Administering Information Security in Microsoft 365 Free Sample Questions

Covers data classification and sensitivity labels in Microsoft Purview, data loss prevention policies, and insider risk management, security alerts and protecting data used by AI services.

20 free sample questions183 in the full practice test Other version: SC-400(172)

Try simulator

SC-401 Sample Questions

  1. Question 1

    A pharmaceutical research company, BioGen Innovations, has implemented Microsoft Purview Insider Risk Management. They are concerned about potential data theft of clinical trial results. An analyst needs to capture video clips of on-screen activity on endpoints when approved high-risk users perform specific risky activities, such as copying files to USB devices. Which setting must be enabled to achieve this?

    Answer and explanation

    Correct answer: B

    Forensic evidence is the opt-in Insider Risk Management feature that captures video clips of user on-screen activity on devices. Captures happen either for specific activities (when a triggering event brings an approved user into scope and a policy indicator is detected) or for all activities. Users must be requested and approved (dual authorization), and devices must be onboarded to Microsoft Purview with the Microsoft Purview Client installed. Microsoft Defender for Endpoint integration is not required. Policy indicators and device indicators only define what's scored; they don't capture clips. Source: Microsoft Learn 'Learn about Insider Risk Management forensic evidence'.

  2. Question 2

    A global logistics firm, TransGlobal Freight, uses Microsoft 365 E5. It plans to deploy an Endpoint DLP policy that blocks printing of documents containing SWIFT codes on Windows 11 devices. What is required for the policy to be enforced on a user's device?

    Answer and explanation

    Correct answer: A

    Endpoint DLP (and insider risk management) require Windows 10/11 devices to be onboarded so they can send monitoring data and enforce policies. You can onboard them directly in the Microsoft Purview portal (Settings > Device onboarding), or they're already onboarded if they're in Microsoft Defender for Endpoint. The Information Protection client isn't required. Advanced classification is optional (it adds cloud-based classification), and a policy in simulation mode doesn't enforce blocks. Source: Microsoft Learn - Onboard Windows devices into Microsoft 365 overview.

  3. Question 3

    An engineering firm uses a custom trainable classifier named 'Project Blueprints' to identify proprietary design documents. To improve accuracy, the administrator needs to provide feedback on items the classifier has identified. Where in the Microsoft Purview portal would the administrator perform this action?

    Answer and explanation

    Correct answer: C

    Match/Not a match feedback for a trainable classifier's matched items is given in the Microsoft Purview portal from the classifier's matched-items view (Data classification > Classifiers > Trainable classifiers, select the classifier). The same feedback is also available in Content explorer and Data explorer, but that isn't one of the listed choices. Activity explorer shows labeling and DLP activity, and the auto-labeling page manages auto-labeling policies. Note that published custom classifiers can't be retrained; feedback helps tune accuracy. Source: Microsoft Learn, 'Increase classifier accuracy'.

  4. Question 4

    Multiple answers

    A healthcare organization, HealthMetric Solutions, needs to protect patient data used by its data science team with Microsoft Copilot. They want to prevent Copilot from accessing and processing any documents containing Electronic Health Records (EHR). Which TWO actions should be implemented to achieve this goal? (Select TWO)

    Answer and explanation

    Correct answers: A, C

    Microsoft 365 Copilot honors sensitivity label encryption through the EXTRACT (Copy) usage right. If a label applies encryption that grants users VIEW but not EXTRACT, Copilot won't summarize or return the content. An auto-labeling policy that detects EHR data applies that label reliably across existing and new documents. A DLP policy that only blocks sharing doesn't restrict Copilot. The Copilot-specific control is a DLP policy scoped to the 'Microsoft 365 Copilot and Copilot Chat' location with a sensitivity-label condition. Information barriers and retention policies don't control Copilot processing. Sources: learn.microsoft.com/purview/ai-m365-copilot-considerations and dlp-microsoft365-copilot-location-learn-about.

  5. Question 5

    True or False: When configuring a retention policy in Microsoft Purview, the principle of preservation always ensures that if a user deletes a file from a SharePoint site included in the policy, a copy is retained in the Preservation Hold Library, regardless of the policy's action.

    Answer and explanation

    Correct answer: B

    False. Whether a copy is kept in the Preservation Hold library depends on the retention settings. With retain-only or retain-and-delete settings, a file that's deleted during the retention period is copied to the Preservation Hold library. With delete-only settings nothing is preserved: the deleted document goes to the first-stage Recycle Bin, then the second-stage Recycle Bin, and is permanently deleted after 93 days. Source: Microsoft Learn, 'Learn about retention for SharePoint and OneDrive' (content paths for retain-only and delete-only settings).

  6. Question 6

    A law firm, Juris Digital, has a retention label named 'Legal-Case-Final' configured to start a 7-year retention period based on the 'event' of a case being closed. An administrator needs to trigger the retention for all documents related to the 'Case-123' matter. What is the correct sequence of actions?

    Answer and explanation

    Correct answer: B

    For event-based retention, the process is to first define an 'event type' (e.g., 'Case Closed'). Once the label is associated with this event type, you then create a specific 'event' when a case actually closes. This event uses asset IDs (like a case number or project ID) to correlate with the metadata in the documents. This action triggers the start of the retention period for all documents tagged with that asset ID and the corresponding retention label. Manually applying the label does not trigger the event. The label policy just makes the label available; it doesn't trigger the retention start.

  7. Question 7

    A compliance administrator at a bank is creating a custom sensitive info type to detect a 9-character internal transaction ID format, which always starts with 'TX' followed by 7 numbers (e.g., TX1234567). They need to increase the detection confidence by requiring a supporting keyword like 'transaction' or 'payment' within 50 characters of the ID. Which component of the sensitive info type definition should be used for the keyword requirement?

    Answer and explanation

    Correct answer: B

    In a custom SIT pattern, the primary element defines the main pattern (the TX ID regular expression). Supporting elements are additional evidence, such as a keyword list containing 'transaction' or 'payment', that must appear within the configured character proximity of the primary element to raise confidence. Character proximity is only the distance setting, and 'corroborative evidence' is the XML rule-package term for these same supporting match elements. Source: Microsoft Learn 'Create custom sensitive information types' / 'Learn about sensitive information types'.

  8. Question 8

    A company has two DLP policies. Policy A is the most restrictive and applies to Exchange online. Policy B is less restrictive and applies to Exchange online, SharePoint online, and OneDrive accounts. A user sends an email that triggers both policies. Which policy will be enforced?

    Answer and explanation

    Correct answer: B

    When multiple DLP policies are triggered for the same content in the same location, Microsoft Purview enforces the most restrictive policy. It does not simply aggregate them. The policy with the lowest priority order number (e.g., 0) is processed first, but the final action is determined by the most restrictive outcome among all matching policies. In this case, since Policy A is explicitly the most restrictive, its actions will be enforced on the email.

  9. Question 9

    A government contractor, AeroDynamics Manufacturing, stores sensitive schematics on an on-premises file share. They need to discover and apply a 'Confidential - ITAR' sensitivity label to all existing files containing specific project codes. The solution must not require migrating the data to the cloud. Which Microsoft Purview tool should be deployed to meet this requirement?

    Answer and explanation

    Correct answer: C

    The Microsoft Purview Information Protection scanner is designed specifically for discovering, classifying, and protecting files on on-premises data stores like file shares and SharePoint Server. It can be configured to run in discovery mode or enforcement mode to automatically apply sensitivity labels based on content inspection. Defender for Cloud Apps is for cloud services, the MPIP client is for user endpoints, and Endpoint DLP focuses on preventing data loss from managed devices, not bulk classification of file shares.

  10. Question 10

    An organization is configuring Microsoft Purview Audit (Premium). They want to retain audit logs for their executive leadership group for 10 years, while all other users' logs are retained for the default 1 year. Which feature allows for this granular retention configuration?

    Answer and explanation

    Correct answer: B

    Microsoft Purview Audit (Premium) allows the creation of specific audit log retention policies. These policies can be configured to retain logs for specific users, activities, or record types for longer periods (up to 10 years). This is the correct tool for applying different retention durations to different sets of users, such as the executive group. The default policy applies to everyone and cannot be customized in this granular way. eDiscovery holds and retention labels apply to user content, not audit logs.