EXAM COVERAGE · SC-401

SC-401 exam objectives and where the book covers them

Microsoft's skills measured for SC-401 as of October 28, 2026, mapped to the chapters of Ultra Transcenders SC-401: Administering Information Security in Microsoft 365.

ObjectiveChapters
Implement information protection (30–35%)
Implement and manage data classification2. Classifying data: sensitive information types, fingerprints, EDM and OCR; 3. Trainable classifiers and monitoring classification
Implement and manage sensitivity labels in Microsoft Purview4. Sensitivity labels: design, protection and publishing; 5. Applying labels automatically and to containers
Implement information protection for Windows, file shares, and Exchange6. Information protection for Windows, file shares and Exchange
Implement data loss prevention and retention (30–35%)
Create and configure data loss prevention policies7. Designing and managing DLP policies; 8. Endpoint DLP and Defender for Cloud Apps file policies
Implement and monitor Microsoft Purview Endpoint DLP8. Endpoint DLP and Defender for Cloud Apps file policies
Implement and manage retention9. Retention policies and the principles of retention; 10. Retention labels, auto-apply and records management
Manage risks, alerts, and activities (30–35%)
Implement and manage Microsoft Purview Insider Risk Management11. Insider Risk Management
Manage information security alerts and activities12. Audit, Activity explorer and responding to alerts; 13. eDiscovery
Protect data used by AI services4. Sensitivity labels: design, protection and publishing; 14. Protecting data used by AI

The full list of tasks under each objective is in the official SC-401 study guide and practice assessment. The book is organised by technology, so one chapter often serves several objectives.

About the book · Free study notes · Certification paths