Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Administering Information Security in Microsoft 365 Question and Answers

Administering Information Security in Microsoft 365

Last Update Jul 25, 2026
Total Questions : 223

We are offering FREE SC-401 Microsoft exam questions. All you do is to just go and sign up. Give your details, prepare SC-401 free exam questions and then go for complete pool of Administering Information Security in Microsoft 365 test questions that will help you more.

SC-401 pdf

SC-401 PDF

$40.25  $114.99
SC-401 Engine

SC-401 Testing Engine

$47.25  $134.99
SC-401 PDF + Engine

SC-401 PDF + Testing Engine

$61.25  $174.99
Questions 1

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. Site1 contains the files shown in the following table.

In the Microsoft Purview portal, you create a content search named Conlent1 and configure the search conditions as shown in the following exhibit.

Which files will be returned by Content1?

Options:

A.  

File2.docx only

B.  

File3.docx only

C.  

File1.docx and File2.docx only

D.  

File1 .docx and File3.docx only

E.  

File1 .docx, File2.docx, and File3.docx

Discussion 0
Questions 2

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You recently discovered that the developers at your company emailed Azure Storage Account keys in plain text to third parties.

You need to ensure that when Azure Storage Account keys are emailed, the emails are encrypted.

Solution: You configure a mail flow rule that matches a sensitive info type.

Does this meet the goal?

Options:

A.  

Yes

B.  

No

Discussion 0
Questions 3

You have a Microsoft 365 E5 tenant that contains a sensitivity label named label1.

You plan to enable co-authoring for encrypted files.

You need to ensure that files that have label1 applied support co-authoring.

Which two settings should you modify? To answer, select the settings in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 4

You create a sensitivity label as shown in the Sensitivity Label exhibit. (Click the Sensitivity Label tab.)

You create an auto-labeling policy as shown in the Auto Labeling Policy exhibit. (Click the Auto Labeling Policy tab.)

A user sends the following email:

Both attachments contain lists of IP addresses.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 5

You have a Microsoft 365 E5 subscription.

You create a data loss prevention (DLP) policy and select.

Use Notifications to inform your users and help educate them on the proper use of sensitive info.

Which apps will show the policy tip?

Options:

A.  

Outlook on the web only

B.  

Outlook Win32 only

C.  

Outlook for iOS and Android only

D.  

Outlook on the web and Outlook Win32 only

E.  

Outlook Win32 and Outlook for iOS and Android only

F.  

Outlook on the web. Outlook Win32, and Outlook for iOS and Android

Discussion 0
Questions 6

You use project codes that have a format of three alphabetical characters that represent the project type, followed by three digits, for example Abe 123.

You need to create a new sensitive info type for the project codes.

How should you configure the regular expression to detect the content? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 7

You need to meet the retention requirement for the users ' Microsoft 365 data.

What is the minimum number of retention policies required to achieve the goal?

Options:

A.  

1

B.  

2

C.  

3

D.  

4

E.  

6

Discussion 0
Questions 8

HOTSPOT

You need to meet the technical requirements for the confidential documents.

What should you create first, and what should you use for the detection method? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 9

HOTSPOT

You are reviewing policies for the SharePoint Online environment.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 10

You need to meet the technical requirements for the Site1 documents.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Discussion 0
Questions 11

You have a Microsoft 365 E5 subscription that uses Microsoft Purview.

You need to deploy a compliance solution that will detect the accidental oversharing of information outside of an organization.

The solution must minimize administrative effort.

What should you use? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 12

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.

You plan to deploy a Defender for Cloud Apps file policy that will be triggered when the following conditions are met:

● A file is shared externally.

● A file is labeled as internal only.

Which filter should you use for each condition? To answer, drag the appropriate filters to the correct conditions. Each filter may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE : Each correct selection is worth one point.

Options:

Discussion 0
Questions 13

You have a Microsoft 365 ES subscription that uses Microsoft Teams and contains the users shown in the following table.

You have the retention policies shown in the following table.

The users perform the actions shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point

Options:

Discussion 0
Questions 14

You have a Microsoft J65 E5 subscription that contains a user named User1.

All users are assigned Microsoft 365 Copilot licenses.

You deploy Microsoft Purview Data Security Posture Management for Al (DSPM for Al).

You need to ensure that User1 can analyze prompts and responses for Al interaction events. The solution must follow the principle of least privilege.

To which two role groups should you add User1? Each correct answer presents part of the solution.

NOTE; Each correct selection is worth one point.

Options:

A.  

Information Protection Analysts

B.  

Security Reader

C.  

Content Explorer Content Viewer

D.  

Insider Risk Management Investigators

E.  

Content Explorer list Viewer

Discussion 0
Questions 15

You have a Microsoft 365 tenant.

You have a database that stores customer details. Each customer has a unique 13-digit identifier that consists of a fixed pattern of numbers and letters.

You need to implement a data loss prevention (DLP) solution that meets the following requirements:

● Email messages that contain a single customer identifier can be sent outside your company.

● Email messages that contain two or more customer identifiers must be approved by the company ' s data privacy team.

Which two components should you include in the solution? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.  

a sensitivity label

B.  

a sensitive information type

C.  

a DLP policy

D.  

a retention label

E.  

a mail flow rule

Discussion 0
Questions 16

HOTSPOT

How many files in Site2 can User1 and User2 access after you turn on DLPpolicy1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 17

You need to meet the technical requirements for the creation of the sensitivity labels.

To which user or users must you assign the Sensitivity Label Administrator role?

Options:

A.  

Admin1 only

B.  

Admin1 and Admin4 only

C.  

Admin1 and Admin5 only

D.  

Admin1, Admin2, and Admin3 only

E.  

Admin1, Admin2, Admin4, and Admin5 only

Discussion 0
Questions 18

You create a data loss prevention (DIP) policy that meets the following requirements:

• Prevents guest users from accessing a sensitive document shared during a Microsoft Teams chat

• Prevents guest users from accessing a sensitive document stored in a Microsoft Team? channel

Which location should you select for each requirement? To answer, select the appropriate options in the answer area NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 19

You have a Microsoft 365 subscription.

Users have devices that run Windows 11.

You plan to create a Microsoft Purview insider risk management policy that will detect when a user performs the following actions:

● Deletes files that contain a sensitive information type (SIT) from their device

● Copies files that contain a SIT to a USB drive

● Prints files that contain a SIT

You need to prepare the environment to support the policy.

What should you do?

Options:

A.  

Configure the physical badging connector.

B.  

Configure the HR data connector.

C.  

Create a Microsoft Purview communication compliance policy.

D.  

Onboard the devices to Microsoft Purview.

Discussion 0
Questions 20

You have a Microsoft OneDrive folder that contains the files shown in the following table.

In Microsoft Defender for Cloud Apps, you create a file policy to automatically apply a classification. What is the effect of applying the policy?

Options:

A.  

The policy will apply to only the .docx and .txt files. The policy will classify the files within 24 hours.

B.  

The policy will apply to only the docx and txt files. The policy will classify the files immediately.

C.  

The policy will apply to all the files. The policy will classify only 100 files daily.

D.  

The policy will apply to only the .docx files. The policy will classify only 100 files daily.

Discussion 0
Questions 21

You have a Microsoft 365 subscription.

You create and run a content search from the Microsoft Purview portal.

You need to download the results of the content search.

What should you obtain first?

Options:

A.  

a certificate

B.  

a password

C.  

a pin

D.  

an export key

Discussion 0
Questions 22

You have a Microsoft 365 E5 tenant that contains a user named User1. User1 is assigned the Compliance Administrator role. User1 cannot view the regular expression in the IP Address sensitive info type. You need to ensure that User! can view the regular expression. What should you do?

Options:

A.  

Assign Used to the Reviewer role group

B.  

Create a copy of the IP Address sensitive info type and instruct User1 to edit the copy.

C.  

Instruct User1 to use the Test function on the sensitive info type.

D.  

Assign User1 the Global Reader role.

Discussion 0
Questions 23

You have a Microsoft 365 subscription that has a retention label named Retention1. The subscription contains the files shown in the following table.

You create an auto-labeling policy named Policy1 that will automatically apply Retention1 as shown in the Auto-labeling policy

Exhibit. (Click the Auto-labeling policy tab.)

You configure Policy1 to apply Retention1 as shown in the Locations exhibit. (Click the Locations tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 24

You have a Microsoft SharePoint Online site named Site1 that has the users shown in the following table.

You create the retention labels shown in the following table.

You publish the retention labels to Site1.

On March 1,2023, you assign the retention labels to the files shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 25

DRAG DROP

You need to create a trainable classifier that can be used as a condition in an auto-apply retention label policy.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Discussion 0
Questions 26

You create a data loss prevention (DLP) policy. The Advanced DLP rules page is shown in the Rules exhibit. (Click the Rules tab.)

The Review your settings page is shown in the Review exhibit. (Click the Review tab.)

You need to review the potential impact of enabling the policy without applying the actions. What should you do?

Options:

A.  

Edit the policy, remove all the actions in DLP rule 1, and select I ' d like to test it out first

B.  

Edit the policy, remove the Restrict access to the content and Send incident report to Administrator actions, and then select Yes, turn it on right away

C.  

Edit the policy, remove all the actions in DLP rule 1, and select Yes, turn it on right away

D.  

Edit the policy, and then select I ' d like to test it out first

Discussion 0
Questions 27

You have a Microsoft 365 ES subscription.

A security manager receives an email message every time a data loss prevention (DIP) policy match occurs. You need to limit alert notifications to actionable DLP events. What should you do?

Options:

A.  

From the Microsoft Defender portal, apply a filter to the alerts.

B.  

From the Microsoft Purview portal, modify the Policy Tips settings of a DLP policy.

C.  

From the Microsoft Purview portal, modify the matched activities threshold of an alert policy.

D.  

From the Microsoft Purview portal, modify the User overrides settings of a DLP policy.

Discussion 0
Questions 28

You have a data loss prevention (DIP) policy that applies to the Devices location. The policy protects documents that contain United States passport numbers

Users report that they cannot upload documents to a travel management website because of the pokey.

You need to ensure that the users can upload the documents to the travel management website. The solution must prevent the protected content from being uploaded to other locations.

Which Microsoft 365 Endpoint data loss prevention (Endpoint DIP) setting should you configure?

Options:

A.  

Service domains

B.  

Unallowed browsers

C.  

File path exclusions

D.  

Unallowed apps

Discussion 0
Questions 29

Your company has offices in multiple countries.

The company has a Microsoft 365 E5 subscription that uses Microsoft Purview insider risk management.

You plan to perform the following actions:

● In a new country, open an office named Office1.

● Create a new user named User1.

● Deploy insider risk management to Office1.

● Add User1 to the Insider Risk Management Admins role group.

You need to ensure that User1 can perform insider risk management tasks for only the users and the devices in Office1.

What should you create first?

Options:

A.  

a dynamic device group

B.  

a dynamic user group

C.  

an administrative unit

D.  

a management group

Discussion 0
Questions 30

You have a Microsoft 365 E5 subscription that contains a trainable classifier named Trainable1.

You plan to create the items shown in the following table.

Which items can use Trainable 1?

Options:

A.  

Label2 only

B.  

Label1 and Label2 only

C.  

Label1 and Policy1 only

D.  

Label2, Policy1, and DLP1 only

E.  

Label1, Label2, Policy1, and DLP1

Discussion 0
Questions 31

You have a Microsoft 365 E5 subscription that contains the adaptive scopes shown in the following table.

You create the retention policies shown in the following table.

Which retention policies support a preservation lock?

Options:

A.  

RPolicy2only

B.  

RPolicy3on1y

C.  

RPolicy1 and RPolicy2 only

D.  

RPolicy1 and RPolicy3 only

E.  

RPolicy1, RPolicy2, and RPolicy3

Discussion 0
Questions 32

HOTSPOT

You have a Microsoft 365 E5 subscription that uses Microsoft Purview and just-in-time (JIT) protection. The subscription contains the users shown in the following table.

The subscription contains the devices shown in the following table.

The devices contain the files shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE : Each correct selection is worth one point.

Options:

Discussion 0
Questions 33

You have a Microsoft 365 sensitivity label that is published to all the users in your Microsoft Entra tenant as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Options:

Discussion 0
Questions 34

At the end of a project, you upload project documents to a Microsoft SharePoint Online library that contains many files. The following is a sample of the project document file names:

• aei_AA989.docx

• bd_WS098.docx

• cei_DF112.docx

• ebc_QQ454.docx

• ecc_BB565.docx

All documents that use this naming format must be labeled as Project Documents:

You need to create an auto-apply retention label policy.

What should you use to identify the files?

Options:

A.  

A retention label

B.  

A trainable classifier

C.  

A sensitive info type

Discussion 0
Questions 35

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 tenant and 500 computers that run Windows 11. The computers are onboarded to Microsoft Purview.

You discover that a third-party application named Tailspin_scanner.exe accessed protected sensitive information on multiple computers. Tailspin_scanner.exe is installed locally on the computers.

You need to block Tailspin_scanner.exe from accessing sensitive documents without preventing the application from accessing other documents.

Solution: From the Microsoft Defender for Cloud Apps, you mark the application as Unsanctioned.

Does this meet the goal?

Options:

A.  

Yes

B.  

No

Discussion 0
Questions 36

You have a data loss prevention (DLP) policy configured for endpoints as shown in the following exhibit.

From a computer named Computer1, a user can sometimes upload files to cloud services and sometimes cannot. Other users experience the same issue.

What are two possible causes of the issue? Each correct answer presents a complete solution.

NOTE : Each correct selection is worth one point.

Options:

A.  

The unallowed browsers in the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings are NOT configured.

B.  

There are file path exclusions in the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings.

C.  

The Access by restricted apps action is set to Audit only.

D.  

The Copy to clipboard action is set to Audit only.

E.  

The computers are NOT onboarded to Microsoft Purview.

Discussion 0
Questions 37

You have a Microsoft 36S ES subscription that contains the devices shown in the following table.

You plan to implement inside ' risk management and capture forensic evidence

Which devices support the collection of forensic evidence, and what should you do lo prepare each supported device? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0
Questions 38

You have a Microsoft 365 E5 subscription.

You need to review a Microsoft 365 Copilot usage report.

From where should you review the report?

Options:

A.  

Information Protection in the Microsoft Purview portal

B.  

the Microsoft 365 admin center

C.  

DSPM for Al in the Microsoft Purview portal

D.  

the Microsoft Defender portal

Discussion 0
Questions 39

You are implementing Microsoft Purview Advanced Message Encryption for a Microsoft 365 tenant named contoso.com You need to meet the following requirements:

• All email to a domain named (abrikam.com must be encrypted automatically.

• Encrypted emails must expire seven days after they are sent

What should you configure for each requirement? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Discussion 0