Microsoft

SC-400 Free Practice Questions — Page 4

Question 30

You have a Microsoft 365 subscription. You are evaluating whether to use the Microsoft Purview auditing solutions shown in the following table. You plan to implement Microsoft Purview Audit (Standard). Which solutions can you use?

A. Solution2 only
B. Solution3 only
C. Solution1 and Solution2 only
D. Solution2 and Solution3 only
E. Solution1, Solution2, and Solution3
Show Answer
Correct Answer: A
Explanation:
Microsoft Purview Audit (Standard) includes only the core auditing capabilities available to all Microsoft 365 tenants. Advanced or specialized audit solutions (such as premium audit, advanced eDiscovery-related auditing, or specialized workloads) require Audit (Premium). Based on the comparison of the three solutions, only Solution2 is supported with Audit (Standard), while Solution1 and Solution3 require additional licensing.

Question 31

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the sensitive information types (SITs) shown in the following table. A user sends the email messages shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 31 Illustration for SC-400 question 31 Illustration for SC-400 question 31
Show Answer
Correct Answer: SIT1 – No SIT2 – Yes SIT3 – No
Explanation:
SIT1: Although prd:\d{4} matches prd:1234, the supporting keyword "product" is more than 15 characters away, so the proximity requirement fails. SIT2: The 12-digit number 123456789012 matches the regex. The excluded value 111-111-1111 does not block detection because it is not the matched value. SIT3: The credit card function does not match because the card number is incomplete (only last 4 digits provided).

Question 32

DRAG DROP - You have a Microsoft 365 E5 subscription. You need to configure the Microsoft Priva Privacy Risk Management policies to generate alerts for the following scenarios: • Scenario1: A user shares a Microsoft SharePoint Online document library link with a user in a different country. • Scenario2: A user from the sales department emails personal data to a user in a different country. • Scenario3: The personal data stored on a Microsoft SharePoint Online site was NOT modified during the last 120 days. Which policy template should you use for each scenario? To answer, drag the appropriate policy templates to the correct scenarios. Each template may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 32
Show Answer
Correct Answer: Scenario1: Data overexposure Scenario2: Data transfers Scenario3: Data minimization
Explanation:
• Data overexposure detects sharing of personal data through links or access that may expose data beyond intended boundaries (e.g., SharePoint sharing across countries). • Data transfers detects movement of personal data across organizational, departmental, or geographic boundaries (e.g., emailing data to another country). • Data minimization identifies personal data that is no longer actively used or modified, supporting retention and cleanup (e.g., no changes in 120 days).

Question 33

DRAG DROP - You have a Microsoft 365 E5 subscription. You plan to update the overall compliance score for the Microsoft 365 environment. You resolve improvement actions that have a Testing type of Manual and discover that the compliance score fails to update. You need to ensure that the compliance score for manual improvement actions is updated. Which three actions should you perform in sequence from Microsoft Purview Compliance Manager? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Illustration for SC-400 question 33
Show Answer
Correct Answer: From Improvement actions, export the actions. Modify the improvement action items in the exported file. From Improvement actions, select Update actions.
Explanation:
Manual testing actions don’t update the score automatically. You must export the improvement actions to Excel, record the testing results in the file, and then upload them using Update actions so Compliance Manager recalculates the compliance score.

Question 34

You have a Microsoft 365 E5 subscription. You plan to use Microsoft Purview insider risk management. You need to create an insider risk management policy that will detect data theft from Microsoft SharePoint Online by users that submitted their resignation or are near their employment termination date. What should you do first?

A. Configure Office indicators.
B. Configure an HR data connector.
C. Configure a Physical badging connector.
D. Onboard devices to Microsoft Defender for Endpoint.
Show Answer
Correct Answer: B
Explanation:
To detect insider risk scenarios tied to resignation or impending termination, Insider Risk Management must have employment status and termination-date signals. These signals come from HR data. Configuring an HR data connector is the first required step so Purview can ingest resignation and termination information and generate the appropriate risk indicators. Other options (Office indicators, physical badging, or Defender for Endpoint onboarding) are not prerequisites for identifying users who have resigned or are near termination.

Question 35

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 subscription that contains 1.000 user mailboxes. An administrator named Admin1 must be able to search for the name of a competing company in the mailbox of a user named User5. You need to ensure that Admin1 can search the mailbox of User5 successfully. The solution must prevent Admin1 from sending email messages as User5. Solution: You assign the eDiscovery Manager role to Admin1, and then create an eDiscovery case. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: A
Explanation:
Assigning the eDiscovery Manager role allows Admin1 to create eDiscovery (Standard/Premium) cases and search the contents of User5’s mailbox without granting mailbox permissions such as Send As or Send on Behalf. Therefore, Admin1 can perform the search while being prevented from sending email as User5.

Question 36

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 subscription that contains 1.000 user mailboxes. An administrator named Admin1 must be able to search for the name of a competing company in the mailbox of a user named User5. You need to ensure that Admin1 can search the mailbox of User5 successfully. The solution must prevent Admin1 from sending email messages as User5. Solution: You modify the permissions of the mailbox of User5, and then create an eDiscovery case. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
Admin1 can search User5’s mailbox by being assigned the appropriate eDiscovery (Purview) role; no mailbox-level permissions are required. Modifying mailbox permissions is unnecessary and could introduce the ability to send mail as User5, which violates the requirement. Therefore, the proposed solution does not meet the goal.

Question 37

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 subscription that contains 1.000 user mailboxes. An administrator named Admin1 must be able to search for the name of a competing company in the mailbox of a user named User5. You need to ensure that Admin1 can search the mailbox of User5 successfully. The solution must prevent Admin1 from sending email messages as User5. Solution: You start a message trace, and then create a Data Subject Request (DSR) case. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
A message trace only tracks mail flow and cannot search mailbox contents, and a Data Subject Request (DSR) case is for privacy compliance, not for ad-hoc content searches of another user’s mailbox. Neither grants Admin1 the ability to search User5’s mailbox. Proper eDiscovery (Content search) permissions would be required, without assigning send-as rights. Therefore, the solution does not meet the goal.

Question 39

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. Site contains resumes saved as Microsoft Word documents. A new collection of resumes is loaded to Site1 every three months. You plan to implement records management. The solution must meet the following requirements: • The resumes must be retained for two years. • The retention period must start at the end of the quarter during which the resumes were loaded. • The resumes must have a retention label applied that identifies the documents as regulatory records. You need to create a file plan in the CSV format that you will use to create the retention labels. Which retention type should you specify in the file plan?

A. CreationAgeInDays
B. TaggedAgeInDays
C. EventAgeInDays
D. ModificationAgeInDays
Show Answer
Correct Answer: C
Explanation:
The retention must start at the end of the quarter when the resumes are loaded, which requires an event-based trigger (for example, a quarterly event) rather than creation, modification, or labeling time. In a file plan CSV, this is implemented by using an event-based retention type, which corresponds to EventAgeInDays.

Question 40

You have a Microsoft 365 E5 subscription. Your company has two departments named department1 and department2. You configure an information barrier (IB) policy that prevents communication between the users in department1 and department2. You discover that a user named User1 in department1 can still communicate with the users in department2. You validate that the policy works properly for all other users. You need to ensure that User1 cannot communicate with the department2 users. What should you modify?

A. the group assignments of User1
B. the user account attributes of User1
C. the IB policy
D. the IB segments
Show Answer
Correct Answer: B
Explanation:
Information barriers rely on user account attributes (such as Department) to place users into IB segments. If User1 can still communicate while others cannot, their attributes are likely missing or incorrect, causing them not to be evaluated into the correct segment. Modifying User1’s account attributes ensures the IB policy applies correctly. Group assignments and the IB policy/segments are already confirmed to work for other users.

$19

Get all 316 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.