Microsoft

SC-400 Free Practice Questions — Page 16

Question 157

You have a Microsoft 365 E5 subscription that contains the users shown in the following table. You have the core eDiscovery cases shown in the following table. You need to ensure that Admin3 can create holds in Case1 and Case2. The solution must use the principle of least privilege. To what should you add Admin3?

A. the Global Administrator role
B. the eDiscovery Manager role group
C. the Compliance Manager Contributors role group
D. the eDiscovery Administrator role group
Show Answer
Correct Answer: D
Explanation:
To create holds in existing core eDiscovery cases (Case1 and Case2) created by others, Admin3 needs organization-wide access to all eDiscovery cases. Members of the eDiscovery Manager role group can create and manage only the cases they create unless specifically added to other cases. The eDiscovery Administrator designation within the eDiscovery Manager role group can access and manage all cases regardless of ownership, satisfying the requirement with least privilege compared to Global Administrator.

Question 158

DRAG DROP - Your company has two departments named department1 and department2 and a Microsoft 365 E5 subscription. You need to prevent communication between the users in department1 and the users in department2. How should you complete the PowerShell script? To answer, drag the appropriate values to the correct targets. Each value may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 158
Show Answer
Correct Answer: New-OrganizationSegment New-InformationBarrierPolicy
Explanation:
First create an organization segment for Department1 using the user group filter. Then create an information barrier policy assigning that segment, blocking communication with Department2, and activating the policy.

Question 159

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 subscription. You have a user named User1. Several users have full access to the mailbox of User1. Some email messages sent to User1 appear to have been read and deleted before the user viewed them. When you search the audit log in the Microsoft Purview compliance portal to identify who signed in to the mailbox of User1, the results are blank. You need to ensure that you can view future sign-ins to the mailbox of User1. Solution: You run the Set-AdminAuditlogConfig -AdminAuditLogEnabled $true -AdminAuditLogCmdlets *Mailbox* command. Does that meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
No. Set-AdminAuditLogConfig configures administrator audit logging for Exchange admin cmdlets, not mailbox auditing or mailbox sign-in/access events. To view future mailbox access/sign-in related audit events, mailbox auditing must be enabled (organization-wide or per mailbox as appropriate), not admin audit logging.

Question 160

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 subscription. You have a user named User1. Several users have full access to the mailbox of User1. Some email messages sent to User1 appear to have been read and deleted before the user viewed them. When you search the audit log in the Microsoft Purview compliance portal to identify who signed in to the mailbox of User1, the results are blank. You need to ensure that you can view future sign-ins to the mailbox of User1. Solution: You run the Set-AuditConfig -Workload Exchange command. Does that meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
The solution does not meet the goal. Set-AuditConfig -Workload Exchange configures organization-level auditing settings and does not enable logging of delegate mailbox sign-ins. To capture future mailbox logons by users with Full Access (delegates), mailbox auditing must include the MailboxLogin action for delegates (or otherwise configure mailbox audit settings appropriately).

Question 161

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 subscription. You have a user named User1. Several users have full access to the mailbox of User1. Some email messages sent to User1 appear to have been read and deleted before the user viewed them. When you search the audit log in the Microsoft Purview compliance portal to identify who signed in to the mailbox of User1, the results are blank. You need to ensure that you can view future sign-ins to the mailbox of User1. Solution: You run the Set-MailboxFolderPermission -Identity "User1" -User -AccessRights Owner command. Does that meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
No. Running Set-MailboxFolderPermission with AccessRights Owner only changes folder permissions. It does not enable or expose mailbox sign-in auditing. To view future mailbox sign-ins, mailbox auditing/audit log configuration must be enabled and the appropriate audit logs reviewed. Changing folder permissions does not meet the stated goal.

Question 162

HOTSPOT - You have a Microsoft 365 subscription. Auditing is enabled. A user named User1 is a member of a dynamic security group named Group1. You discover that User1 is no longer a member of Group1. You need to search the audit log to identify why User1 was removed from Group1. Which two activities should you use in the search? To answer, select the appropriate activities in the answer area.

Illustration for SC-400 question 162
Show Answer
Correct Answer: Updated user Updated group
Explanation:
For a dynamic group, membership changes occur because either the user's attributes changed (affecting the membership rule) or the group's dynamic membership rule changed. Auditing these two activities identifies the cause.

Question 163

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 E5 subscription. You need to identify resumes that are stored in the subscription by using a built-in trainable classifier. Solution: You create a data loss prevention (DLP) policy. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: A
Explanation:
Yes. Microsoft Purview DLP policies can use built-in trainable classifiers, including the Resume classifier, as conditions to detect and act on stored content across supported Microsoft 365 locations. Creating a DLP policy is therefore a valid way to identify resumes stored in the subscription.

Question 164

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 E5 subscription. You need to identify resumes that are stored in the subscription by using a built-in trainable classifier. Solution: You create an auto-labeling policy for a sensitivity label. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: A
Explanation:
Yes. Built-in trainable classifiers (such as Resume) can be used as conditions in Microsoft Purview auto-labeling policies for sensitivity labels. Creating an auto-labeling policy that uses the Resume trainable classifier will identify matching resumes stored in supported locations and apply the sensitivity label, meeting the stated goal.

Question 165

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 E5 subscription. You need to identify resumes that are stored in the subscription by using a built-in trainable classifier. Solution: You create an auto-labeling policy for a retention label. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
No. Built-in trainable classifiers (such as the Resume classifier) are used with Microsoft Purview auto-labeling for sensitivity labels or with policies that support trainable classifiers, not by creating an auto-labeling policy for a retention label. A retention label auto-apply policy does not use built-in trainable classifiers to identify resumes.

Question 166

HOTSPOT - You have a Microsoft 365 subscription. In Microsoft Exchange Online, you configure the mail flow rule shown in the following exhibit. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 166 Illustration for SC-400 question 166
Show Answer
Correct Answer: Recipients who use Gmail: must sign in to the Office 365 Message Encryption (OME) portal to read messages Recipients from an external Microsoft 365 subscription: will have messages decrypted automatically
Explanation:
The mail flow rule applies the 'Encrypt' RMS template (OMEv2). Gmail recipients access encrypted mail through the OME portal after authentication, while Microsoft 365 recipients using supported Outlook/Microsoft 365 clients get a native experience with automatic decryption.

$19

Get all 318 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.