Microsoft

SC-400 Free Practice Questions — Page 8

Question 72

HOTSPOT - You have a Microsoft 365 subscription that contains a sensitivity label named Contoso Confidential. You publish Contoso Confidential to all users. Contoso Confidential is configured as shown in the Configuration exhibit. (Click the Configuration tab.) The Encryption settings of Contoso Confidential are configured as shown in the Encryption exhibit. (Click the Encryption tab.) For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 72 Illustration for SC-400 question 72 Illustration for SC-400 question 72
Show Answer
Correct Answer: No Yes No
Explanation:
Offline access is allowed for 7 days, so a disabled user is not immediately blocked from opening previously accessed protected content while offline. Permissions are granted to Authenticated users, which includes authenticated guest/B2B users. The label shows no configured auto-labeling policy, so it will not be applied automatically to SharePoint files.

Question 73

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the data loss prevention (DLP) policies shown in the following table. You have a custom employee information form named Templatel.docx. You plan to create a sensitive info type named Sensitive1 that will use the document fingerprint from Template1.docx. What should you use to create Sensitive1, and in which DLP policies can you use Sensitive1? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 73 Illustration for SC-400 question 73
Show Answer
Correct Answer: Security & Compliance PowerShell DLP1, DLP2, and DLP3
Explanation:
Document fingerprint-based sensitive information types are created using Security & Compliance PowerShell (per the documented exam context). Once created, the custom sensitive info type can be referenced by DLP policies across Exchange Online, SharePoint Online, and Microsoft Teams.

Question 74

HOTSPOT - You have a Microsoft 365 subscription that has Enable Security defaults set to No in Azure AD. You have a custom compliance manager template named Regulation1. You have the assessments shown in the following table. Assessment1 has the improvement actions shown in the following table. Assessment2 has the improvement actions shown in the following table. You perform the following actions: • For Assessment2, change the Test status of Establish a threat intelligence program to Implemented. • Enable multi-factor authentication (MFA) for all users. • Configure a privileged access policy. For each of the following statements, select Yes if the statement is true. Otherwise select No. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 74 Illustration for SC-400 question 74 Illustration for SC-400 question 74 Illustration for SC-400 question 74
Show Answer
Correct Answer: No Yes No
Explanation:
Changing the test status in Assessment2 does not affect Assessment1. Enabling MFA satisfies the two MFA technical actions in Assessment1 (+27 +27 = 54). In Assessment2, the privileged access policy technical action can be automatically credited (+15), but manually changing the operational action's test status does not automatically increase the assessment score in the same way, so the score does not increase by 78 points.

Question 75

DRAG DROP - You have a Microsoft 365 E5 subscription and use Microsoft Purview. The subscription contains the following users: • User1: Must be able to investigate policy matches, but unable to view the file content related to the match. • User2: Must be able to investigate policy matches and view the file content related to the match. • User3: Must be able to create, update, and delete Microsoft Priva Privacy Risk Management policies. You need to add each user to a role group. The solution must follow the principle of least privilege. To which role group should you add each user? To answer, drag the appropriate role groups to the correct users. Each group may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 75
Show Answer
Correct Answer: User1: Privacy Management Analysts User2: Privacy Management Investigators User3: Privacy Management Administrators
Explanation:
Analysts can investigate policy matches without viewing file content. Investigators can investigate matches and view associated file content. Administrators have full permissions, including creating, updating, and deleting Privacy Risk Management policies.

Question 76

HOTSPOT - You have a Microsoft 365 E5 tenant that contains the objects shown in the following table. You need to restore a Microsoft Word document that was deleted from the Sales channel by User1. From where can the document be restored, and how long will the document be retained? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 76 Illustration for SC-400 question 76
Show Answer
Correct Answer: Restored from: Microsoft SharePoint Online Retained for: 93 days
Explanation:
Files shared in a Microsoft Teams channel are stored in the team's SharePoint Online document library. Deleted files can be restored from the SharePoint recycle bin, where they are retained for up to 93 days by default.

Question 77

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Project1. You need to recommend a record management solution that meets the following requirements: • Retains files in Project1 for a minimum of 10 years • Once Project1 is complete, retains files for an additional five years before the files are deleted Which two components should you include in the recommendation? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A. a data loss prevention (DLP) policy
B. an adaptive scope
C. an event type
D. a file plan
E. a sensitivity label
Show Answer
Correct Answer: C, D
Explanation:
Use a retention label configured with an event-based retention trigger. An event type is required to start the additional retention period when the project is completed. A file plan is used to define and publish retention labels, including event-based retention settings and retention/deletion behavior. DLP and sensitivity labels do not provide this records retention workflow, and an adaptive scope is for targeting policies, not defining event-based retention logic.

Question 78

You create a label that encrypts email data. Users report that they cannot use the label in Outlook on the web to protection the email messages they send. You need to ensure that the users can use the new label to protect their email. What should you do?

A. Create a label policy.
B. Create a new sensitive information type.
C. Modify the priority order of label policies.
D. Wait six hours and ask the users to try again.
Show Answer
Correct Answer: A
Explanation:
Sensitivity labels must be published through a label policy before users can see and apply them in Outlook on the web or other supported apps. Simply creating the label is not sufficient. Creating a sensitive information type is unrelated, changing policy priority does not publish an unpublished label, and waiting does not resolve the absence of a publishing policy.

Question 80

HOTSPOT - You have a Microsoft 365 E5 subscription. You are evaluating Data Protection Baseline compliance by using Compliance Manager. You need to identify improvement actions that meet the following requirements: • Provide data loss prevention (DLP) policy recommendations. • Provide Data Protection Baseline recommendations. Which filter should you use for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 80
Show Answer
Correct Answer: DLP policy recommendations: Solutions Data Protection Baseline recommendations: Regulations
Explanation:
Filter by Solutions to find improvement actions related to the DLP solution. Filter by Regulations to view improvement actions associated with the Microsoft Data Protection Baseline assessment.

Question 81

HOTSPOT - You have a Microsoft 365 E5 subscription that contains the groups shown in the following table. The subscription contains the users shown in the following table. You create the mail flow rules shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 81 Illustration for SC-400 question 81 Illustration for SC-400 question 81 Illustration for SC-400 question 81
Show Answer
Correct Answer: No Yes No
Explanation:
Rule2 matches only when the sender is the distribution group's address ([email protected]), not a member of that group. Rule1 matches when the recipient is a member of Group1 (such as User1), but not when the recipient is the Group1 address itself.

Question 82

HOTSPOT - You have a Microsoft 365 E5 subscription that uses Microsoft Exchange Online and Teams. You need to ensure that when a user sends a message containing a cloud attachment, a retention label is applied to the cloud attachment by using auto-labeling policy. How should you configure the retention label to start the retention period, and to which locations should you apply the auto-labeling policy? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-400 question 82
Show Answer
Correct Answer: Labeled Microsoft 365 Group mailboxes & sites, OneDrive accounts, and SharePoint classic and communication sites only
Explanation:
For auto-applied retention labels on cloud attachments, start retention when the item is labeled so the retention period begins upon automatic labeling. Cloud attachments used in Exchange and Teams reside in SharePoint and OneDrive, and Microsoft 365 Groups cover Teams-connected group resources, so include all these locations.

$19

Get all 318 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.