Microsoft

SC-400 Free Practice Questions — Page 3

Question 21

HOTSPOT - You have a Microsoft 365 subscription that contains the users shown in the following table. You have the information barrier (IB) segments shown in the following table. You apply the IB policies shown in the following table. You create the new IB policies shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 21 Illustration for SC-400 question 21 Illustration for SC-400 question 21 Illustration for SC-400 question 21 Illustration for SC-400 question 21
Show Answer
Correct Answer: No No No
Explanation:
Allow policies restrict a segment to communicate only with specified target segments. HR is only allowed with Engineering; Engineering only with HR. Investments and Marketing have block policies. A user with no segment is not covered by these segments, but existing allow-policy configuration and IB policy validation mean the added block policies conflict with the existing allow configuration and cannot all be applied together.

Question 22

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the users shown in the following table. You have the eDiscovery cases shown in the following table. The eDiscovery cases have the members shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 22 Illustration for SC-400 question 22 Illustration for SC-400 question 22 Illustration for SC-400 question 22
Show Answer
Correct Answer: No No Yes
Explanation:
Only an eDiscovery Administrator can remove members from a case. Admin1 is only an eDiscovery Manager. Admin2 is an eDiscovery Administrator and can manage/remove members in cases after accessing the case.

Question 23

You have a Microsoft 365 subscription that contains the users shown in the following table. You review the audit retention period of each user. Which users' audit logs are retained for nine months?

A. User3 only
B. User1 and User3
C. User2 and User3
D. User1, User2, and User3
Show Answer
Correct Answer: A
Explanation:
Microsoft Purview Audit (Standard) retains audit records for 90 days. Microsoft 365 E5 includes Microsoft Purview Audit (Premium/Advanced Audit), which provides a default retention of nine months for eligible audit records. Microsoft 365 E3 and F3 without the Advanced Audit add-on remain at the standard 90-day retention. Therefore, only the E5-licensed user has audit logs retained for nine months.

Question 24

You have a Microsoft 365 E5 subscription. You use the following services: • Microsoft Teams • Microsoft Entra ID • Microsoft OneDrive • Microsoft Exchange Online • Microsoft SharePoint Online Which two services can you monitor by using Microsoft Purview communication compliance? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

A. SharePoint Online
B. Exchange Online
C. Microsoft Entra ID
D. OneDrive
E. Teams
Show Answer
Correct Answer: B, E
Explanation:
Microsoft Purview Communication Compliance monitors communications across supported workloads such as Exchange Online email and Microsoft Teams chats/channels. SharePoint Online and OneDrive are monitored by other Purview capabilities (such as Insider Risk or DLP) rather than as primary communication sources, and Microsoft Entra ID is not a communication workload.

Question 25

DRAG DROP - You have a Microsoft 365 E5 subscription. You need to meet the following requirements: • Prevent the sharing of files between the users in a department named department and the users in a department named department2. • Generate an alert if a user downloads large quantities of sensitive customer data. Which type of policy should you use for each requirement? To answer, drag the appropriate policy types to the correct requirements. Each policy type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 25
Show Answer
Correct Answer: Prevent sharing: Information barrier policy Generate alert for large sensitive downloads: Insider risk management policy
Explanation:
Information barriers block communication and file sharing between defined groups. Insider Risk Management detects risky activities such as mass downloads of sensitive data and generates alerts.

Question 26

You have a Microsoft 365 E5 subscription that contains a retention policy named RP1 as shown in the following table. You place a preservation lock on RP1. You need to modify RP1. Which two actions can you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A. Decrease the retention period of the policy.
B. Delete the policy.
C. Increase the retention period of the policy.
D. Disable the policy.
E. Remove locations from the policy.
F. Add locations to the policy.
Show Answer
Correct Answer: C, F
Explanation:
A preservation lock makes a retention policy immutable in ways that would reduce its protective scope. You cannot decrease the retention period, delete or disable the policy, or remove locations. You can increase the retention period and add new locations because those changes strengthen or expand retention.

Question 27

HOTSPOT - You have a Microsoft 365 E5 subscription. You plan to create the Microsoft Priva Privacy Risk Management policies shown in the following table. Which policies can you apply to Microsoft Exchange Online email, and which policies can you apply to Microsoft SharePoint Online sites? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 27 Illustration for SC-400 question 27
Show Answer
Correct Answer: Exchange Online email: Policy2 only SharePoint Online sites: Policy1, Policy2, and Policy3
Explanation:
Data Transfers policies apply to Exchange Online. SharePoint Online supports Data Overexposure, Data Transfers, and Data Minimization policies.

Question 28

You have a Microsoft 365 E5 subscription that contains the groups shown in the following table. You need to create a Privacy Risk Management policy in Microsoft Priva. To which groups can you apply the policy?

A. Group1 only
B. Group1 and Group2 only
C. Group1, Group2, and Group3 only
D. Group1, Group3, and Group4 only
E. Group1, Group2, Group3, and Group4
Show Answer
Correct Answer: A
Explanation:
Microsoft Priva Privacy Risk Management policies can be scoped to individual users and Microsoft 365 (Office 365) Groups. Without the group table, the supported interpretation is that only the Microsoft 365 group is applicable, making Group1 only the valid choice.

Question 29

HOTSPOT - You have a Microsoft 365 E5 subscription the uses Microsoft Priva. You plan to create the Privacy risk management policies shown in the following table. Which policies can send email notifications, and which policies can show policy tips in Microsoft Teams when a policy match is detected? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 29 Illustration for SC-400 question 29
Show Answer
Correct Answer: Can send email notifications: Policy1, Policy2, and Policy3 Can show policy tips in Teams: Policy2 only
Explanation:
In Microsoft Priva Privacy Risk Management, all three policy types support email notification actions, while Microsoft Teams policy tips are supported only for Data transfers policies.

Question 30

HOTSPOT - You have a Microsoft 365 E5 subscription. You plan to use the Microsoft Purview compliance portal to map human resources (HR) data for use with insider risk management policies. You need to add a data connector to import the HR data. What should you do first, and in which format should you import the data? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 30
Show Answer
Correct Answer: First: Register an app in Microsoft Entra ID Import as: CSV
Explanation:
For the Microsoft Purview HR connector used with Insider Risk Management, you first register an application in Microsoft Entra ID, then create the HR connector. HR data is uploaded in CSV format.

$19

Get all 318 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.