Skip Navigation Links
 

Microsoft - SC-401: Administering Information Security in Microsoft 365

Sample Questions

Question: 288
Measured Skill: Manage risks, alerts, and activities (30–35%)

You have a Microsoft 365 E5 subscription that contains a group named Group1.

You need to ensure that the members of Group1 can view and export alerts and cases in Microsoft Purview insider risk management. The solution must follow the principle of least privilege.

To which role group should you add to Group1?

AInsider Risk Management Analysts
B Insider Risk Management Admins
C Insider Risk Management Approvers
D Insider Risk Management Investigators

Correct answer: D

Explanation:

Investigators are specifically intended to work with Insider Risk cases and alerts and perform investigation activities, including exports, while avoiding unnecessary administrative permissions.

Choose from these role group options and solution actions when working with Insider Risk Management:

Reference: Assign permissions in Insider Risk Management



Question: 289
Measured Skill: Implement data loss prevention and retention (30–35%)

Your organization manages highly sensitive legal, financial, and regulatory information. You have been tasked with implementing Microsoft Purview Data Loss Prevention (DLP) to help prevent the accidental or unauthorized disclosure of sensitive data.

Before creating and deploying DLP policies, you need to determine the appropriate design approach.

What should be the first step in designing an effective DLP strategy?

AEnable auditing for all users across Microsoft 365
B Analyze and classify the types of sensitive information handled by the organization
C Block all external sharing in Microsoft 365 workloads
D Configure retention policies for all corporate data

Correct answer: B

Explanation:

An effective DLP implementation begins with identifying and understanding the sensitive information that requires protection. This includes determining what types of data exist within the organization, where the data is stored, how it is used, and the associated regulatory or business requirements. Once sensitive data has been identified and classified, appropriate DLP policies, conditions, and actions can be designed and deployed.

Reference: Design a data loss prevention policy



Question: 290
Measured Skill: Implement data loss prevention and retention (30–35%)

Your organization uses Microsoft Purview to protect sensitive information and enforce compliance requirements.

You need to ensure that designated compliance officers can create, modify, and manage Data Loss Prevention (DLP) policies. The solution must prevent users from having unnecessary administrative permissions and follow the principle of least privilege.

Which role should you assign to the compliance officers?

AGlobal Administrator
B Compliance Administrator
C Security Reader
D Exchange Administrator

Correct answer: B

Explanation:

The Compliance Administrator role is designed for users who need to manage Microsoft Purview compliance features, including Data Loss Prevention (DLP) policies. This role provides the necessary permissions to create, modify, and manage DLP policies without granting broader tenant-wide administrative privileges.

  • Global Administrator grants full administrative access across the tenant and exceeds the required permissions.
  • Security Reader provides read-only access and cannot create or modify DLP policies.
  • Exchange Administrator manages Exchange Online settings but does not provide full DLP policy management capabilities across Microsoft Purview.

Reference: Create and deploy data loss prevention policies



Question: 291
Measured Skill: Manage risks, alerts, and activities (30–35%)

You have a Microsoft 365 E5 subscription that contains two Microsoft SharePoint Online sites named Site1 and Site2. Site1 contains the files shown in the following table.



Site2 contains the files shown in the following table.



From the Microsoft Purview portal, you create the content searches shown in the following table.



For each of the following statements, select Yes if the statement is true. Otherwise, select No.

(NOTE: Each correct selection is worth one point.)

www.cert2brain.com

AThe results of Search1 include File2.docx: Yes
The results of Search2 include File1.docx, File2.docx, FileA.pptx, and FileB.docx: Yes
The results of Search3 include FileB.docx: Yes
B The results of Search1 include File2.docx: Yes
The results of Search2 include File1.docx, File2.docx, FileA.pptx, and FileB.docx: Yes
The results of Search3 include FileB.docx: No
C The results of Search1 include File2.docx: No
The results of Search2 include File1.docx, File2.docx, FileA.pptx, and FileB.docx: Yes
The results of Search3 include FileB.docx: No
D The results of Search1 include File2.docx: No
The results of Search2 include File1.docx, File2.docx, FileA.pptx, and FileB.docx: Yes
The results of Search3 include FileB.docx: Yes
E The results of Search1 include File2.docx: No
The results of Search2 include File1.docx, File2.docx, FileA.pptx, and FileB.docx: No
The results of Search3 include FileB.docx: Yes
F The results of Search1 include File2.docx: No
The results of Search2 include File1.docx, File2.docx, FileA.pptx, and FileB.docx: No
The results of Search3 include FileB.docx: No

Correct answer: E

Explanation:

The results of Search1 include File2.docx: No
Search1 is limited to Site1 and searches for Author:User1 and FileExtension:docx. In Site1, File1.docx was authored by User1, while File2.docx was authored by User2. Therefore, File2.docx is not returned.

The results of Search2 include File1.docx, File2.docx, FileA.pptx, and FileB.docx: No
Search2 searches Site1 and Site2 for Author:User* AND FileExtension:docx. The wildcard matches both User1 and User2, but the file extension condition restricts results to .docx files. Therefore, File1.docx, File2.docx, and FileB.docx are returned. FileA.pptx is excluded because it is a PowerPoint file.

The results of Search3 include FileB.docx: Yes
Search3 is limited to Site2 and searches for Author:USER1. Keyword searches are not case-sensitive, so USER1 matches User1. In Site2, FileB.docx was authored by User1, so it is returned.

Reference: Get started with Content search



Question: 292
Measured Skill: Implement data loss prevention and retention (30–35%)

You have a Microsoft 365 subscription that uses Microsoft Purview data loss prevention (DLP) policies. The subscription contains the devices shown in the following table.



You create a DLP policy that has the following configurations:
  • Name: Policy1
  • Locations: Devices
  • Action (enforcement): Block
  • Adaptive protection Enabled
  • Targets elevated risk users
  • Users and groups: All users and groups
  • User notification: Notify users (optional)
  • Targeted URLs: Unapproved AI websites
  • Sensitive information types (SITs): Confidential
You deploy Policy1 and set the mode to enforcement.

What will occur when a user on each device attempts to paste text to a Microsoft Copilot website?

(To answer, select the options in the answer area. NOTE: Each correct selection is worth one point.)

www.cert2brain.com

ADevice1: A warning will be sent by using an override.
Device2: There will be no action.
B Device1: A warning will be sent by using an override.
Device2: The action will be blocked.
C Device1: The action will be blocked.
Device2: There will be no action.
D Device1: The action will be blocked.
Device2: A warning will be sent by using an override.
E Device1: There will be no action.
Device2: The action will be blocked.
F Device1: There will be no action.
Device2: A warning will be sent by using an override.

Correct answer: C

Explanation:

Monitoring and enforcing DLP actions for generative AI websites requires devices to be onboarded to Microsoft Purview/Endpoint DLP.

When a user attempts to paste confidential information into a supported AI website, the configured action is Block.

On Device1, the action will be blocked.

Because Device2 is not onboarded, Endpoint DLP policies cannot be enforced.

References:

Considerations for DSPM for AI to manage data security and compliance protections for AI interactions

Microsoft Purview data security and compliance protections for generative AI apps





 
Tags: exam, examcollection, exam simulation, exam questions, questions & answers, training course, study guide, vce, braindumps, practice test
 
 

© Copyright 2014 - 2026 by cert2brain.com