Skip Navigation Links
 

Microsoft - SC-401: Administering Information Security in Microsoft 365

Sample Questions

Question: 313
Measured Skill: Implement data loss prevention and retention (30–35%)

You have a Microsoft 365 E5 subscription.

A DLP policy named DLP-Fin is scoped to Exchange, SharePoint, OneDrive, and Teams and contains three rules:
  • Rule1, priority 0, audits content containing one or more instances of a routing number sensitive info type.
  • Rule2, priority 1, blocks external sharing of content containing 10 or more instances of the same sensitive info type and allows user overrides.
  • Rule3, priority 2, blocks external sharing with no override for content that carries the Highly Confidential label.
A user externally shares a labeled document containing 40 routing numbers and receives an override prompt. The security team states that no override must be offered.

You need to ensure the no-override block applies.

What should you do?

ARaise the priority of Rule3 above Rule2.
B Delete Rule1.
C Increase the instance count in Rule2 to 50.
D Move Rule3 to a separate policy with lower policy priority.

Correct answer: A

Explanation:

The document matches both Rule2 and Rule3:

  • Rule2 matches because the document contains 40 routing numbers (more than the threshold of 10) and allows user overrides.
  • Rule3 matches because the document has the Highly Confidential sensitivity label and is intended to block sharing without override.

In Microsoft Purview DLP, when multiple rules can apply, rule priority determines which rule is evaluated first within the policy. The current configuration places Rule2 (priority 1) above Rule3 (priority 2), which is why the user receives the override prompt. To ensure the stricter action is enforced, the Highly Confidential rule must have a higher priority (lower priority number) than the routing-number rule. Microsoft documents that DLP rules are processed in priority order, with lower numbers indicating higher priority.

References: Data Loss Prevention policy reference



Question: 314
Measured Skill: Implement data loss prevention and retention (30–35%)

You have a Microsoft 365 E5 subscription.

The finance team emails workbooks containing a small number of legitimate account numbers to an approved external auditor. A DLP policy blocks messages containing three or more instances of a custom account number sensitive info type. The custom sensitive info type uses a regular expression with no supporting evidence, and it also matches unrelated 10-digit purchase order numbers in the same workbooks.

You need to reduce false positives without excluding the auditor domain and without changing the instance threshold.

What should you do?

AEnable simulation mode on the DLP policy.
B Change the rule condition to recipient domain is.
C Convert the custom sensitive info type to a keyword dictionary.
D Add a supporting element with a proximity window to the custom sensitive info type and require a higher confidence level in the rule.

Correct answer: D

Explanation:

We shoulkd add a supporting element with a proximity window to the custom sensitive info type and require a higher confidence level in the rule.

The false positives occur because the custom sensitive information type relies solely on a regular expression that matches any 10-digit number, including legitimate purchase order numbers. By adding supporting evidence (for example, keywords such as "Account Number", "Acct", "Bank Account") within a defined proximity window, Microsoft Purview can distinguish real account numbers from unrelated numeric strings. Requiring a higher confidence level ensures that only matches containing both the regex pattern and the supporting evidence trigger the DLP rule. This is a recommended approach for reducing false positives in custom sensitive information types.

Reference: Create custom sensitive information types



Question: 315
Measured Skill: Implement information protection (30–35%)

You have a Microsoft 365 E5 subscription.

An auditor must be able to view the names and locations of all files that contain sensitive info types, but must not be able to open or read the file contents.

You need to assign permissions that follow the principle of least privilege.

To which role should you add the auditor?

AInformation Protection Admin
B Content Explorer Content Viewer
C Content Explorer List Viewer
D Compliance Data Administrator

Correct answer: C

Explanation:

The requirement is to let the auditor see the file names and locations of items containing sensitive information, but not view the file contents.

Microsoft Purview provides two separate Content Explorer permission levels:

  • Content Explorer List Viewer — allows the user to see each item and its location in the list view.
  • Content Explorer Content Viewer — allows the user to view the contents of each item.

Reference: Get started with Content Explorer



Question: 316
Measured Skill: Manage risks, alerts, and activities (30–35%)

You have a Microsoft 365 E5 subscription.

A document previously labeled Confidential now carries the General label. You must identify which user changed the label, when the change occurred, and the justification text that was supplied.

You need to obtain this information.

What should you use?

AContent explorer
B Activity explorer
C The DLP alerts dashboard
D Records management disposition

Correct answer: B

Explanation:

The requirement is to identify:

  • Which user changed the sensitivity label
  • When the change occurred
  • The justification text supplied when the label was downgraded

Microsoft Purview Activity explorer records Sensitivity label changed events and captures details such as the user, timestamp, old and new labels, and the justification text provided during a label downgrade.

Reference: Labeling activities available in Activity explorer



Question: 317
Measured Skill: Manage risks, alerts, and activities (30–35%)

You have a Microsoft 365 E5 subscription.

You plan to create an insider risk management policy that uses the Data theft by departing users template. After creating the policy, you observe that no alerts are generated even though several departing employees downloaded large volumes of files.

You need to ensure the policy generates alerts.

What should you configure?

AA Microsoft 365 HR connector that imports resignation and termination dates
B A priority user group that contains all departing employees
C Forensic evidence capture for the affected devices
D A Microsoft Defender for Cloud Apps file policy

Correct answer: A

Explanation:

We should configure a Microsoft 365 HR connector that imports resignation and termination dates

The Data theft by departing users insider risk management template is specifically designed to detect potentially risky activities performed by users who are identified as leaving the organization. To determine who is a departing employee, Insider Risk Management relies on HR data, such as resignation or termination dates, imported through a Microsoft 365 HR connector.

Without HR signals identifying users as departing employees, the policy doesn't know which users should be monitored under the departing-user scenario, so alerts may not be generated even when large-scale file downloads occur.

Reference: Create and manage Insider Risk Management policies





 
Tags: exam, examcollection, exam simulation, exam questions, questions & answers, training course, study guide, vce, braindumps, practice test
 
 

© Copyright 2014 - 2026 by cert2brain.com