Microsoft

SC-400 Free Practice Questions — Page 6

Question 51

HOTSPOT - You are creating a data loss prevention (DLP) policy named DLP1 as shown in the following exhibit. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 51 Illustration for SC-400 question 51
Show Answer
Correct Answer: cannot enable any other location Content contains
Explanation:
Selecting Power BI workspaces as the DLP location locks the policy to that workload, so no other locations can be enabled. For Power BI/Fabric DLP policies, supported rule conditions are limited, and content inspection is done using the **Content contains** condition.

Question 52

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. Site1 contains a file named File1. You have a retention policy named Retention1 that has the following settings: • Retention items for a specific period o Retention period: 5 years o At the end of the retention period: Delete items automatically Retention1 is applied to Site1. You need to ensure that File1 is deleted automatically after seven years. The solution must NOT affect the retention of other files on Site1. What should you do first?

A. Move File1 to a new folder and configure the access control list (ACL) entries for File1.
B. Create a new retention policy.
C. Publish and apply a new retention label.
D. Move File1 to a new folder and list the excluded locations for Retention1.
Show Answer
Correct Answer: C
Explanation:
The existing retention policy retains all items in Site1 for 5 years and then deletes them, which would delete File1 too early. To keep File1 for a different duration without affecting other files, you must use a retention label. Creating and publishing a new retention label with a 7‑year retention and applying it to File1 overrides the site-level retention policy for that file only. This ensures File1 is deleted after seven years while other files continue to follow Retention1.

Question 53

You have a Microsoft 365 E5 subscription. You create a sensitivity label named Label1 and publish Label1 to all users and groups. You have the following files on a computer: • File1.doc • File2.docx • File3.xlsx • File4.txt You need to identify which files can have Label1 applied. Which files should you identify?

A. File2.docx only
B. File2.docx and File3.xlsx only
C. File1.doc, File2.docx, and File3.xlsx only
D. File1.doc, File2.docx, File3.xlsx, and File4.txt
Show Answer
Correct Answer: B
Explanation:
Microsoft Purview sensitivity labels are supported for modern Office file formats such as .docx and .xlsx. Legacy Office formats like .doc and plain text files like .txt do not support sensitivity labeling. Therefore, only File2.docx and File3.xlsx can have Label1 applied.

Question 54

You have a Microsoft 365 subscription. Users have devices that run Windows 11. You plan to create a Microsoft Purview insider risk management policy that will detect when a user performs the following actions: • Deletes files that contain a sensitive information type (SIT) from their device • Copies files that contain a SIT to a USB drive • Prints files that contain a SIT You need to prepare the environment to support the policy. What should you do?

A. Configure the physical badging connector.
B. Onboard the devices to Microsoft Purview.
C. Configure the HR data connector.
D. Create a Microsoft Purview communication compliance policy.
Show Answer
Correct Answer: B
Explanation:
To detect file deletion, USB copy, and printing of files containing sensitive information on Windows 11 endpoints, Insider Risk Management requires endpoint activity signals. These signals are available only after devices are onboarded to Microsoft Purview (via Microsoft Defender for Endpoint integration). Physical badging and HR connectors are optional enrichment sources, and communication compliance is unrelated.

Question 55

HOTSPOT - You have a Microsoft 365 E5 subscription that has data loss prevention (DLP) implemented. You plan to export DLP activity by using Activity explorer. The exported file needs to display the sensitive info type detected for each DLP rule match. What should you do in Activity explorer before exporting the data, and in which file format is the file exported? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 55
Show Answer
Correct Answer: In Activity explorer: Add a custom column File type: CSV
Explanation:
To include the sensitive info type for each DLP rule match in the export, you must add the Sensitive info type as a custom column in Activity explorer. Activity explorer exports data only in CSV format, not JSON, TXT, or XML.

Question 56

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the groups shown in the following table. The subscription contains the resources shown in the following table. You create a sensitivity label named Label 1. You need to publish Label1 and have the label apply automatically. To what can you publish Label1, and to what can Label1 be auto-applied? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 56 Illustration for SC-400 question 56 Illustration for SC-400 question 56
Show Answer
Correct Answer: Publish to: Group1, Group2, Site1, and Team1 Auto-apply to: Site1 only
Explanation:
Sensitivity labels can be published to users and groups (Microsoft 365 groups and security groups), and to containers such as SharePoint sites and Teams. However, auto-apply (service-side) sensitivity labeling applies only to content stored in SharePoint Online or OneDrive, not directly to groups or Teams containers. Therefore, automatic application is supported only for the SharePoint site (Site1).

Question 57

SIMULATION - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below. Microsoft 365 Username: Microsoft 365 Password: ********** If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 12345678 - You need to create a retention policy that meets the following requirements: • Applies to Microsoft Teams chat and Teams channel messages of users that have a department attribute of Sales. • Retains item for five years from the date they are created, and then deletes them. To complete this task, sign in to the appropriate admin center.

Show Answer
Correct Answer: Sign in to Microsoft Purview compliance portal Create an adaptive scope (Users) with attribute Department = Sales Create a retention policy using Adaptive scope Select locations: Teams chats and Teams channel messages Set retention: Retain 5 years from creation, then delete
Explanation:
An adaptive scope filters users by the Department attribute (Sales). A Purview retention policy scoped to that adaptive scope can target Teams chats and channel messages. Setting retention to five years from creation with automatic deletion meets the lifecycle requirement.

Question 58

SIMULATION - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below. Microsoft 365 Username: Microsoft 365 Password: ********** If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 12345678 - You plan to implement Endpoint data loss prevention (Endpoint DIP) policies for computers that run Windows. Users have an application named App1 that stores data locally in a folder named C:\app1\data. You need to prevent the folder from being monitored by Endpoint DIP. To complete this task, sign in to the appropriate admin center.

Show Answer
Correct Answer: Microsoft Purview compliance portal Settings > Data loss prevention > Endpoint DLP settings File path exclusions for Windows Add: C:\app1\data
Explanation:
Endpoint DLP path exclusions are configured centrally in the Microsoft Purview compliance portal. Adding C:\app1\data under File path exclusions for Windows prevents Endpoint DLP from monitoring or enforcing policies on files in that folder.

Question 59

SIMULATION - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below. Microsoft 365 Username: Microsoft 365 Password: ********** If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 12345678 - You plan to automatically apply a watermark to the documents of a project named Falcon. You need to create a label that will add a watermark of “Project Falcon” in red, size-12 font diagonally across the documents. To complete this task, sign in to the appropriate admin center.

Show Answer
Correct Answer: Sign in to the Microsoft Purview compliance portal. Go to Solutions > Information protection > Labels. Create a sensitivity label for Project Falcon. Configure content marking with a diagonal watermark: "Project Falcon", red, size 12. Publish the label (and auto-label if required).
Explanation:
Sensitivity labels and document watermarks are created and managed in the Microsoft Purview compliance portal under Information protection. From there, you can define the label, configure the watermark settings, and publish or auto-apply the label to project documents.

Question 60

SIMULATION - Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and click on the username below. To enter your password, place your cursor in the Enter password box and click on the password below. Microsoft 365 Username: Microsoft 365 Password: ********** If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab. The following information is for technical support purposes only: Lab Instance: 12345678 - You need to ensure that a group named U.S. Sales can store files containing information subject to General Data Protection Regulation (GDPR) in their OneDrive accounts. All other current GDPR restrictions must remain in effect. To complete this task, sign in to the appropriate admin center.

Show Answer
Correct Answer: Sign in to the Microsoft Purview compliance portal. Create a new custom DLP policy for OneDrive. Scope the policy to include only the U.S. Sales group. Configure the rule to allow GDPR-sensitive information. Leave existing GDPR DLP policies unchanged.
Explanation:
You must not modify existing GDPR restrictions. Instead, create a separate custom DLP policy in Microsoft Purview that applies only to OneDrive accounts of the U.S. Sales group and allows GDPR-sensitive content. All other users remain governed by the current GDPR DLP policies.

$19

Get all 316 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.