Microsoft Certified: Information Security Administrator Associate
Administering Information Security in Microsoft 365. Umfasst Microsoft Purview Information Protection (Klassifizierung, Sensitivity Labels, Verschlüsselung), Data Loss Prevention & Retention sowie Insider Risk Management, Audit, eDiscovery und den Schutz von Daten in KI-Umgebungen (DSPM for AI).
Skill-Bereiche
- Implement information protection~34 % · 58 Fragen
- Implement data loss prevention and retention~33 % · 49 Fragen
- Manage risks, alerts, and activities~33 % · 77 Fragen
Über die SC-401-Zertifizierung
Die SC-401 ist Microsofts Associate-Zertifizierung für Information Security Administratoren. Im Mittelpunkt steht der Schutz sensibler Daten mit Microsoft Purview: Du planst und implementierst Informationsschutz, Verhinderung von Datenverlust (DLP) und Aufbewahrung, verwaltest Insider-Risiken und sicherst Daten ab, die von KI-Diensten verarbeitet werden.
Die Prüfung richtet sich an Praktiker, die bereits mit Microsoft 365, PowerShell, Microsoft Entra, dem Defender-Portal und Defender for Cloud Apps arbeiten. Erwartet wird, dass du Anforderungen an den Schutz sensibler Daten in konkrete Konfigurationen übersetzen kannst — von benutzerdefinierten Typen für vertrauliche Informationen über Vertraulichkeitsbezeichnungen und Endpoint DLP bis zu Richtlinien im Insider Risk Management.
Weil die SC-401 deutlich tiefer geht als eine Fundamentals-Prüfung, sind unsere Fragen überwiegend szenariobasiert: Du entscheidest, welches Werkzeug für eine Anforderung das richtige ist, in welcher Reihenfolge Schritte ablaufen und wie sich Richtlinien gegenseitig beeinflussen. Nach jeder Antwort gibt es eine Erklärung auf Deutsch und den belegenden Textausschnitt aus dem offiziellen Lernpfad.
Beispielfragen aus dem SC-401-Pool
So sehen die Fragen aus. Im Test-Examen bekommst du zusätzlich eine KI-Erklärung und den belegenden Textausschnitt aus dem Lernpfad.
- Single Choice·leicht·Container labels
1. An administrator applies a sensitivity label with the Groups & sites scope to a SharePoint site. What effect does this label have on the Word documents stored in the site's document library?
- The documents are automatically encrypted with the site's label settings.
- The documents receive headers and footers defined in the label's content markings.
- The documents are not encrypted or marked; the label only protects workspace-level settings such as privacy and external sharing.
- The documents inherit the label as soon as the site is recrawled by the search index.
Richtige Antwort: The documents are not encrypted or marked; the label only protects workspace-level settings such as privacy and external sharing.
Container-Labels schützen den Arbeitsbereich selbst (Privatsphäre, externer Zugriff, Conditional Access), aber sie verschlüsseln oder markieren nicht die Dateien darin. Jedes Dokument braucht ein eigenes, direkt angewendetes Label, damit Verschlüsselung und Content Markings greifen.
- Single Choice·leicht·DLP purpose
2. Your organization is planning a data loss prevention (DLP) strategy. Which type of data loss scenario is DLP primarily designed to address?
- Sensitive information shared accidentally by users during everyday work
- External attackers breaching the network perimeter through malware
- Data corruption caused by failed storage hardware
- Unauthorized access resulting from misconfigured firewall rules
Richtige Antwort: Sensitive information shared accidentally by users during everyday work
Die meisten Datenverluste entstehen nicht durch böswillige Absicht, sondern versehentlich bei der täglichen Arbeit — etwa beim Teilen von Dateien oder Kopieren von Inhalten. Genau hier setzt DLP an; Malware-Angriffe, Hardware-Defekte und Firewall-Fehlkonfigurationen sind keine DLP-Kernszenarien.
- Single Choice·leicht·Insider risk types
3. Which of the following is an example of an accidental insider risk?
- A frustrated employee downloads trade secrets and shares them with a competitor.
- An employee opens a phishing link, exposing sensitive company data.
- An external hacker brute-forces an administrator account.
- A departing employee deliberately copies confidential files to a personal drive.
Richtige Antwort: An employee opens a phishing link, exposing sensitive company data.
Versehentliche Insider-Risiken entstehen durch unbeabsichtigte Handlungen wie Fehler oder Fahrlässigkeit, z. B. das Öffnen eines Phishing-Links. Das Teilen von Geschäftsgeheimnissen mit einem Wettbewerber oder gezieltes Kopieren vertraulicher Dateien sind böswillige Insider-Risiken, und ein externer Hacker ist gar kein Insider-Risiko.
- Single Choice·leicht·Copilot label inheritance
4. A user asks Microsoft 365 Copilot in Word to draft a proposal by referencing a document labeled Confidential and a document labeled Highly Confidential (the higher-priority label). Which sensitivity label does the generated proposal receive?
- No label, because Copilot-generated content is always unlabeled by default.
- The Highly Confidential label, because Copilot inherits the label with the highest priority from the source files.
- The Confidential label, because Copilot always applies the lowest common label.
- The default label from the user's label policy, which overrides inheritance.
Richtige Antwort: The Highly Confidential label, because Copilot inherits the label with the highest priority from the source files.
Wenn Copilot neue Inhalte aus gelabelten Quelldateien erstellt, erbt das Ergebnis automatisch das Label mit der höchsten Priorität. Ein geerbtes Label ersetzt zwar Default-Labels und manuell gesetzte Labels mit niedrigerer Priorität, überschreibt aber nie ein höher priorisiertes Label.
Themen im SC-401-Fragenpool
Diese Themen deckt unser Pool aus 184 Fragen ab — gruppiert nach den offiziellen Skill-Bereichen.
Implement information protection (~34 %)
Activity Explorer facts · Advanced encryption features · Advanced encryption licensing · Auto-labeling methods · Availability key fallback · BitLocker key hierarchy · BitLocker key roles · Branding rule order · Classification method selection · Classification methods · Classifier limitations · Classifier requirements · Classifier training data · Container labels · Copilot encryption rights · Copilot label inheritance · Custom classifier creation · Custom SIT patterns · Customer Key facts · Data explorer purpose · Data-in-transit scenarios · Deleting sensitivity labels · Document fingerprinting · EDM experiences · Enable container labels · Encryption PowerShell cmdlets · Encryption technologies · Exact data match · Expiration and revocation · Explorer permissions · Fingerprinting capabilities · Incident investigation tools · Information Protection reports · Insider risk management · Investigation tools · Keyword dictionaries · Label application surfaces · Label creation workflow · Label encryption settings · Label policy behavior · Meeting label scopes · Message encryption · Message encryption setup · Named entities · On-premises DLP actions · On-premises DLP deployment · Power BI label export · Predefined filter sets · Pretrained classifiers · Purview AI protections · Report purposes · Scanner authentication · Scanner deployment steps · Scanner discovery mode · Scanner prerequisites · Simulation mode · Volume level encryption · Zero Trust principles
Implement data loss prevention and retention (~33 %)
Adaptive Protection · Advanced DLP controls · Alert behavior · Alert investigation tools · Alert licensing · Alert response actions · Auto-apply label conditions · Auto-labeling simulation · Clipboard enforcement behavior · Connector classification · Device onboarding methods · DLP alert lifecycle · DLP capabilities and limits · DLP enforcement actions · DLP evaluation signals · DLP in Microsoft Teams · DLP purpose · DLP rollout approach · DLP triage agent · Edit vs clone policies · End of retention actions · Endpoint DLP enforcement · Endpoint DLP rollout · Endpoint DLP settings · File policy elements · File policy inspection methods · File policy vs Purview DLP · Investigation starting points · JIT protection fallback · Labels vs policies · OneDrive recovery · Policy priority · Power Platform DLP · Power Platform permissions · Power Platform policy creation · Principles of retention · Purview browser extension · Retention configurations · Retention fundamentals · Retention label locations · Retention limitations · Retention policy purpose · Retention precedence · Retention vs DLP · Rule-level detection · Scoping retention · Simulation mode behavior · Simulation mode limits · Template vs custom policy
Manage risks, alerts, and activities (~33 %)
Adaptive Protection DLP locations · Adaptive Protection purpose · Adaptive Protection setup · Advanced Auditing enablement · Advanced hunting · AI audit record types · AI data storage · AI retention locations · AI tool categories · Alert generation process · Alert retention · Alert volume tuning · Audit log verification · Audit record types · Audit retention timing · Audit tiers · Azure AI app onboarding · Browser DLP for Edge · Case actions · Case investigation tabs · Collection policy prerequisite · Communication Compliance AI · Conditional Access integration · Copilot auditing · Copilot in Fabric · Copilot retention · Copilot Studio agents · Copilot Studio investigation · Custom policy creation · Custom setup steps · Data connectors · Data theft investigation · Default assessments · Defender XDR integration · Departing users prerequisites · DLM preservation opt-in · DLP for Copilot · DSPM enforcement scope · DSPM for AI basics · DSPM risk assessments · eDiscovery case model · eDiscovery Copilot deletion · eDiscovery licensing · eDiscovery permissions · eDiscovery roles · eDiscovery search phases · Empty audit results · Endpoint DLP actions · Enforcement mechanisms · Entra-registered AI apps · Export Teams content · Health record misuse · Insider risk analytics · Insider risk types · Insights vs events · Investigative tools · IRM dashboards · IRM integrations · IRM planning · IRM prerequisites · IRM principles · IRM settings · Layered AI protections · Licensing requirements · MailItemsAccessed throttling · One-click DLP policies · Policy deletion · Policy triggers · PowerShell audit export · Protections by tool type · Quick vs custom policies · Risky AI usage template · Search by file · Search result types · Securing developer AI · Sensitivity labels Copilot · SIEM integration
Offizielle Lernpfade zur SC-401
Unsere Fragen sind aus diesen 27 Modulen von Microsoft Learn abgeleitet. Die Inhalte selbst findest du kostenlos bei Microsoft:
- Apply sensitivity labels for data protection9 Lerneinheiten
- Create and manage sensitive information types10 Lerneinheiten
- Protect email with Microsoft Purview Message Encryption9 Lerneinheiten
- Protect sensitive data in a digital world10 Lerneinheiten
- Classify and protect on-premises data with Microsoft Purview8 Lerneinheiten
- Review and analyze data classification and protection6 Lerneinheiten
- Understand Microsoft 365 encryption6 Lerneinheiten
- Create and configure sensitivity labels with Microsoft Purview8 Lerneinheiten
- Classify data for protection and governance7 Lerneinheiten
- Investigate and respond to Microsoft Purview Data Loss Prevention alerts11 Lerneinheiten
- Configure DLP policies for Microsoft Defender for Cloud Apps and Power Platform6 Lerneinheiten
- Create and manage data loss prevention policies12 Lerneinheiten
- Understand and plan data loss prevention8 Lerneinheiten
- Implement endpoint data loss prevention (DLP) with Microsoft Purview10 Lerneinheiten
- Implement and manage Microsoft 365 retention and recovery10 Lerneinheiten
- Understand retention in Microsoft Purview6 Lerneinheiten
- Understand Microsoft Purview Insider Risk Management7 Lerneinheiten
- Create and manage Insider Risk Management policies7 Lerneinheiten
- Investigate insider risk alerts and related activity13 Lerneinheiten
- Prepare for Microsoft Purview Insider Risk Management7 Lerneinheiten
- Implement Adaptive Protection in Microsoft Purview9 Lerneinheiten
- Search for content with Microsoft Purview eDiscovery8 Lerneinheiten
- Conduct investigations with Microsoft Purview Audit10 Lerneinheiten
- Secure Microsoft 365 Copilot interactions with Microsoft Purview11 Lerneinheiten
- Understand How to Secure AI Data with Microsoft Purview10 Lerneinheiten
- Secure developer AI environments with Microsoft Purview11 Lerneinheiten
- Secure enterprise and browser-based AI apps with Microsoft Purview10 Lerneinheiten
Häufige Fragen zur SC-401
Wie viele Fragen hat die SC-401-Prüfung?
Microsoft-Associate-Prüfungen umfassen typischerweise 40 bis 60 Fragen. Unser Test-Examen stellt 40 Fragen aus einem Pool von aktuell 184 Fragen zusammen, sodass sich jeder Durchlauf unterscheidet.
Wie lange dauert die SC-401?
Für die SC-401 sind 100 Minuten vorgesehen. Unsere Test-Examen bilden diesen Umfang ab, laufen aber ohne Zeitlimit, damit du die Erklärungen in Ruhe durcharbeiten kannst.
Wie viele Punkte braucht man zum Bestehen?
Wie bei allen Microsoft-Zertifizierungen sind 700 von 1000 Punkten zum Bestehen nötig. Unsere Auswertung nutzt dieselbe Skala und zeigt zusätzlich deine Leistung je Skill-Bereich.
Welche Themen werden geprüft?
Die Prüfung verteilt sich auf drei etwa gleich gewichtete Bereiche: Informationsschutz umsetzen (30–35 %), Verhinderung von Datenverlust und Aufbewahrung umsetzen (30–35 %) sowie Risiken, Warnungen und Aktivitäten verwalten (30–35 %). Letzterer Bereich enthält auch den Schutz von Daten, die von KI-Diensten genutzt werden.
Welche Vorkenntnisse brauche ich für die SC-401?
Du solltest Microsoft 365 sicher bedienen, Grundkenntnisse in PowerShell mitbringen und mit Microsoft Entra, dem Microsoft-Defender-Portal sowie Microsoft Defender for Cloud Apps vertraut sein. Praxiserfahrung mit Microsoft Purview hilft besonders bei den szenariobasierten Fragen.
Ersetzt die SC-401 die SC-400?
Die SC-401 ist die Nachfolgerin der früheren SC-400 (Information Protection and Compliance Administrator). Der Fokus wurde erweitert, unter anderem um den Schutz von Daten in KI-Umgebungen mit Data Security Posture Management für KI.
Kostet dieses Test-Examen etwas?
Nein. Die Test-Examen sind kostenlos und ohne Anmeldung nutzbar. Ein Konto brauchst du nur für den gespeicherten Prüfungsverlauf und die KI-Erklärungen mit deinem eigenen API-Key.