SC-400: Microsoft Certified: Information Protection and Compliance Administrator Associate — Questions and Answers
Question 1: A company operates in both the US and EU and needs location-specific retention periods for the same record type. What is the best approach in Microsoft Purview?
- Apply a global retention policy and override with regional eDiscovery holds
- Create two file plans — one per region — and assign labels accordingly
- Create separate retention labels for US and EU with different periods and publish them to the appropriate locations (Correct answer)
- Use a single label with adaptive scopes per region
Correct answer: Create separate retention labels for US and EU with different periods and publish them to the appropriate locations
Creating region-specific retention labels and publishing them only to the relevant SharePoint sites or mailboxes ensures each location follows its own regulatory retention period.
Question 2: An organization receives a court order requiring data to be held for litigation. The IT team wants to ensure the hold is not accidentally removed. What is the recommended approach in Microsoft Purview?
- Apply an eDiscovery hold through a case and restrict case access to authorized personnel only (Correct answer)
- Configure a DLP policy to prevent deletion
- Store copies of the data in an external archive immediately
- Use a retention policy with delete-blocking instead of an eDiscovery hold
Correct answer: Apply an eDiscovery hold through a case and restrict case access to authorized personnel only
Creating an eDiscovery hold within a case and limiting case membership to authorized personnel ensures the hold can only be modified by those with explicit case access.
Question 3: When using eDiscovery in Microsoft Purview, which statement correctly describes the difference between eDiscovery (Standard) and eDiscovery (Premium)?
- There is no functional difference; only the licensing cost differs
- Premium includes custodian management, advanced analytics, and predictive coding; Standard does not (Correct answer)
- Standard includes machine learning relevance scoring; Premium requires manual tagging only
- Standard supports review sets; Premium does not
Correct answer: Premium includes custodian management, advanced analytics, and predictive coding; Standard does not
eDiscovery Premium adds custodian management, advanced indexing, review sets with analytics (threading, near-dupe, predictive coding) that are not available in eDiscovery Standard.
Question 4: In Microsoft Purview, which role is required to create and manage retention labels in the Records Management solution?
- Records Management role (Correct answer)
- Security Administrator role
- Global Administrator role
- Compliance Administrator role
Correct answer: Records Management role
The Records Management role group grants permissions to configure retention labels, file plans, and disposition reviews in Microsoft Purview.
Question 5: What is the most effective approach to records management in the SC-400 field?
- Following competitors
- Systematic planning and continuous improvement (Correct answer)
- Reactive problem-solving
- Maintaining the status quo
Correct answer: Systematic planning and continuous improvement
Systematic planning combined with continuous improvement ensures sustainable success and allows for proactive management of challenges.
Question 6: A compliance administrator needs to prevent users from emailing documents labeled 'Confidential' outside the organization. Which Microsoft Purview feature should they configure?
- Communication compliance policy
- Sensitivity label auto-labeling
- Retention policy
- Data Loss Prevention policy (Correct answer)
Correct answer: Data Loss Prevention policy
DLP policies can block or restrict sharing of content with specific sensitivity labels to external recipients.
Question 7: What is the minimum number of Azure Key Vault instances recommended when configuring Customer Key to ensure high availability?
- Three vaults spread across three continents
- Four vaults with geo-redundancy enabled on each
- Two vaults in two different Azure regions (Correct answer)
- One vault in a single region
Correct answer: Two vaults in two different Azure regions
Microsoft requires at least two Azure Key Vault instances in two separate Azure regions for each Customer Key DEP to ensure availability if one region experiences an outage.
Question 8: What is the effect of enabling the 'delete content older than' action without enabling 'retain content' in a Microsoft Purview retention policy?
- Content is retained and then deleted after the specified period
- Content is only deleted when older than the specified age, with no protection during the period (Correct answer)
- An error occurs because both settings must be enabled together
- Content is moved to an archive and deleted after expiration
Correct answer: Content is only deleted when older than the specified age, with no protection during the period
A delete-only action removes content older than the specified age but does not protect content from early deletion during that period.
Question 9: A reviewer in the Microsoft Purview compliance portal marks a Communication Compliance alert as 'Resolved.' What does this action signify?
- The alert has been investigated and no further action is required (Correct answer)
- The message is permanently deleted from all mailboxes
- The supervised user's account is suspended
- The policy is paused pending further configuration
Correct answer: The alert has been investigated and no further action is required
Marking an alert as 'Resolved' indicates that the reviewer has investigated the flagged communication and determined that no further action is needed.
Question 10: A retention policy is configured for Exchange with a 3-year retain-and-delete action. A mailbox is placed on Litigation Hold. What is the effective outcome?
- Content is deleted after 3 years but a copy is kept in the hold
- The Litigation Hold takes precedence and content is retained indefinitely (Correct answer)
- Both settings cancel each other out and no retention applies
- The retention policy overrides the Litigation Hold and deletes after 3 years
Correct answer: The Litigation Hold takes precedence and content is retained indefinitely
Litigation Hold takes precedence over retention policy deletion actions; content is retained indefinitely until the hold is released, per the principles of retention.
Question 11: An administrator must prevent a specific set of external domains from receiving unencrypted email from their organization. Which feature enforces TLS for outbound mail to those domains?
- A connector in Exchange Online with 'Require TLS' configured for the partner domain (Correct answer)
- Data Loss Prevention policy with an encrypt action
- Office 365 Message Encryption with a transport rule
- Azure AD Conditional Access policy
Correct answer: A connector in Exchange Online with 'Require TLS' configured for the partner domain
An outbound partner connector in Exchange Online can be configured to require TLS when sending mail to specific domains, rejecting delivery if TLS cannot be negotiated.
Question 12: In the context of Insider Risk Management, what is a 'triggering event'?
- A DLP alert that feeds into an insider risk policy
- A user login from an anonymous IP
- An event that automatically creates a case
- An activity that causes a user to enter the active monitoring window of a policy (Correct answer)
Correct answer: An activity that causes a user to enter the active monitoring window of a policy
A triggering event (such as a resignation date or a DLP policy match) is what activates a policy for a specific user and begins monitoring their activity.
Question 13: A trainable classifier has been created and is in 'Need test items' status. What is the next required step?
- Configure auto-labeling policies
- Provide test content for the classifier to evaluate (Correct answer)
- Upload a keyword dictionary
- Publish the classifier to production
Correct answer: Provide test content for the classifier to evaluate
After initial training, the classifier requires test content items to evaluate its accuracy before it can be published for use.
Question 14: Which foundational principle is MOST important for success in the Microsoft Certified Information Protection and Compliance Administrator Associate profession?
- Maintaining the minimum requirements for certification
- Specializing in only one narrow area of practice
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Maximizing financial returns on every engagement
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success in any professional field requires a commitment to continuous learning to stay current, ethical practice to maintain trust and integrity, and a focus on quality outcomes that serve stakeholders and the public interest.
Question 15: A compliance team wants to review only 10% of all communications captured by a policy to manage review workload. Which feature supports this requirement?
- Content sampling with a percentage threshold (Correct answer)
- Keyword exclusion list
- Reviewer assignment rotation
- Alert aggregation by user
Correct answer: Content sampling with a percentage threshold
Communication Compliance policies support percentage-based content sampling, allowing organizations to review only a subset of captured communications.
Question 16: A sensitivity label policy is configured with 'Require users to justify removing a label or lowering its classification'. Which audit log activity captures a user's justification text?
- SensitivityLabelChanged (Correct answer)
- SensitivityLabelPolicyMatch
- SensitivityLabelApplied
- SensitivityLabelRemoved
Correct answer: SensitivityLabelChanged
The SensitivityLabelChanged audit event is recorded when a user changes a label (including downgrading it) and captures the justification text the user provided.
Question 17: A search in Microsoft Purview Content Search returns 0 results despite the compliance admin being certain relevant emails exist. What is a likely cause related to permissions?
- The retention policy is interfering with the search query
- The search account lacks the eDiscovery Manager role in the compliance portal (Correct answer)
- The user whose mailbox is being searched has blocked the search
- Sensitivity labels are preventing search from returning results
Correct answer: The search account lacks the eDiscovery Manager role in the compliance portal
Without the eDiscovery Manager or equivalent role in the Microsoft Purview compliance portal, a user cannot perform content searches and would receive no results.
Question 18: A retention policy is applied to a Microsoft 365 Group. Which locations are affected by this policy?
- Only the group's Exchange mailbox
- Only the group's SharePoint site
- The group's Teams channel, mailbox, and SharePoint site
- Both the group's Exchange mailbox and SharePoint site (Correct answer)
Correct answer: Both the group's Exchange mailbox and SharePoint site
A retention policy applied to Microsoft 365 Groups covers both the group mailbox (Exchange) and the associated SharePoint site.
Question 19: What is the most important professional competency for SC-400 certification in ediscovery?
- Deep knowledge combined with practical application skills (Correct answer)
- Ability to work alone exclusively
- Speed of task completion
- Memorization of all reference materials
Correct answer: Deep knowledge combined with practical application skills
Professional competency requires both deep knowledge of the subject matter and the ability to apply that knowledge in practical situations.
Question 20: Microsoft Purview Insider Risk Management uses which type of signals to detect potential data theft by a departing employee?
- Behavioral signals such as file downloads, USB transfers, and HR departure indicators (Correct answer)
- Only signals from Microsoft Defender for Endpoint
- Manual reports submitted by managers through the compliance portal
- Only email content scanned by DLP policies
Correct answer: Behavioral signals such as file downloads, USB transfers, and HR departure indicators
Insider Risk Management correlates behavioral signals (file activity, HR data, network events) to identify risky patterns like data exfiltration by departing employees.
Question 21: Hold Your Own Key (HYOK) in Microsoft Purview Information Protection is best suited for which scenario?
- Enabling mobile device access to encrypted content without VPN
- Protecting highly classified on-premises content that must never be decrypted in the cloud (Correct answer)
- Protecting documents shared with external partners via Azure RMS
- Automating key rotation for Exchange Online mailboxes
Correct answer: Protecting highly classified on-premises content that must never be decrypted in the cloud
HYOK uses Active Directory Rights Management Services (AD RMS) on-premises to encrypt content, ensuring that decryption never occurs in the Microsoft cloud — ideal for top-secret or sovereignty-constrained data.
Question 22: An organization wants to automatically classify and label scanned contracts using machine learning instead of keywords. Which Microsoft Purview feature should they use?
- Sensitive information types
- Content search with auto-apply
- Trainable classifiers (Correct answer)
- Keyword query auto-labeling
Correct answer: Trainable classifiers
Trainable classifiers use machine learning trained on sample documents to identify content like contracts and automatically apply the correct retention label.
Question 23: A compliance administrator wants to search for content across all Exchange Online mailboxes in the organization without specifying individual users. How should the content location be configured?
- Use a distribution group as the content location
- Select 'All mailboxes' to search across all Exchange Online mailboxes at once (Correct answer)
- Create a separate search for each department
- Add each mailbox individually to the search
Correct answer: Select 'All mailboxes' to search across all Exchange Online mailboxes at once
Selecting 'All mailboxes' in the content location configuration searches every Exchange Online mailbox in the organization in a single search operation.
Question 24: What is the purpose of the 'Review Set' feature in Microsoft Purview eDiscovery (Premium)?
- To automatically delete irrelevant documents from a case
- To automatically classify documents using sensitivity labels
- To publish search results to SharePoint for collaboration
- To provide a static, curated collection of documents for attorney review and analysis (Correct answer)
Correct answer: To provide a static, curated collection of documents for attorney review and analysis
A review set in eDiscovery Premium is a static snapshot of collected content that attorneys can annotate, tag, and analyze without affecting original data.
Question 25: An organization wants to classify documents based on their content after they are created, without requiring user intervention. Which classification method achieves this?
- Manual labeling by users
- Recommended labeling prompts
- Default label assignment
- Automatic labeling using auto-labeling policies (Correct answer)
Correct answer: Automatic labeling using auto-labeling policies
Auto-labeling policies scan content in SharePoint, OneDrive, and Exchange and apply sensitivity labels automatically based on detected sensitive information types.
Question 26: When configuring an audit log search, which date/time zone do the start and end times correspond to?
- The administrator's local time zone
- UTC (Coordinated Universal Time) (Correct answer)
- Pacific Standard Time (PST)
- The tenant's registered country time zone
Correct answer: UTC (Coordinated Universal Time)
All audit log timestamps in Microsoft Purview use UTC, so search date/time parameters must be specified in UTC.
Question 27: What is the PRIMARY reason for regulatory compliance in the Microsoft Certified Information Protection and Compliance Administrator Associate profession?
- To create additional paperwork for documentation
- To justify higher service fees
- To protect public safety, ensure quality standards, and maintain professional integrity (Correct answer)
- To avoid penalties and fines only
Correct answer: To protect public safety, ensure quality standards, and maintain professional integrity
Regulatory compliance serves the broader purpose of protecting public safety, ensuring consistent quality standards, and maintaining the integrity of the profession. While avoiding penalties is a benefit, the primary motivation is safeguarding the public interest.
Question 28: An organization needs to ensure that emails classified as 'Confidential' cannot be forwarded by recipients. Which sensitivity label encryption option achieves this?
- Assign 'Do Not Forward' permission in the encryption settings (Correct answer)
- Enable S/MIME signing for the label
- Block all external recipients with DLP policy
- Apply watermark to email body
Correct answer: Assign 'Do Not Forward' permission in the encryption settings
The 'Do Not Forward' permission in Azure RMS encryption prevents recipients from forwarding, printing, or copying the email content.
Question 29: What is the BEST way for a Microsoft Certified Information Protection and Compliance Administrator Associate professional to stay current with regulatory changes?
- Actively monitor regulatory bodies, attend continuing education, and participate in professional associations (Correct answer)
- Depend on colleagues to share updates informally
- Rely solely on employer notifications
- Check regulations only during certification renewal
Correct answer: Actively monitor regulatory bodies, attend continuing education, and participate in professional associations
Staying current requires a multi-faceted approach: monitoring regulatory agencies directly, attending relevant continuing education programs, and participating in professional associations that disseminate regulatory updates.
Question 30: How can compliance risks be monitored in real-time?
- By monitoring compliance status using automated tools. (Correct answer)
- By allowing employees to handle compliance on their own.
- By checking reports annually.
- By outsourcing risk management.
Correct answer: By monitoring compliance status using automated tools.
Compliance risks can be monitored in real-time by utilizing automated tools and systems that continuously track activities, configurations, and data flows against defined policies and regulations. These tools can detect deviations or suspicious behaviors instantly, providing immediate alerts to compliance officers. This proactive approach allows for rapid response to potential non-compliance issues, significantly reducing exposure and impact.
Question 31: In SC-400 practice, what is the best approach to quality improvement in data classification?
- Wait for problems to occur before acting
- Make changes without measuring results
- Use data-driven methods with measurable outcomes (Correct answer)
- Copy what other organizations do without analysis
Correct answer: Use data-driven methods with measurable outcomes
Data-driven quality improvement with measurable outcomes ensures that changes actually produce the intended improvements and can be verified.
Question 32: Which sensitivity label setting controls whether external users from a federated Azure AD tenant can access an encrypted SharePoint document?
- External sharing controls on the site
- Encryption settings: Add any authenticated users (Correct answer)
- Let users assign permissions setting
- Conditional access policy
Correct answer: Encryption settings: Add any authenticated users
Adding 'Any authenticated users' in the label's encryption settings allows any user who authenticates with a Microsoft identity, including external federated users, to access the content.
Question 33: An organization wants DLP policies to apply to endpoints (Windows 10/11 devices). What must be enabled first?
- Microsoft Defender for Cloud Apps
- Azure Information Protection unified labeling client
- Microsoft Purview Information Protection scanner
- Microsoft Purview compliance portal device onboarding (Correct answer)
Correct answer: Microsoft Purview compliance portal device onboarding
Devices must be onboarded into Microsoft Purview compliance portal before endpoint DLP policies can be applied to them.
Question 34: In SC-400 practice, what is the primary purpose of strategic planning?
- To satisfy external auditors
- To reduce workforce
- To align resources with goals and anticipate challenges (Correct answer)
- To create paperwork
Correct answer: To align resources with goals and anticipate challenges
Strategic planning aligns organizational resources with goals and helps anticipate challenges before they become critical issues.
Question 35: Which foundational principle is MOST important for success in the Microsoft Certified Information Protection and Compliance Administrator Associate profession?
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Maintaining the minimum requirements for certification
- Maximizing financial returns on every engagement
- Specializing in only one narrow area of practice
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success in any professional field requires a commitment to continuous learning to stay current, ethical practice to maintain trust and integrity, and a focus on quality outcomes that serve stakeholders and the public interest.
Question 36: An administrator needs to ensure that compliance assessments reflect configurations in Azure as well as Microsoft 365. What must be enabled?
- Microsoft Defender for Cloud connected to Compliance Manager (Correct answer)
- Azure Arc for hybrid compliance monitoring
- Azure Security Center compliance dashboard
- Azure Policy integration with Compliance Manager
Correct answer: Microsoft Defender for Cloud connected to Compliance Manager
Microsoft Defender for Cloud can be connected to Compliance Manager to extend compliance assessments to Azure resources.
Question 37: Which license is required to retain audit logs for up to one year with Microsoft Purview Audit (Premium)?
- Microsoft 365 E5 or Microsoft 365 E5 Compliance add-on (Correct answer)
- Microsoft 365 E1
- Microsoft 365 Business Basic
- Microsoft 365 E3
Correct answer: Microsoft 365 E5 or Microsoft 365 E5 Compliance add-on
Microsoft Purview Audit (Premium) with one-year retention requires Microsoft 365 E5 or the E5 Compliance add-on.
Question 38: In Microsoft Purview, which license is required to use eDiscovery Premium features such as custodian management and predictive coding?
- Microsoft 365 E3 or equivalent
- Any Microsoft 365 Business plan
- Microsoft 365 F1 with eDiscovery add-on
- Microsoft 365 E5 or Microsoft 365 E5 Compliance add-on (Correct answer)
Correct answer: Microsoft 365 E5 or Microsoft 365 E5 Compliance add-on
eDiscovery Premium requires Microsoft 365 E5 or the Microsoft 365 E5 Compliance add-on for E3 subscribers to access advanced features.
Question 39: A retention policy with a 'retain only' action is applied to a SharePoint site. What happens when the retention period expires?
- A deletion workflow is triggered for administrator review
- Content remains in place with no action taken by the policy (Correct answer)
- Content is automatically deleted by the policy
- Content is moved to an archive
Correct answer: Content remains in place with no action taken by the policy
A 'retain only' policy keeps content for the specified period but takes no action after expiration — deletion is left to normal user or system processes.
Question 40: What is the role of DLP in compliance management?
- It monitors and prevents unauthorized access or sharing of sensitive data to ensure compliance. (Correct answer)
- It ensures that only authorized personnel can access sensitive data.
- It encrypts all stored data.
- It prevents data from being shared outside the organization.
Correct answer: It monitors and prevents unauthorized access or sharing of sensitive data to ensure compliance.
DLP plays a vital role in compliance management by actively monitoring and preventing unauthorized access, sharing, or transfer of sensitive data. It enforces policies that align with regulatory requirements (like GDPR or HIPAA), ensuring that confidential information remains within the organization's control. By detecting and blocking potential data leaks, DLP helps organizations avoid legal penalties, reputational damage, and financial losses associated with non-compliance.
SC-400: Microsoft Certified: Information Protection and Compliance Administrator Associate
This certification validates the skills to implement and manage information protection and compliance solutions across Microsoft 365.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds