Microsoft

SC-400 Free Practice Questions — Page 10

Question 94

You have a Microsoft 365 E5 tenant that has data loss prevention (DLP) policies. You need to create a report that includes the following: • Documents that have a matched DLP policy. • Documents that have had a sensitivity label changed. • Documents that have had a sensitivity label changed. What should you use?

A. a content search
B. an eDiscovery case
C. communication compliance reports
D. Activity explorer
Show Answer
Correct Answer: D
Explanation:
Activity explorer in the Microsoft Purview compliance portal is designed to report on DLP-related activities and labeling events. It can show items that matched DLP policies as well as sensitivity label activities such as labels being applied, changed, or removed. Content search and eDiscovery are for locating and preserving content, while Communication Compliance focuses on communication policy violations rather than DLP and labeling activity reports.

Question 95

You have a Microsoft 365 subscription. From Microsoft Purview, you plan to create a content search for email messages that have a recipient of either or user2.contoso.com. You need to add a condition to the KQL editor for the content search. Which KQL query should you add as a condition?

A. Recipients: “user””#1-2””@contoso.com”
B. Recipients: (“ [email protected] ” “ [email protected] ”)
C. Recipients: (“user””#1-1””@contoso.com”)
D. Recipients= “ [email protected] ” OR Recipients= “ [email protected] ”
Show Answer
Correct Answer: D
Explanation:
In Microsoft Purview Content Search KQL, you can combine property filters with the OR operator to match either recipient. The syntax `Recipients="[email protected]" OR Recipients="[email protected]"` correctly expresses either recipient. The wildcard-like patterns shown in A and C are not valid for this scenario, and B omits the required boolean operator between values.

Question 96

HOTSPOT - You have a Microsoft 365 E5 subscription. You plan to create a new sensitive information type (SIT) by using the Microsoft Purview compliance portal. You need to copy and modify an existing SIT from which to create the new SIT. What are two SITs that you can copy and modify? To answer, select the appropriate SITs in the answer area. NOTE: Each selection is worth one point.

Illustration for SC-400 question 96
Show Answer
Correct Answer: ABA Routing Number Adatum numbers
Explanation:
Only supported sensitive information types can be copied as a starting point. In this list, the Entity-type SITs shown (built-in ABA Routing Number and the custom Adatum numbers) are copyable, while Credential, Fingerprint, and Bundled types are not.

Question 97

You have a Microsoft 365 E5 subscription. You need to review the compliance of the subscription with the General Data Protection Regulation (GDPR) by using Compliance Manager. The solution must minimize administrative effort. What should you create first?

A. an assessment
B. an alert policy to monitor for score changes
C. a template
D. review assessments
Show Answer
Correct Answer: A
Explanation:
In Microsoft Purview Compliance Manager, the starting point for evaluating compliance with a regulation such as GDPR is to create an assessment, typically based on the Microsoft-provided GDPR assessment template. This provides the compliance score, improvement actions, and control tracking. Creating a template is not required first because built-in templates already exist, and alert policies or reviewing assessments occur after an assessment exists.

Question 98

DRAG DROP - You have a Microsoft 365 E5 subscription. You need to create the Microsoft Purview insider risk management policies shown in the following table. Which policy template should you use for each policy? To answer, drag the appropriate policy templates to the correct policies. Each template may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 98 Illustration for SC-400 question 98
Show Answer
Correct Answer: Policy1: Data theft by departing users Policy2: Data leaks by priority users Policy3: Data leaks
Explanation:
Departing users template monitors risky actions after resignation (including printing). Data leaks by priority users is for accidental sharing by designated priority users. Data leaks monitors exfiltration activities such as downloading SharePoint files to personal cloud storage.

Question 99

HOTSPOT - You have a Microsoft 365 E5 subscription that contains a security group named Group1 and the users shown in the following table. You assign the Compliance Manager roles to the users as shown in the following table. You add two assessments to Compliance Manager as shown in the following exhibit. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 99 Illustration for SC-400 question 99 Illustration for SC-400 question 99 Illustration for SC-400 question 99
Show Answer
Correct Answer: Yes Yes Yes
Explanation:
Compliance Administrator maps to sufficient Compliance Manager permissions to edit assessments. Compliance Manager Contributors can add assessments. Compliance Manager Administrators can also add assessments, including using available templates such as HIPAA/HITECH and Microsoft 365.

Question 100

You have a Microsoft 365 subscription. You create and run a content search from the Microsoft Purview compliance portal. You need to download the results of the content search. What should you obtain first?

A. a certificate
B. a password
C. an export key
D. a pin
Show Answer
Correct Answer: C
Explanation:
To download content search results from the Microsoft Purview compliance portal, you first initiate an export. The export process provides an export key, which is required by the export/download tool to retrieve and decrypt the exported results. A certificate, password, or PIN is not the required prerequisite for downloading the exported search results.

Question 101

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 subscription. You have a user named User1. Several users have full access to the mailbox of User1. Some email messages sent to User1 appear to have been read and deleted before the user viewed them. When you search the audit log in the Microsoft Purview compliance portal to identify who signed in to the mailbox of User1, the results are blank. You need to ensure that you can view future sign-ins to the mailbox of User1. Solution: You run the Set-Mailbox -Identity "User1" -AuditEnabled $true command. Does that meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
No. Enabling mailbox auditing with Set-Mailbox -AuditEnabled $true only turns on mailbox audit logging if it is not already enabled. The requirement is to view future mailbox sign-ins by users with Full Access (delegates). Delegate MailboxLogin auditing is not enabled by this command alone; the relevant audit action must be included for delegate auditing. Therefore, this solution does not meet the stated goal.

Question 102

DRAG DROP - You have a Microsoft 365 subscription that contains 20 data loss prevention (DLP) policies. You need to identify the following: • Rules that are applied without triggering a policy alert • The top 10 files that have matched DLP policies • Alerts that are miscategorized Which report should you use for each requirement? To answer, drag the appropriate reports to the correct requirements. Each report may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 102
Show Answer
Correct Answer: Rules that are applied without triggering a policy alert: Incident reports The top 10 files that have matched DLP policies: DLP policy matches Alerts that are miscategorized: False positive and override
Explanation:
Incident reports capture rule matches even without policy alerts if incident reporting is configured. DLP policy matches shows matched items including top files. False positive and override tracks user/admin classification of false positives and overrides, helping identify miscategorized alerts.

Question 103

HOTSPOT - You have a Microsoft 365 E5 subscription that uses data loss prevention (DLP) to protect sensitive information. You need to create scheduled reports that generate: • DLP policy matches reported over the shortest frequency of time • DLP incidents reported over the longest frequency of time Which frequency should you configure for each report? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 103
Show Answer
Correct Answer: DLP policy matches: Daily DLP incidents: Every three months
Explanation:
The shortest supported schedule for DLP policy match reports is Daily. The longest supported schedule for DLP incident reports is Every three months (90 days).

$19

Get all 318 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.