I’m taking a new approach to my study resources and trying to simplify it all. To start off, a simple URL for each eam to get to the corresponding exam objectives. In this case it’s aka.ms/SC-400. The, just append “StudyGuide and then you will have all of the resources that I used to create these sessions and links for you to further study a little deeper on areas that you are not as strong in. In the case of this blog, it is https://aka.ms/SC-400StudyGuide. I can’t review everything in my C.E.R.T. sessions, but try to highlight what areas I think are closest to what the exam objectives called out. Then you have two choices. 1. Listen through the audio sessions on YouTube, plus all of the links on the blog. No PowerPoints to drill down to. Just the resources to quickly listen to, or research through to get your ready faster!
How to prepare for any exam
Below I am going to link all the resource links that I find in order to build out my review slides. This is the process I use to build out my C.E.R.T. sessions on YouTube –https://aka.ms/YouTube/CERT.
- You have to start with and know the Skills measured for each exam. Here are the SC-400 Exam Objectives (also generally outlined below). It is really important to always check these becuase the trend now is that they are refreshing these quite frequently now about every 6 months or so. For the record, these links and Skille Measure below, were created on and around May 31, 2021. But these resources below are high enough in the headings, that those pages should hold true for quite some time!
- Review through thes Skills and look ar what you know or don’t know. If you look at something and say “Yeah, I know RBAC better than myself” then go on to the next topic. You have to them research those weaker areas. Oh, wait – I’m doing that part for you. Now I never know what links were actually used, so I take my best search and link it. In this case, I will put every one below that I think is good. Now in the powerpoint and hence YouTube, I’ll just highlight a couple of the key things to note. NOTE: you should also review those links and scan through those resources to really understand that topic as well as possible. Since my recordings are broken down into topic modules, you can listen over and over to help cement into your learning those topics which you don’t know as well.
- If there are practice exams out, then take one or two of those to gauge your relative readiness. At the time of this writingm, MeasureUp doesn’t have a practice exam for the SC-400. But just wait a little, and I’m sure they will have one soon. They do have the SC-900 Practive Exam ready now, in case that is another exam you are interested in.
- Book it and take it! It[‘s like training for a race! If you have it booked out a month from now, then you can realistically break down the study efforts, week by week, and day by day. And even if you don’t pass, you now know some of the content on the exam. Nobody can tell you, legally, what is on the exam! So book it and take it. You never know….you just may pass it!
Implement Information Protection (35-40%)
Create and manage sensitive information types
- select a sensitive information type based on an organization’s requirements
- create and manage custom sensitive information types
- create custom sensitive information types with exact data match
- implement document fingerprinting
- create a keyword dictionary
Create and manage trainable classifiers
- identify when to use trainable classifiers
- create a trainable classifier
- verify a trainable classifier is performing properly
- retrain a classifier
Implement and manage sensitivity labels
- identify roles and permissions for administering sensitivity labels
- create sensitivity labels
- configure and manage sensitivity label policies
- apply sensitivity labels to Microsoft Teams, Microsoft 365 groups, and SharePoint sites
- configure and publish automatic labeling policies (excluding MCAS scenarios)
- monitor label usage by using label analytics
- apply bulk classification to on-premises data by using the AIP unified labelling scanner
- manage protection settings and marking for applied sensitivity labels
- apply protections and restrictions to email including content marking, usage, permission,encryption, expiration, etc.
Plan and implement encryption for email messages
- Apply Protections and Restrictions to emails and files
- define requirements for implementing Office 365 Message Encryption
- implement Office 365 Advanced Message Encryption
Implement Data Loss Prevention (30-35%)
Create and configure data loss prevention policies
- recommend a data loss prevention solution for an organization also see
- configure data loss prevention for policy precedence
- configure policies for Microsoft Exchange email
- configure policies for Microsoft SharePoint sites
- configure policies for Microsoft OneDrive accounts
- configure policies for Microsoft Teams chat and channel messages
- integrate Microsoft Cloud App Security (MCAS) with Microsoft Information Protection
- Learning Path: Combine DLP with Microsoft Cloud App Security
- configure policies in Microsoft Cloud App Security (MCAS)
- implement data loss prevention policies in test mode
Implement and monitor Microsoft Endpoint data loss prevention
- configure policies for endpoints
- configure Endpoint data loss prevention settings
- recommend configurations that enable devices for Endpoint data loss prevention policies
- monitor endpoint activities
Manage and monitor data loss prevention policies and activities
- manage and respond to data loss prevention policy violations
- review and analyze data loss prevention reports
- manage permissions for data loss prevention reports
- manage data loss prevention violations in Microsoft Cloud App Security (MCAS)
Implement Information Governance (25-30%)
Configure retention policies and labels
- create and apply retention labels
- create and apply retention label policies
- configure and publish auto-apply label policies
Manage data retention in Microsoft 365
- create and apply retention policies in Microsoft SharePoint and OneDrive
- create and apply retention policies in Microsoft Teams
- recover content in Microsoft Teams, SharePoint, and OneDrive
- recover content in Microsoft Exchange
- implement retention policies and tags in Microsoft Exchange
- apply mailbox holds in Microsoft Exchange
- implement Microsoft Exchange Online archiving policies
Implement records management in Microsoft 365
- configure labels for records management
- Get Started with Records Management – the “how to”
- manage and migrate retention requirements with a file plan
- configure automatic retention using File Plan descriptors
- classify records using retention labels and policies
- implement in-place records management in Microsoft SharePoint
- configure event-based retention
- manage disposition of records