Big Black Friday Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Microsoft Information Protection Administrator Question and Answers

Microsoft Information Protection Administrator

Last Update Nov 30, 2025
Total Questions : 334

We are offering FREE SC-400 Microsoft exam questions. All you do is to just go and sign up. Give your details, prepare SC-400 free exam questions and then go for complete pool of Microsoft Information Protection Administrator test questions that will help you more.

SC-400 pdf

SC-400 PDF

$40.25  $114.99
SC-400 Engine

SC-400 Testing Engine

$47.25  $134.99
SC-400 PDF + Engine

SC-400 PDF + Testing Engine

$61.25  $174.99
Questions 1

You have a Microsoft 365 E5 tenant that contains the users shown in the following table.

You have a retention policy that has the following configurations:

    Name: Policy1

    Retain items for a specific period: 5 years

    Locations to apply the policy: Exchange email, SharePoint sites

You place a Preservation Lock on Policy1.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE:Each correct selection is worth one point.

Options:

Discussion 0
Questions 2

You have a Microsoft 365 E5 subscription that uses Microsoft Purview.

You need to deploy a compliance solution that will detect the accidental oversharing of information outside of an organization. The solution must minimize administrative effort.

What should you use? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 3

You need to protect documents that contain credit card numbers from being opened by users outside your company. The solution must ensure that users at your company can open the documents.

What should you use?

Options:

A.  

a sensitivity label policy

B.  

a sensitivity label

C.  

a retention policy

D.  

a data loss prevention (DLP) policy

Discussion 0
Questions 4

You have a Microsoft 365 E5 tenant.

You create sensitivity labels as shown in the Sensitivity Labels exhibit.

The Confidential/External sensitivity label is configured to encrypt files and emails when applied to content.

The sensitivity labels are published as shown in the Published exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE:Each correct selection is worth one point.

Options:

Discussion 0
Questions 5

You have a Microsoft 365 ES subscription.

You need to create a Microsoft Defender for Cloud Apps policy that will detect data loss prevention (DLP) violations.

What should you create?

Options:

A.  

an activity policy

B.  

a session policy

C.  

a Cloud Discovery

D.  

a file policy

Discussion 0
Questions 6

You have a Microsoft 365 tenant that uses data loss prevention (DLP) to protect sensitive information.

You create a new custom sensitive info type that has the matching element shown in the following exhibit.

The supporting elements are configured as shown in the following exhibit.

The confidence level and character proximity are configured as shown in the following exhibit.

For each of the following statements, select Yes if statement is true. Otherwise, select No

NOTE:Each correct selection is worth one point.

Options:

Discussion 0
Questions 7

You need to implement a solution that meets the compliance requirements for the Windows 10 computers.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each coned selection is worth one point.

Options:

A.  

Deploy a Microsoft 36S Endpoint data loss prevention (Endpoint DLP) configuration package to the computers.

B.  

Configure hybrid Azure AD join for all the computers.

C.  

Configure the Microsoft Intune device enrollment settings.

D.  

Configure a compliance policy in Microsoft Intune.

E.  

auto in Microsoft Defender for Endpoint protection.

Discussion 0
Questions 8

You have a Microsoft 365 subscription.

You need to ensure that users can apply retention labels to individual documents in their Microsoft SharePoint libraries.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.  

From the Microsoft Purview compliance portal, create a label.

B.  

From Microsoft Defender for Cloud Apps, create a file policy.

C.  

From the Microsoft Purview compliance portal, publish a label.

D.  

From the SharePoint admin center, modify the Site Settings.

E.  

From the SharePoint admin center, modify the records management settings.

Discussion 0
Questions 9

Task 10

You plan to create a data loss prevention (DLP) policy that will apply to content containing the following keywords:

• Tailspin

• litware

• Falcon

You need to create a keyword list that can be used in the DLP policy. You do NOT need to create the DLP policy at this time.

Options:

Discussion 0
Questions 10

Task 1

You need to provide users with the ability to manually classify files that contain product information that are stored in SharePoint Online sites. The solution must meet the following requirements:

• The users must be able to apply a classification of Product1 to the files.

• Any authenticated user must be able to open files classified as Product1.

• files classified as Product1 must be encrypted.

Options:

Discussion 0
Questions 11

Task 6

You plan to implement Endpoint data loss prevention (Endpoint DLP) policies for computers that run Windows.

Users have an application named App1 that stores data locally in a folder named C:\app1\data.

You need to prevent the folder from being monitored by Endpoint DLP.

Options:

Discussion 0
Questions 12

Task 8

You need to retain Microsoft SharePoint files that contain the word Falcon for two years from the date they were created, and then delete them.

Options:

Discussion 0
Questions 13

You are reviewing policies for the SharePoint Online environment.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE:Each correct selection is worth one point.

Options:

Discussion 0
Questions 14

You need to meet the technical requirements for the creation of the sensitivity labels.

To which user or users must you grant the Sensitivity label administrator role?

Options:

A.  

Admin1, Admin2, Admin4, and Admin5 only

B.  

Admin1, Admin2, and Admin3 only

C.  

Admin1 only

D.  

Admin1 and Admin4 only

E.  

Admin1 and Admin5 only

Discussion 0
Questions 15

You need to meet the technical requirements for the Site3 documents.

What should you create?

Options:

A.  

a retention label policy and a retention label that uses an event

B.  

a sensitive info type that uses a dictionary and a sensitivity label

C.  

a sensitive info type that uses a regular expression and a sensitivity label

D.  

a retention policy that has Only delete items when they reach a certain age selected

Discussion 0
Questions 16

You need to meet the technical requirements for the confidential documents.

What should you created first, and what should you use for the detection method? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 17

How many files in Site2 will be visible to User1 and User2 after you turn on DLPpolicy1? To answer, select the appropriate options in the answer area.

NOTE:Each correct selection is worth one point.

Options:

Discussion 0
Questions 18

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth is worth one point.

Options:

Discussion 0
Questions 19

You are evaluating the technical requirements for the DLP reports.

Which user can currently view the DLP reports?

Options:

A.  

Admin4

B.  

Admin1

C.  

Admin5

D.  

Admin2

E.  

Admin3

Discussion 0
Questions 20

You need to meet the technical requirements for the creation of the sensitivity labels. Which administrative users are currently missing the Sensitivity label administrator role?

Options:

A.  

Admin1 only

B.  

Admm1, Admin2, Admin4, and Admin5 only

C.  

Admin 1. Admin2, and Admin3 only

D.  

Admin 1 and Admin5 only

E.  

Admin 1 and Admin4 only

Discussion 0
Questions 21

You need to meet the technical requirements for the Site1 documents.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Discussion 0
Questions 22

You need to recommend a solution that meets the compliance requirements for viewing DLP tooltip

justifications.

What should you recommend?

Options:

A.  

Instruct the compliance department users to review the False positive and override report.

B.  

Configure a Microsoft Power Automate workflow to route DLP notification emails to the compliance

department.

C.  

Instruct the compliance department users to review the DLP incidents report.

D.  

Configure an Azure logic app to route DLP notification emails to the compliance department.

Discussion 0
Questions 23

You need to recommend a solution that meets the compliance requirements for Dropbox.

What should you recommend?

Options:

A.  

Create a DLP policy that applies to devices.

B.  

Create a file policy in Microsoft Defender for Cloud Apps that uses the built-in DLP inspection method.

C.  

Create a retention label that enforces the item deletion settings.

D.  

Edit an existing retention label that enforces the item deletion settings.

Discussion 0
Questions 24

You have a Microsoft 365 ES subscription.

You plan to create a custom trainable classifier by uploading 1,000 machine-generated files as seed content.

The files have sequential names and are uploaded in one-minute intervals as shown in the following table.

Which files were processed first and last when you created the custom trainable classifier? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 25

You have a Microsoft 365 E5 tenant that contains a user named User1.

You need to identify the type and number of holds placed on the mailbox of User1.

What should you do first?

Options:

A.  

From the Microsoft 365 compliance center, create an eDiscovery case.

B.  

From Exchange Online PowerShell. run the Gee-Mailbox cmdlet.

C.  

From the Microsoft 365 compliance center, run a content search.

D.  

From Exchange Online PowerShell. run the Get-HoldCompliancePolicy cmdlet.

Discussion 0
Questions 26

You have a Microsoft 365 subscription.

You have a user named Userl. Several users have full access to the mailbox of Userl.

Some email messages sent to User1 appear to have been read and deleted before the user viewed them.

When you search the audit log in the Microsoft Purview compliance portal to identify who signed in to the mailbox of User1, the results are blank.

You need to ensure that you can view future sign-ins to the mailbox of User1.

Solution: You run the Set-Mailbox –identity ‘’User1’’ –AuditEnabled $true command.

Does that meet the goal?

Options:

A.  

Yes

B.  

No

Discussion 0
Questions 27

You need to recommend a solution that meets the Data Loss Prevention requirements for the HR department.

Which three actions should you perform? Each correct answer presents part of the solution. (Choose three.)

NOTE: Each correct selection is worth one point.

Options:

A.  

Schedule EdmUploadAgent.exe to hash and upload a data file that contains employee information.

B.  

Create a sensitive info type rule package that contains the EDM classification.

C.  

Define the sensitive information database schema in the XML format.

D.  

Create a sensitive info type rule package that contains regular expressions.

E.  

Define the sensitive information database schema in the CSV format.

Discussion 0
Questions 28

You need to recommend a solution that meets the executive requirements. What should you recommend?

Options:

A.  

From the Microsoft 365 compliance center, create a retention policy.

B.  

From the Exchange admin center, enable archive mailboxes.

C.  

From the Microsoft 365 compliance center, create a retention label.

D.  

From the Microsoft 365 compliance center, create a DLP policy.

Discussion 0
Questions 29

You need to recommend a solution that meets the compliance requirements for protecting the documents in the Data shared folder. What should you recommend?

Options:

A.  

From the Microsoft 365 compliance center, configure a DLP policy.

B.  

From the Microsoft 365 compliance center, configure a Content Search query.

C.  

From the Microsoft 365 compliance center, configure an auto-labeling policy.

D.  

From Azure Information Protection, configure a content scan job.

Discussion 0
Questions 30

You need to recommend a solution to configuration the Microsoft 365 Records management settings by using the CSV file must meet the compliance requirements.

What should you recommend?

Options:

A.  

From the Microsoft 365 compliance center, import the CSV file to a file plan.

B.  

Use EdmUploadAgent.exe to upload a hash of the CSV to a datastore.

C.  

Use a PowerShell command that pipes the import csv cmdlet to the New-RetentionPolicy cmdlet.

D.  

Use a PowerShell command that pipes the import-csv cmdlet to the New-Label cmdlet.

Discussion 0
Questions 31

You need to recommend a solution that meets the sales requirements.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Discussion 0
Questions 32

You need to recommend an information governance solution that meets the HR requirements for handling employment applications and resumes.

What is the minimum number of information governance solution components that you should create? To answer, select the appropriate options in the answer area.

NOTE:Each correct selection is worth one point.

Options:

Discussion 0
Questions 33

You need to recommend a solution that meets the compliance requirements for protecting the documents in the Data shared folder.

What should you configure in the Microsoft Purview compliance portal?

Options:

A.  

a content scan job

B.  

a Content Search query

C.  

an auto-labeling policy

D.  

a DLP policy

Discussion 0
Questions 34

You need to recommend a solution that meets the compliance requirements for Dropbox.

What should you recommend?

Options:

A.  

Create a DLP policy that applies to Cloud App Security.

B.  

Edit an existing retention label that enforces the item deletion settings.

C.  

Create a retention label that enforces the item deletion settings.

D.  

Create a DLP policy that applies to devices.

Discussion 0
Questions 35

You need to implement a solution to encrypt email. The solution must meet the compliance requirements.

What should you create in the Exchange admin center and the Microsoft 36.S compliance center? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 36

You create a label that encrypts email data.

Users report that they cannot use the label in Outlook on the web to protect the email messages they send.

You need to ensure that the users can use the new label to protect their email.

What should you do?

Options:

A.  

Wait six hours and ask the users to try again.

B.  

Create a label policy.

C.  

Create a new sensitive information type.

D.  

Modify the priority order of label policies

Discussion 0
Questions 37

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

You need to prevent users in the finance department from sharing files with users in the research department. Which type of policy should you configure?

Options:

A.  

communication compliance

B.  

information barrier

C.  

Conditional Access

D.  

insider risk management

Discussion 0
Questions 38

You are creating a data loss prevention (DLP) policy that will apply to all available locations. You configure an advanced DLP rule in the policy. Which type of condition can you use in the rule?

Options:

A.  

Keywords

B.  

Content search query

C.  

Sensitive info type

D.  

Sensitive label

Discussion 0
Questions 39

You have a Microsoft 365 tenant that has data loss prevention (DLP) policies.

You need to review DLP policy matches for the tenant.

What should you use?

Options:

A.  

Content explorer

B.  

Activity explorer

C.  

Compliance Manager

D.  

records management events

Discussion 0
Questions 40

You have a Microsoft 365 subscription.

You create a retention label named Label! as shown in the following exhibit.

You publish Label1 to SharePoint sites.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 41

You have a Microsoft 365 tenant that has devices onboarded to Microsoft Defender for Endpoint as shown in the following table.

You plan to start using Microsoft 365 Endpoint data loss protection (Endpoint DLP).

Which devices support Endpoint DLP?

Options:

A.  

Device5 only

B.  

Device2 only

C.  

Device 1, Device2, Device3, Device4, and Device5

D.  

Device3 and Device4 only

E.  

Device1 and Device2 only

Discussion 0
Questions 42

You have a Microsoft 365 E5 subscription.

Your company has two departments named department1 and department2.

You configure an information barrier (IB) policy that prevents communication between the users in department1 and department2.

You discover that a user named User1 in department1 can still communicate with the users in department2. You validate that the policy works properly for all other users.

You need to ensure that User1 cannot communicate with the department2 users.

What should you modify?

Options:

A.  

the group assignments of User1

B.  

the user account attributes of User1

C.  

the IB policy

D.  

the IB segments

Discussion 0
Questions 43

You have a Microsoft 365 E5 subscription.

You have the data loss prevention (DLP) rule match shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 44

You have a Microsoft 365 E5 subscription that contains the resources shown in the following table.

You have a retention label configured as shown in the following exhibit.

You apply the label to the resources.

Which items can you delete?

Options:

A.  

Mail1 only

B.  

Filel.docx and File2.xlsx only

C.  

Mail1 and Filel.docx only

D.  

Mail1 and File2.xlsx only

E.  

Mail1, Filel.docx, and File2.xlsx

Discussion 0
Questions 45

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

You need to delegate the following tasks:

• Configure role group assignments for communication compliance.

• Update and view the status of communication compliance alerts.

Which users can perform each task? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 46

You create a retention label policy named Contoso_policy that contains the following labels.

    10 years then delete

    5 years then delete

    Do not retain

Contoso_Policy is applied to content In Microsoft Sharepoint Online sites.

After a couple of days, yon discover the following messages on the Properties page of the label policy.

* Statue Off (Error)

* It's taking longer than expected to deploy the policy

You need to reinitiate the policy.

How should you complete the command? To answer, select the appropriate options in the; answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 47

You have a Microsoft 365 E5 subscription that contains a user named User1.

You need to ensure that User1 can perform the following tasks:

• View the Privacy risk management Data profile page and subject rights request reports.

• Add approvers for subject rights requests.

The solution must follow the principle of least privilege.

To which role group should you add User1 for each task? To answer, drag the appropriate role groups to the correct tasks. Each role group may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 48

You have a Microsoft 365 E5 subscription. You need to create a subject rights request What can be configured as a search location?

Options:

A.  

Microsoft Exchange Online and Teams only

B.  

Microsoft Exchange Online, SharePoint Online, and Teams

C.  

Microsoft Exchange Online only

D.  

Microsoft Exchange Online and SharePoint Online only

E.  

Microsoft SharePoint Online only

Discussion 0
Questions 49

You have a Microsoft 365 E5 subscription.

You need to ensure that encrypted email messages sent to an external recipient can be revoked or will expire within seven days.

What should you configure first?

Options:

A.  

a custom branding template

B.  

a mail flow rule

C.  

a Conditional Access policy

D.  

a sensitivity label

Discussion 0
Questions 50

You have a Microsoft 365 subscription that has a retention label named Retention1. The subscription contains the files shown in the following table.

You create an auto-labeling policy named Policy! that will automatically apply Retention1 as shown in the Auto-labeling policy exhibit. (Click the Auto-labeling policy tab.)

You configure Policy1 to apply Retention1 as shown in the Locations exhibit. (Click the Locations tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0