Updated Sep 11, 2025 SC-401 Exam Dumps - PDF Questions and Testing Engine
New (2025) Microsoft SC-401 Exam Dumps
Microsoft SC-401 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
NEW QUESTION # 55
You have a Microsoft S65 E5 subscription that contains two users named User! and Admin1 Admin1 manages audit retention policies for the subscription.
You need to ensure that the audit logs of User1 will be retained for 10 years.
What should you do first?
- A. Assign a 10 year audit log retention add-on license to Admin1.
- B. Assign a 10-year audit log retention add-on license to User1.
- C. Assign a Microsoft Purview Audit (Premium) add-on license to Admin1.
- D. Assign a Microsoft Purview Audit (Premium) add on license to User1.
Answer: B
Explanation:
The scenario is about retaining audit logs for User1 for 10 years in Microsoft 365. Admin1 is responsible for managing audit retention policies, but the requirement specifically applies to User1's audit logs.
Key points:
Microsoft 365 E5 includes Audit (Premium) by default. This provides access to advanced auditing features and retention up to 1 year.
To retain audit logs for longer than 1 year (such as 10 years), Microsoft requires the 10-year Audit Log Retention Add-on license.
This license must be assigned to the user whose activities need to be retained (User1), not the administrator (Admin1).
Admin1 only needs permissions to configure and manage retention policies, but the actual long-term retention is tied to the licensed users' activity.
Why other options are incorrect:
A). Assign a Microsoft Purview Audit (Premium) add-on license to User1: Not needed because E5 already includes Audit (Premium).
B). Assign a 10-year audit log retention add-on license to Admin1: Incorrect because Admin1 is not the user whose logs must be retained; the license applies to the user being audited, not the admin.
D). Assign a Microsoft Purview Audit (Premium) add-on license to Admin1: Again, unnecessary because E5 already includes Audit (Premium), and Admin1's license does not affect User1's log retention.
Reference:
Microsoft Learn: Audit (Premium) licensing and requirements
"To retain audit records for 10 years, assign the 10-year Audit Log Retention Add-on license to the users whose activities you want to retain."
NEW QUESTION # 56
You have a Microsoft 365 tenant that is opt-in for trainable classifiers.
You need to ensure that a user named User1 can create custom trainable classifiers. The solution must use the principle of least privilege.
Which role should you assign to User1?
- A. Security Administrator
- B. Compliance Administrator
- C. Security Operator
- D. Global Administrator
Answer: D
NEW QUESTION # 57
You have the files shown in the following table.
You configure a retention policy as shown >n the exhibit. (Click the Exhibit lab.) The start of the retention period is based on when items are created. The current date is January 01. 207S.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Answer:
Explanation:
Explanation:
File1
Location: SharePoint Online.
Created: Dec 28, 2015.
As of Jan 1, 2025 # File is 9+ years old.
If retention is (example: 7 years), then the retention period has expired, and the file will be deleted once the policy is turned on.
# Answer: Yes
File2
Location: OneDrive.
Created: Jan 2, 2015.
As of Jan 1, 2025 # File is 10 years old.
Retention period (7 years, for example) has expired # File will be deleted once the policy is turned on.
# Answer: Yes
File3
Location: Exchange Online public folder.
Created: May 1, 2010.
As of Jan 1, 2025 # File is 15 years old.
But Exchange public folders are not supported locations for Microsoft 365 retention policies.
Therefore, policy does not apply, and file will not be deleted.
# Answer: No
NEW QUESTION # 58
You have a Microsoft SharePoint Online site named Site1 that has the users shown in the following table.
You create the retention labels shown in the following table.
You publish the retention labels to Site1.
On March 1,2023, you assign the retention labels to the files shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 59
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1 and the users shown in the following table.
You have a data loss prevention (DLP) policy named DLP1 as shown in the following exhibit.
You apply DLP1 to Site1.
User1 uploads a file named File1 to Site1. File1 does NOT match any of the DLP1 rules. User2 updates File1 to contain data that matches the DLP1 rules.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 60
You have a Microsoft 365 IS subscription that contains the resources shown in the following table.
The subscription contains a Windows 11 device named Device 1 and has the Microsoft Purview Information Protection client installed. Device i contains the resources shown in the following table.
You publish a sensitivity label named Label1 to User1 and Group1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Answer:
Explanation:
Explanation:
Step 1 - Label publishing and scope
The sensitivity label Label1 is published to User1 and Group1.
User1 # Directly included in label publishing.
User2 # Member of Group1, so also included indirectly.
This means both User1 and User2 are eligible to use Label1.
Step 2 - File vs Folder labeling with the Information Protection client The Microsoft Purview Information Protection (AIP unified labeling) client can apply labels to files such as .
docx, .png, .pdf, etc.
It cannot label folders directly. Labels are applied to items (files and emails), not folders.
Reference: Apply sensitivity labels using the AIP client
Step 3 - Analyze each statement
User1 can apply Label1 to File1.png
File1.png is a file type supported by the Information Protection client.
User1 has Label1 published directly.
# Answer: Yes
User1 can apply Label1 to Folder2
Sensitivity labels cannot be applied to folders in File Explorer.
# Answer: No
User2 can apply Label1 to File2.docx
File2.docx is a supported file type (Word document).
User2 is a member of Group1, and Label1 is published to Group1.
# Answer: Yes
NEW QUESTION # 61
You have a Microsoft 36S ES subscription that contains the devices shown in the following table.
You plan to implement inside' risk management and capture forensic evidence Which devices support the collection of forensic evidence, and what should you do lo prepare each supported device? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
The question is about Insider Risk Management forensic evidence collection in Microsoft 365 E5 (Microsoft Purview).
# Step 1 - Which devices are supported?
According to Microsoft documentation, forensic evidence collection for insider risk investigations is supported only on:
Windows 10
Windows 11
It is not supported on:
macOS
Android
iOS
# Reference: Forensic evidence collection in Microsoft Purview Insider Risk Management
# So, only Device1 (Windows 11) and Device2 (Windows 10) qualify.
# Step 2 - What preparation is needed?
For forensic evidence to be collected, supported devices must:
Be onboarded to Microsoft Purview (via Microsoft Defender for Endpoint integration).
Have the Microsoft Purview client installed.
This enables capture of user actions such as file copies, USB transfers, printing, etc., to provide forensic evidence for insider risk alerts.
# Correct option: Onboard the devices to Microsoft Purview and install the Microsoft Purview client
NEW QUESTION # 62
You have a Microsoft 36S ES subscription that contains the devices shown in the following table.
You publish Microsoft Purview Information Protection sensitivity labels.
You plan to deploy the information protection client to the devices. The solution must ensure that the labels can be applied to sensitive images and documents On which devices can you install the information protection client, and what should users use to apply labels?
To answer, select the appropriate options in the answer area.
Answer:
Explanation:
Explanation:
NEW QUESTION # 63
You have a Microsoft 36S ES subscription.
You need to create the Microsoft Purview insider risk management policies shown in the following table.
Which policy template should you use for each policy? To answer, drag the appropriate policy templates to the correct polices Each template may be used once more than once or not at all. You may need to drag the split bar between panes or scroll to view..
Answer:
Explanation:
Explanation:
NEW QUESTION # 64
You have a Microsoft 365 sensitivity label that is published to all the users in your Microsoft Entra tenant as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Answer:
Explanation:
Explanation:
Statement 1 - No. The sensitivity label includes content marking (watermark: INTERNAL), but it only applies to documents where the label is manually or automatically applied, not to all documents by default.
Statement 2 - No. The sensitivity label only specifies a watermark, not a header. If a header marking was configured, it would explicitly appear in the label settings.
Statement 3 - No. There is no indication that auto-labeling is configured to apply the label only to documents with the word "rebranding". Auto-labeling is an optional setting that needs explicit configuration.
NEW QUESTION # 65
You have two Microsoft 365 subscriptions named Contoso and Fabrikam. The subscriptions contain the users shown in the following table.
You have a sensitivity label named Sensitivity! as shown in the exhibit. (Click the Exhibit tab) you have the files shown in the following table.
For each of the following statements, select yes if the statement is true. Otherwise select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 66
You have a Microsoft 365 E5 subscription.
Users access their mailbox by using the following apps.
* Outlook for Microsoft 365
* Outlook on the web
* Outlook Mobile fiOS. Android)
You create a data loss prevention (DLP) policy named DLP1 that has the following settings:
* Location; Exchange email
* Status: On
* User notifications: On
* Notify users with a policy tip: Enabled
Which apps display a policy tip when content is matched by using DIP1 ?
- A. Outlook on the web only
- B. Outlook for Microsoft 365. Outlook on the web, and Outlook Mobile (iOS. Android)
- C. Outlook for Microsoft 365 and Outlook on the web only
- D. Outlook for Microsoft 365 only
- E. Outlook for Microsoft 365 and Outlook Mobile (iOS. Android) only
Answer: C
Explanation:
Policy tips in DLP: Policy tips are messages shown to users when their action (such as sending sensitive content via email) conflicts with a DLP policy.
For Exchange email location, policy tips are supported in the following apps:
Outlook for Microsoft 365 (desktop client) #
Outlook on the web (OWA) #
Outlook Mobile (iOS/Android) # Policy tips are not shown in mobile apps. Instead, DLP actions (block/restrict
/send incident report) still apply, but the user does not see a policy tip notification.
Therefore:
Supported: Outlook for Microsoft 365, Outlook on the web.
Not supported: Outlook Mobile apps.
Reference:
Microsoft Learn: Policy tips in DLP
Quote: "Policy tips are supported in Outlook on the web and Outlook 2013 and later. Policy tips are not supported in Outlook mobile apps."
NEW QUESTION # 67
You have a Microsoft 365 tenant.
You have a database that stores customer details. Each customer has a unique 13-digit identifier that consists of a fixed pattern of numbers and letters.
You need to implement a data loss prevention (DLP) solution that meets the following requirements:
*Email messages that contain a single customer identifier can be sent outside your company.
*Email messages that contain two or more customer identifiers must be approved by the company's data privacy team.
Which two components should you include in the solution? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
- A. a mail flow rule
- B. a retention label
- C. a sensitivity label
- D. a sensitive information type
- E. a DLP policy
Answer: D,E
Explanation:
You need to define a custom sensitive information type that recognizes the unique 13-digit identifier format for customer records. Microsoft Purview DLP policies use these types to identify and protect sensitive data.
A Data Loss Prevention (DLP) policy is required to enforce the rules. It will allow emails with a single identifier but trigger an approval workflow when two or more identifiers are detected.
NEW QUESTION # 68
You have Microsoft 365 E5 tenant that has a domain name of 86s40q.ofimicrosoft.com. The tenant contains the users shown in the following table.
You have a published sensitivity label.
The Access control settings for the sensitivity label are configured as shown in the exhibit (Click the Exhibit tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Answer:
Explanation:
Explanation:
NEW QUESTION # 69
You have a Microsoft 365 tenant that uses Microsoft Purview Message Encryption.
You need to ensure that any emails containing attachments and sent to [email protected] are encrypted automatically by using Microsoft Purview Message Encryption.
What should you do?
- A. From the Microsoft Defender portal, create a Safe Attachments policy.
- B. From the Exchange admin center, create a mail flow rule.
- C. From the Microsoft Purview portal, configure an auto-apply retention label policy.
- D. From the Exchange admin center, create a new sharing policy.
Answer: B
Explanation:
To automatically encrypt email messages using Microsoft Purview Message Encryption (OME), administrators must configure mail flow rules (also known as transport rules) in the Exchange admin center.
These rules can be configured to check conditions, such as when a recipient is a specific user or when an email contains attachments, and then apply encryption automatically. Sharing policies, Safe Attachments policies, and retention label policies are not used for OME encryption.
Reference: Define mail flow rules to encrypt email messages
NEW QUESTION # 70
You have a Microsoft 365 subscription that contains 20 data loss prevention (DLP) policies.
You need to identify the following:
*Rules that are applied without triggering a policy alert
*The top 10 files that have matched DLP policies
*Alerts that are miscategorized
Which report should you use for each requirement? To answer, drag the appropriate reports to the correct requirements. Each report may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 71
You have a Microsoft SharePoint Online site named Site1 that contains a document library. The library contains more than 1,000 documents. Some of the documents are job applicant resumes. All the documents are in the English language.
You plan to apply a sensitivity label automatically to any document identified as a resume. Only documents that contain work experience, education, and accomplishments must be labeled automatically.
You need to identify and categorize the resumes. The solution must minimize administrative effort.
What should you include in the solution?
- A. an exact data match (EDM) classifier
- B. a trainable classifier
- C. a keyword dictionary
- D. a function
Answer: B
Explanation:
Since you need to automatically apply a sensitivity label to resumes based on their content and structure (work experience, education, accomplishments), a trainable classifier is the best choice.
Trainable classifiers use machine learning to identify unstructured data, such as resumes, contracts, or legal documents. Instead of relying on predefined patterns (like keywords or regular expressions), a trainable classifier learns from sample documents and can accurately identify resumes even if they are formatted differently.
Final Approach:
*Train a trainable classifier using sample resumes.
*Deploy the classifier in Microsoft Purview.
*Configure a sensitivity label to be automatically applied when a document matches the classifier.
NEW QUESTION # 72
You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.
You create the audit retention policies shown in the following table.
The users perform the following actions:
*User1 renames a Microsoft SharePoint Online site.
*User2 sends an email message.
How long will the audit log records be retained for each action? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 73
DRAG DROP
You have a Microsoft 365 subscription that contains 20 data loss prevention (DLP) policies.
You need to identify the following:
# Rules that are applied without triggering a policy alert
# The top 10 files that have matched DLP policies
# Alerts that are miscategorized
Which report should you use for each requirement? To answer, drag the appropriate reports to the correct requirements. Each report may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
The False positive and override report helps identify rules that were applied but did not generate an actual policy alert, which means they were overridden or deemed false positives.
The DLP policy matches report provides details on files that matched DLP policies, including the top 10 files.
The Incident reports report helps analyze and review alerts, including those that may have been miscategorized.
NEW QUESTION # 74
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.
You need to ensure that you receive an alert when a user uploads a document to a third-party cloud storage service.
What should you use?
- A. an insider risk policy
- B. an activity policy
- C. a file policy
- D. a sensitivity label
Answer: C
NEW QUESTION # 75
You have a Microsoft 365 ES subscription.
You have a Microsoft SharePoint Online document library that contains Microsoft Word and Excel documents. The documents contain the following types of information:
* Credit card numbers
* Physical addresses in the UK
* National hearth service numbers from the UK
* Sensitive projects that contain the following words: Project Tailspin. Project Contoso, and Project falcon You have email messages m Microsoft Exchange Online that contain the following information types:
* Credit card numbers
* User sign-in credentials
* National health service numbers from the UK
You plan to use sensitive information types (SITs) for compliance policies.
What is the minimum number of SITs required to classify all the information types?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
Explanation:
You need one Sensitive Information Type (SIT) per distinct information pattern. The minimum set that covers both SharePoint and Exchange is:
Credit Card Number (built#in) - used for documents and email.
UK National Health Service Number (built#in) - used for documents and email.
EU/UK Physical Address (built#in "EU PII: Physical address").
User credentials (built#in "Credentials"/"User credentials").
Custom keyword#based SIT for the sensitive project names ("Project Tailspin", "Project Contoso", "Project Falcon") - can be one SIT using a keyword list.
SITs are reusable across locations, so you don't count duplicates for email and documents.
References:
NEW QUESTION # 76
......
Updated Verified Pass SC-401 Exam - Real Questions and Answers: https://www.prep4away.com/Microsoft-certification/braindumps.SC-401.ete.file.html
Best Way To Study For Microsoft SC-401 Exam Brilliant SC-401 Exam Questions PDF: https://drive.google.com/open?id=1aYOmd54dBwlaZvXq0RZrSKmlVhCn8tVm