sc-400 5
sc-400 5
Get the Full SC-400 dumps in VCE and PDF From SurePassExam
https://www.surepassexam.com/SC-400-exam-dumps.html (154 New Questions)
Microsoft
Exam Questions SC-400
Microsoft Information Protection Administrator
NEW QUESTION 1
- (Topic 1)
You have a Microsoft 365 E5 subscription. You create a role group named Rote1.
You need to add a role to Role1 that will enable group members to view the metadata of records that were tagged for deletion automatically at the end of the
records' retention period. The solution must use the principle of least privilege.
Which role should you add?
A. Review
B. View-Only Retention Management
C. Retention Management
D. Disposition Management
E. Record Management
Answer: B
NEW QUESTION 2
HOTSPOT - (Topic 1)
You plan to create a custom sensitive information type that will use Exact Data Match (EDM).
You need to identify what to upload to Microsoft 365, and which tool to use for the upload. What should you identify? To answer, select the appropriate options in
the answer area. NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
NEW QUESTION 3
HOTSPOT - (Topic 1)
You have Microsoft 365 ES subscription that has data loss prevention (DLP) implemented. You plan to export DLP activity by using Activity explorer.
The exported file needs to display the sensitive info type detected for each DLP match.
What should you do in Activity explorer before the data, and in which file exported? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
NEW QUESTION 4
- (Topic 1)
You have a Microsoft OneDrive for Business folder that contains the files shown in the following table.
In Microsoft Cloud App Security, you create a file policy to automatically apply a classification.
What is the effect of applying the policy?
A. The policy will apply to only the .docx and .txt file
B. The policy will classify the files within 24 hours.
C. The policy will apply to all the file
D. The policy will classify only 100 files daily.
E. The policy will apply to only the .docx file
F. The policy will classify only 100 files daily.
G. The policy will apply to only the .docx and .txt file
H. The policy will classify the files immediately.
Answer: C
Explanation:
Reference:
https://docs.microsoft.com/en-us/cloud-app-security/azip-integration
NEW QUESTION 5
- (Topic 1)
You have a sensitive information type based on a trainable classifier. You are unsatisfied with the result of the result of trainable classifier. You need to retrain the
classifier.
What should you use in the Microsoft 365 compliance center?
Answer: C
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/classifier-how-to-retrain-content-explorer?view=o365-worldwide
NEW QUESTION 6
- (Topic 1)
Your company has a Microsoft 365 tenant that uses a domain named contoso.
The company uses Microsoft Office 365 Message Encryption (OMI ) to encrypt email sent to users in fabrikam.com.
A user named User1 erroneously sends an email to user2@fabrikam You need to disable user2@fabrikam.com from accessing the email. What should you do?
Answer: C
NEW QUESTION 7
- (Topic 1)
You have a Microsoft 365 E5 subscription that contains a user named User1.
You need to ensure that all email messages that contain attachments are encrypted automatically by using Microsoft Purview Message Encryption.
What should you create?
A. a sensitivity label
B. an information barrier segment
C. a data loss prevention (DLP) policy
D. a mail flow rule
Answer: D
NEW QUESTION 8
HOTSPOT - (Topic 1)
You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.
You create the mail flow rules shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
NEW QUESTION 9
- (Topic 1)
You need to recommend a solution that meets the compliance requirements for protecting the documents in the Data shared folder. What should you recommend?
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/azure/information-protection/deploy-aip-scanner
NEW QUESTION 10
HOTSPOT - (Topic 1)
You have a Microsoft 365 E5 subscription.
You receive the data loss prevention (DIP) alert shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graph.
NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
NEW QUESTION 10
HOTSPOT - (Topic 1)
You need to recommend an information governance solution that meets the HR requirements for handling employment applications and resumes.
What is the minimum number of information governance solution components that you should create? To answer, select the appropriate options in the answer
area.
NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
NEW QUESTION 14
- (Topic 1)
You have a Microsoft 365 E5 tenant that contains a user named User1.
You need to identify the type and number of holds placed on the mailbox of User1. What should you do first?
Answer: B
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/identify-a-hold-on-an-exchange-online-mailbox?view=o365-worldwide
NEW QUESTION 18
HOTSPOT - (Topic 1)
You have a Microsoft 365 ES subscription.
You plan to create a custom trainable classifier by uploading 1,000 machine-generated files as seed content.
The files have sequential names and are uploaded in one-minute intervals as shown in the following table.
Which files were processed first and last when you created the custom trainable classifier? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
NEW QUESTION 19
HOTSPOT - (Topic 1)
You have Microsoft 365 E5 tenant that has a domain name of M365x925027.onmicrosoft.com.
You have a published sensitivity label.
The Encryption settings for the sensitivity label are configured as shown in the exhibit.
For each of the following statements, select Yes if statement is true. Otherwise, select No
NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
Box 1: Yes
When you create a sensitivity label, you can restrict access to content that the label will be applied to. Only users within your organization can open a confidential
document or email.
Box 2: No
Assign permissions now has been selected.
Box 3: No
Only co-author and co-owner can print.
NEW QUESTION 20
- (Topic 1)
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the
stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You are configuring a file policy in Microsoft Cloud App Security.
You need to configure the policy to apply to all files. Alerts must be sent to every file owner who is affected by the policy. The policy must scan for credit card
numbers, and alerts must be sent to the Microsoft Teams site of the affected department.
Solution: You use the Data Classification service inspection method and send alerts as email.
Does this meet the goal?
A. Yes
B. No
Answer: B
Explanation:
Reference:
https://docs.microsoft.com/en-us/cloud-app-security/dcs-inspection https://docs.microsoft.com/en-us/cloud-app-security/data-protection-policies
NEW QUESTION 22
- (Topic 1)
You have a Microsoft 365 tenant that uses 100 data loss prevention (DLP) policies.
A Microsoft Exchange administrator frequently investigates emails that were blocked due to DLP policy violations.
You need to recommend which DLP report the Exchange administrator can use to identify how many messages were blocked based on each DLP policy.
Which report should you recommend?
Answer: C
NEW QUESTION 24
- (Topic 1)
You have a Microsoft 365 tenant that uses records management.
You use a retention label to mark legal files stored in a Microsoft SharePoint Online document library as
regulatory records.
What can you do to the legal files?
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/records- management?view=o365-worldwide
NEW QUESTION 29
HOTSPOT - (Topic 1)
You have a Microsoft 365 sensitivity label that is published to all the users in your Azure AD tenant as shown in the following exhibit.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
NEW QUESTION 33
HOTSPOT - (Topic 1)
You have a Microsoft 365 ES subscription that uses data loss prevention (DLP) to protect sensitive information.
You need to create scheduled reports that generate.
* DLP policy matches reported over the shortest frequency of time
* DLP incidents reported over the longest frequency of time
Which frequency should you configure for each repot? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
NEW QUESTION 35
- (Topic 1)
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You implement Microsoft 365 Endpoint data loss prevention (Endpoint DLP).
You have computers that run Windows 10 and have Microsoft 365 Apps installed. The computers are joined to Azure Active Directory (Azure AD).
You need to ensure that Endpoint DLP policies can protect content on the computers. Solution: You onboard the computers to Microsoft Defender for Endpoint.
Does this meet the goal?
A. Yes
B. No
Answer: A
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-getting-started?view=o365-worldwide
NEW QUESTION 37
- (Topic 1)
You have a Microsoft 365 E5 subscription.
You plan to use insider risk management to collect and investigate forensic evidence. You need to enable forensic evidence capturing.
What should you do first?
Answer: D
NEW QUESTION 38
- (Topic 1)
You have a Microsoft 365 tenant that uses the following sensitivity labels:
* Confidential
* Internal
* External
The labels are published by using a label policy named Policy1.
Users report that Microsoft Office for the wen apps do not display the Sensitivity button. The Sensitivity button appears in Microsoft 365 Apps that are installed
locally.
You need to ensure that the users can apply sensitivity labels to content when they use Office for the web apps.
Solution: You modify the scope of the Confidential label. Does this meet the goal?
A. Yes
B. No
Answer: B
NEW QUESTION 39
- (Topic 1)
You need to create a retention policy to delete content after seven years from the following locations:
? Exchange email
? SharePoint sites
? OneDrive accounts
? Office 365 groups
? Teams channel messages
? Teams chats
What is the minimum number of retention policies that you should create?
A. 1
B. 2
C. 3
D. 4
Answer: A
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/retention?view=o365-worldwide
NEW QUESTION 43
- (Topic 1)
You have a Microsoft 365 E5 subscription that contains a trainable classifier named Trainable1. You plan to create the items shown in the following table.
A. Label2 only
B. Label1 and Label2 only
C. Label1 and Policy1 only
D. Label2 Policy1, and DLP1 only
E. Label1, Label2, Policy1, and DLP1
Answer: A
NEW QUESTION 45
- (Topic 1)
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the
stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 tenant and 500 computers that run Windows 10. The computers are onboarded to the Microsoft 365 compliance center.
You discover that a third-party application named Tailspin_scanner.exe accessed protected
sensitive information on multiple computers. Tailspin_scanner.exe is installed locally on the computers.
You need to block Tailspin_scanner.exe from accessing sensitive documents without preventing the application from accessing other documents.
Solution: From the Cloud App Security portal, you create an app discovery policy. Does this meet the goal?
A. Yes
B. No
Answer: B
Explanation:
You can create app discovery policies to alert you when new apps are detected within your organization.
Use the unallowed apps list instead.
Reference:
https://docs.microsoft.com/en-us/cloud-app-security/cloud-discovery-policies
https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-using?view=o365- worldwide
NEW QUESTION 47
- (Topic 1)
You need to recommend a solution that meets the executive requirements. What should you recommend?
Answer: C
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/create-apply-retention-labels?view=o365-worldwide
NEW QUESTION 52
- (Topic 1)
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the
stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 subscription.
You have a user named User1. Several users have full access to the mailbox of User1. Some email messages sent to User1 appear to have been read and
deleted before the user viewed them.
When you search the audit log in the Microsoft Purview compliance portal to identify who signed in to the mailbox of User1, the results are blank.
You need to ensure that you can view future sign-ins to the mailbox of User1. Solution: You run the Set-AuditConfig -Workload Exchange command.
Does that meet the goal?
A. Yes
B. No
Answer: A
NEW QUESTION 54
- (Topic 1)
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the
stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 E5 subscription.
You need to identify resumes that are stored in the subscription by using a built-in trainable classifier.
Solution: You create a data loss prevention (DLP) policy. Does this meet the goal?
A. Yes
B. No
Answer: B
NEW QUESTION 59
- (Topic 1)
You have a Microsoft 365 E5 subscription that uses Yammer.
You need to create a Microsoft Purview communication compliance policy that will detect inappropriate images in Yammer conversations.
What should you do first?
Answer: B
NEW QUESTION 62
HOTSPOT - (Topic 1)
You have a Microsoft 365 subscription that contains the users shown in the following table.
You create the data loss prevention (DLP) policies shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select. No.
NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
NEW QUESTION 66
DRAG DROP - (Topic 1)
Your company has two departments named department1 and department2 and a Microsoft 365 E5 subscription.
You need to prevent communication between the users in department1 and the users in department.
How should you complete the PowerShell script? To answer, drag the appropriate values to the correct targets. Each value may be used once, more than once, or
not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
NEW QUESTION 70
HOTSPOT - (Topic 1)
You have a Microsoft 365 E5 subscription that contains a user named User1 and the groups shown in the following table.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
NEW QUESTION 73
- (Topic 1)
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the
stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You implement Microsoft 365 Endpoint data loss prevention (Endpoint DLP).
You have computers that run Windows 10 and have Microsoft 365 Apps installed. The computers are joined to Azure Active Directory (Azure AD).
You need to ensure that Endpoint DLP policies can protect content on the computers. Solution: You deploy the Endpoint DLP configuration package to the
computers. Does this meet the goal?
A. Yes
B. No
Answer: A
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-getting-started?view=o365-worldwide
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-endpoints?view=o365-worldwide
NEW QUESTION 78
- (Topic 1)
You have a Microsoft 365 subscription.
You have a team named Team! in Microsoft Teams. You plan to place all the content in Team1 on hold.
You need to identify which mailbox and which Microsoft SharePoint site collection are
associated to Team1.
Which cmdlet should you use?
A. Get-UnifiedGroup
B. Get-MalUser
C. Get-TeamChannel
D. Get-Team
Answer: D
NEW QUESTION 79
- (Topic 1)
You have a Microsoft 365 E5 subscription that contains a user named User1 and a Microsoft SharePoint Online site named Site 1. You create the alert policy
shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
How many alerts will be generated in response to the file uploads?
A. 1
B. 2
C. 3
D. 4
E. 5
Answer: C
NEW QUESTION 84
HOTSPOT - (Topic 1)
You enable archive mailboxes for all the users at your company. The Default MRM Policy is shown in the MRM exhibit.
A Microsoft 365 retention label policy is shown in the Label Policy exhibit.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
NEW QUESTION 87
- (Topic 1)
You have a Microsoft 365 tenant that has devices onboarded to Microsoft Defender for Endpoint as shown in the following table.
You plan to start using Microsoft 365 Endpoint data loss protection (Endpoint DLP). Which devices support Endpoint DLP?
A. Device5 only
B. Device2 only
C. Device 1, Device2, Device3, Device4, and Device5
D. Device3 and Device4 only
E. Device1 and Device2 only
Answer: E
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-learn-about?view=o365-worldwide
NEW QUESTION 90
HOTSPOT - (Topic 1)
You have a Microsoft 365 E5 subscription that contains a security group named Group1 and the users shown in the following table.
You assign the Compliance Manager roles to the users as shown in the following table.
You add two assessments to Compliance Manager as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
NEW QUESTION 92
HOTSPOT - (Topic 1)
You have a data loss prevention (DLP) policy that has the advanced DLP rules shown in the following table.
You need to identify which rules will apply when content matches multiple advanced DLP
rules.
Which rules should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
Graphical user interface, text Description automatically generated
NEW QUESTION 96
HOTSPOT - (Topic 1)
You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.
You need to onboard the devices to Microsoft Purview. The solution must ensure that you can apply Endpoint data loss prevention (Endpoint DLP) policies to the
devices. What can you use to onboard each device? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
NEW QUESTION 97
- (Topic 1)
You have a Microsoft 365 E5 subscription. You need to create a subject rights request What can be configured as a search location?
Answer: B
You need to manage the status of Alert2. To which status can you change Alert2?
Answer: E
A. Content contains
B. Content is shared from Microsoft 365
C. Document size equals or is greater than
D. Attachment's file extension is
E. Document property is
Answer: AB
Answer: C
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/classifier-get-started-with?view=o365-worldwide
A. Yes
B. No
Answer: B
Explanation:
Alerts must be sent to the Microsoft Teams site of the affected department. A Microsoft Power Automate playbook should be used.
Reference:
https://docs.microsoft.com/en-us/cloud-app-security/content-inspection-built-in https://docs.microsoft.com/en-us/cloud-app-security/flow-integration
A. Mastered
B. Not Mastered
Answer: A
Explanation:
A. a retention policy
B. an auto-apply label policy
C. a sensitive info type
D. a retention label
E. a sensitivity label
F. a publishing label policy
Answer: BD
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/apply-retention-labels-automatically?view=o365Worldwide
A. Mastered
B. Not Mastered
Answer: A
Explanation:
A. Mastered
B. Not Mastered
Answer: A
Explanation:
A. Mastered
B. Not Mastered
Answer: A
Explanation:
A. Mastered
B. Not Mastered
Answer: A
Explanation:
A. Yes
B. No
Answer: A
A. Schedule EdmUploadAgent.exe to hash and upload a data file that contains employee information.
B. Create a sensitive info type rule package that contains the EDM classification.
C. Define the sensitive information database schema in the XML format.
D. Create a sensitive info type rule package that contains regular expressions.
E. Define the sensitive information database schema in the CSV format.
Answer: ABC
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/create-custom-sensitive-information-types-withexact-data-match-based-
classification?view=o365-worldwide
A. Mastered
B. Not Mastered
Answer: A
Explanation:
To which devices can you apply Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings?
Answer: C
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-getting-started?view=o365-worldwide
Answer: D
A. Mastered
B. Not Mastered
Answer: A
Explanation:
A. Keywords
B. Content search query
C. Sensitive info type
D. Sensitive label
Answer: A
A. an activity policy
B. a session policy
C. a Cloud Discovery
D. a file policy
Answer: D
Answer: A
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/classifier-get-started-with?view=o365-worldwide
A. Mastered
B. Not Mastered
Answer: A
Explanation:
A. Yes
B. NO
Answer: A
A. Mastered
B. Not Mastered
Answer: A
Explanation:
A. a trainable classifier
B. a keyword dictionary OC.
C. a function
D. an exact data match (EDM) classifier
Answer: A
Answer: AB
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/classifier-learn- about?view=o365-worldwide
https://docs.microsoft.com/en-us/microsoft-365/compliance/apply-sensitivity-label-automatically?view=o365-worldwide
A. Deploy a Microsoft 36S Endpoint data loss prevention (Endpoint DLP) configuration package to the computers.
B. Configure hybrid Azure AD join for all the computers.
C. Configure the Microsoft Intune device enrollment settings.
Answer: BE
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-getting-started?view=o365-worldwide
Answer: C
Which users can update the title of Assessment1, and which users can add User5 to the Compliance Manager Readers role group? To answer, select the
appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
A. Yes
B. No
Answer: A
Answer: BD
The start of the retention period is based on when items are created. The current date is January 01, 2021.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
A. Mastered
B. Not Mastered
Answer: A
Explanation:
A. Yes
B. No
Answer: B
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-getting-started?view=o365-worldwide
Answer: D
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/add-your-organization-brand-to-encryptedmessages?view=o365-worldwide
Answer: B
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/apply-retention-labels-automatically?view=o365-worldwide
A. Mastered
B. Not Mastered
Answer: A
Explanation:
A. Mastered
B. Not Mastered
Answer: A
Explanation:
A. Mastered
B. Not Mastered
Answer: A
Explanation:
A. Mastered
B. Not Mastered
Answer: A
Explanation:
* SC-400 Most Realistic Questions that Guarantee you a Pass on Your FirstTry
* SC-400 Practice Test Questions in Multiple Choice Formats and Updatesfor 1 Year