Microsoft

SC-401 Free Practice Questions — Page 7

Question 62

You have a Microsoft 365 E5 subscription. You need to apply data loss prevention (DLP) policies to the following: • Microsoft Exchange Online mailboxes • Microsoft SharePoint Online sites • Microsoft Power BI workspaces • Microsoft OneDrive accounts • On-premises repositories What is the minimum number of DLP policies required to achieve the goal?

A. 1
B. 2
C. 3
D. 4
E. 5
Show Answer
Correct Answer: B
Explanation:
Two DLP policies are required. One can cover Exchange Online, SharePoint Online, OneDrive, and supported on-premises repositories. Power BI workspaces require a separate DLP policy because Power BI policies can’t be combined with policies for other locations.

Question 63

You are creating a custom trainable classifier to identify organizational product codes referenced in Microsoft 365 content. You identify 300 files to use as seed content. Where should you store the seed content?

A. an Azure file share
B. a Microsoft OneDrive folder
C. a Microsoft SharePoint Online folder
D. a Microsoft Exchange Online shared mailbox
Show Answer
Correct Answer: C
Explanation:
Store the seed files in a Microsoft SharePoint Online folder. Trainable classifiers use SharePoint content as the location for training files.

Question 64

You have a Microsoft 365 E5 subscription. You have a Microsoft SharePoint Online document library that contains Microsoft Word and Excel documents. The documents contain the following types of information: • Credit card numbers • Physical addresses in the UK • National health service numbers from the UK • Sensitive projects that contain the following words: Project Tailspin, Project Contoso, and Project Falcon You have email messages in Microsoft Exchange Online that contain the following information types: • Credit card numbers • User sign-in credentials • National health service numbers from the UK You plan to use sensitive information types (SITs) for compliance policies. What is the minimum number of SITs required to classify all the information types?

A. 2
B. 5
C. 7
D. 10
Show Answer
Correct Answer: B
Explanation:
Five SITs are required: one each for credit card numbers, UK physical addresses, UK NHS numbers, and user sign-in credentials, plus one custom SIT that detects all three project names using keywords or a keyword dictionary.

Question 65

You have a Microsoft 365 subscription that contains 100 users and a Microsoft 365 group named Group1. All users have Windows 11 devices and use Microsoft SharePoint Online and Exchange Online. A sensitivity label named Label1 is published as the default label for Group1. You add two sublabels named Sublabel1 and Sublabel2 to Label1. You need to ensure that the settings in Sublabel1 are applied by default to Group1. What should you do?

A. Modify the policy of Label1.
B. Duplicate all the settings from Sublabel1 to Label1.
C. Delete the policy of Label1 and publish Sublabel1.
D. Change the order of Sublabel1.
Show Answer
Correct Answer: A
Explanation:
The default label is specified in the publishing policy. Modify that policy to set Sublabel1 as the default; changing the sublabel’s order or copying its settings to Label1 will not select Sublabel1 by default.

Question 66

HOTSPOT You have a Microsoft 365 subscription that contains the sensitive information types (SITs) shown in the following exhibit. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

Illustration for SC-401 question 66 Illustration for SC-401 question 66
Show Answer
Correct Answer: To create a new SIT, you can copy: ABA Routing Number and Adatum numbers only. You can edit directly without creating a copy first: Adatum numbers only.
Explanation:
The built-in ABA Routing Number SIT can be copied but not edited directly. Adatum numbers is a custom entity SIT, so it can be copied or edited directly.

Question 67

HOTSPOT You have a Microsoft 365 subscription that contains the users shown in the following table. You create the data loss prevention (DLP) policies shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for SC-401 question 67 Illustration for SC-401 question 67 Illustration for SC-401 question 67
Show Answer
Correct Answer: 1. No 2. Yes 3. No
Explanation:
Policy1 excludes messages to user4@fabrikam.com, so Policy2 blocks the first message. Policy1 encrypts the second message and stops further DLP processing. User2 is outside Policy1’s scope, so Policy2 blocks the third message.

Question 68

You have a Microsoft 365 E5 subscription. You plan to create an exact data match (EDM) classifier named EDM1. You need to grant permissions to hash and upload the sensitive information source table for EDM1. What should you create first?

A. a Microsoft 365 group named EDM_DataUploaders
B. a Microsoft Entra enterprise application named EDM_DataUploaders
C. a Microsoft Entra app registration named EDM_DataUploaders
D. a Microsoft Purview role group named EDM_DataUploaders
E. a security group named EDM_DataUploaders
Show Answer
Correct Answer: E
Explanation:
Create a Microsoft Entra security group named EDM_DataUploaders first. You can then grant that group the permissions needed to hash and upload the EDM source table.

Question 69

You have a Microsoft 365 subscription. You plan to retain the following audit log record types and activities for the next three years: • CopilotInteraction: All activities selected (1/1) o Interacted with Copilot • ComplianceDLPEndpoint: All activities selected (2/2) o Matched DLP rule o Removed DLP rule from document • AzureActiveDirectory: 2 of 25 activities selected (2/25) o Reset user password o Changed user password What is the minimum number of audit retention policies you should create to retain only the selected record types and activities?

A. 1
B. 2
C. 3
D. 5
Show Answer
Correct Answer: B
Explanation:
Create two policies. CopilotInteraction and ComplianceDLPEndpoint can be combined because all activities are selected for both record types. AzureActiveDirectory needs a separate policy to retain only the two selected activities rather than all activities.

Question 70

HOTSPOT You are implementing Microsoft Purview Advanced Message Encryption for a Microsoft 365 tenant named contoso.com. You need to meet the following requirements: • All email to a domain named fabrikam.com must be encrypted automatically. • Encrypted emails must expire seven days after they are sent. What should you configure for each requirement? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-401 question 70
Show Answer
Correct Answer: All email to fabrikam.com: A mail flow rule in the Exchange admin center Encrypted emails expire after seven days: A custom branding template in Microsoft Exchange Online PowerShell
Explanation:
A mail flow rule can automatically encrypt messages addressed to fabrikam.com. Advanced Message Encryption expiration is configured on a custom branding template.

Question 71

HOTSPOT You have a Microsoft 365 tenant. You need to create a new sensitive info type for items that contain the following: • An employee ID number that consists of the hire date of the employee followed by a three digit number • The words "Employee", "ID", or "Identification" within 300 characters of the employee ID number What should you use for the primary and secondary elements? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for SC-401 question 71
Show Answer
Correct Answer: Primary element: A regular expression Secondary element: A keyword list
Explanation:
A regular expression matches the hire-date-plus-three-digit ID format. A keyword list matches “Employee,” “ID,” or “Identification” within 300 characters of the ID.

$19

Get all 268 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.