Microsoft

SC-401 Free Practice Questions — Page 6

Question 52

HOTSPOT You have a Microsoft SharePoint Online site named Site1 that contains the users shown in following table. You create the retention labels shown in the following table. You publish the retention labels to Site1. Site1 contains the files shown in following table. Which files can User1 delete on May 15, 2025, and which files can User2 delete on August 15, 2026? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-401 question 52 Illustration for SC-401 question 52 Illustration for SC-401 question 52 Illustration for SC-401 question 52
Show Answer
Correct Answer: May 15, 2025: File1 and File2 August 15, 2026: File1 and File2
Explanation:
Both users can delete files from the site. Retention preserves a copy of a deleted file for the required period; it does not prevent deletion from the library.

Question 53

HOTSPOT You have a Microsoft 365 E5 subscription that uses Microsoft Teams and contains the users shown in the following table. You have the retention policies shown in the following table. The users perform the actions shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-401 question 53 Illustration for SC-401 question 53 Illustration for SC-401 question 53 Illustration for SC-401 question 53
Show Answer
Correct Answer: 1. No 2. Yes 3. Yes
Explanation:
When these retain-then-delete policies overlap, the longer seven-year retention period applies. A deleted Teams message is removed from the user's view, but a compliance copy is preserved in the SubstrateHolds folder during retention.

Question 54

You have a Microsoft 365 E5 subscription. You need to create a Microsoft Defender for Cloud Apps policy that will detect data loss prevention (DLP) violations. What should you create?

A. an access policy
B. an activity policy
C. a file policy
D. a session policy
Show Answer
Correct Answer: C
Explanation:
Create a file policy. Defender for Cloud Apps file policies inspect files and their contents or metadata to detect DLP violations, such as sensitive information in a file.

Question 55

DRAG DROP You have a Microsoft 365 E5 subscription. You need to create the Microsoft Purview insider risk management policies shown in the following table. Which policy template should you use for each policy? To answer, drag the appropriate policy templates to the correct policies. Each template may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

Illustration for SC-401 question 55 Illustration for SC-401 question 55
Show Answer
Correct Answer: Policy1: Data theft by departing users Policy2: Data leaks by priority users Policy3: Data leaks
Explanation:
The departing-users template monitors activity around resignation, including printing. The priority-users template covers accidental external sharing by that group. The general data-leaks template covers SharePoint downloads and transfers to personal cloud storage.

Question 56

You have a Microsoft 365 E5 subscription. You plan to use Microsoft Purview insider risk management. You need to create an insider risk management policy that will detect data theft from Microsoft SharePoint Online by users that submitted their resignation or are near their employment termination date. What should you do first?

A. Configure Office indicators.
B. Onboard devices to Microsoft Defender for Endpoint.
C. Configure a Physical badging connector.
D. Configure a HR data connector.
Show Answer
Correct Answer: D
Explanation:
Configure a human resources (HR) data connector first. Insider risk management uses HR data, such as resignation and termination dates, to identify departing employees for the policy.

Question 57

HOTSPOT You have a Microsoft 365 E5 subscription. From the Microsoft Purview Data Security Posture Management for AI portal, you review the recommendations for AI data security. You plan to create a one-click policy to block elevated risk users from pasting or uploading sensitive data to AI websites. How will the policy be configured? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-401 question 57
Show Answer
Correct Answer: Policy mode: Turn it on right away Policy applies to: Devices only
Explanation:
The one-click policy enforces the block on device-based paste and upload actions to AI websites.

Question 58

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1 and the data loss prevention (DLP) policies shown in the following table. The DLP rules are configured as shown in the following table. All the policies are assigned to Site1. You need to ensure that if a user uploads a document to Site1 that matches all the rules, the user will be shown the Tip 2 policy tip. What should you do?

A. Enable additional processing of the policies if there is a match for Rule1.
B. Prevent additional processing of the policies if there is a match for Rule2.
C. Change the priority of DLP2 to 3.
D. Change the priority of DLP2 to 0.
Show Answer
Correct Answer: D
Explanation:
Set DLP2 to priority 0, the highest priority. When multiple DLP policies match, the policy with the highest priority determines the policy tip shown. This ensures Tip 2 is selected before a matching rule in another policy can stop further processing.

Question 59

You have a Microsoft 365 E5 subscription that contains two users named User1 and Admin1. Admin1 manages audit retention policies for the subscription. You need to ensure that the audit logs of User1 will be retained for 10 years. What should you do first?

A. Assign a Microsoft Purview Audit (Premium) add-on license to Admin1.
B. Assign a 10-year audit log retention add-on license to Admin1.
C. Assign a Microsoft Purview Audit (Premium) add-on license to User1.
D. Assign a 10-year audit log retention add-on license to User1.
Show Answer
Correct Answer: D
Explanation:
Assign the 10-year audit log retention add-on license to User1 first. The retention add-on must be assigned to the user whose audit logs need 10-year retention; Admin1’s role managing the policies does not make Admin1 the licensed user for User1’s activity.

Question 60

HOTSPOT You have a data loss prevention (DLP) policy that has the advanced DLP rules shown in the following table. You need to identify which rules will apply when content matches multiple advanced DLP rules. Which rules should you identify? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-401 question 60 Illustration for SC-401 question 60
Show Answer
Correct Answer: Rule1, Rule2, and Rule3: Only Rule2 takes effect Rule2, Rule3, and Rule4: Only Rule2 takes effect
Explanation:
Rule2 is the first matching rule with the most restrictive action: it restricts access without allowing user overrides.

Question 61

You have a Microsoft 365 E5 subscription that contains a user named User1. All users are assigned Microsoft 365 Copilot licenses. You deploy Microsoft Purview Data Security Posture Management for AI (DSPM for Al). You need to ensure that User1 can analyze prompts and responses for AI interaction events. The solution must follow the principle of least privilege. To which two role groups should you add User1? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

A. Security Reader
B. Content Explorer List Viewer
C. Insider Risk Management Investigators
D. Information Protection Analysts
E. Content Explorer Content Viewer
Show Answer
Correct Answer: D, E
Explanation:
Information Protection Analysts provides the least-privilege access needed to analyze AI interaction events in DSPM for AI. Content Explorer Content Viewer is required to view the actual prompt and response content, rather than only event metadata.

$19

Get all 268 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.