk Management role group

Granting access through the appropriate IRM role group (Analyst or Investigator) is the correct and secure method to enable portal collaboration.

5. What is the function of 'cumulative exfiltration detection' in Insider Risk Management?
It identifies users who gradually move large volumes of data over time

Cumulative exfiltration detection identifies users whose total data movement over time exceeds normal baselines, even if individual events seem small.

6. A legal hold is placed on a SharePoint site. A site owner deletes a document library. What happens to the documents in that library?
They are preserved in the Preservation Hold Library and cannot be permanently deleted

SharePoint's Preservation Hold Library retains copies of content subject to legal holds even if the original is deleted by site owners.

🎯 Free SC-400 Practice Tests

📖 SC-400 Guides & Articles

Your SC-400 Study Path
1. Learn with Flashcards → 2. Drill Practice Tests → 3. Take the Full Exam Simulation
Was this helpful?