[Jun 01, 2026] SC-401 Exam Dumps 100% Same Q&A In Your Real Exam
SC-401 Test Engine Dumps Training With 275 Questions
Microsoft SC-401 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
NEW QUESTION # 43
You have a Microsoft 365 E5 subscription that contains three users named U$er1, User2, and User3. The subscription contains the groups shown in the following table.
The subscription contains the devices shown in the following table.
All the devices are onboarded to Microsoft Purview.
You have the data loss prevention (DLP) policies shown in the following table.
Answer:
Explanation:
Explanation:
NEW QUESTION # 44
You have a Microsoft 365 E5 subscription.
You create a sensitivity label named Label1 and publish Label1 to all users and groups.
You have the following files in a SharePoint site:
* File1.doc
* File2.docx
* File3.xlsx
* File4.txt
You need to identify which files can have Label1 applied.
Which files should you identify?
- A. File2.docx only
- B. File1.doc File2-docx, File3.xlsx, and File4.txt
- C. File1.doc File2-docx, and File3.xlsx only
- D. File2.docx and File3.xlsx only
Answer: D
Explanation:
Sensitivity labels can be applied to modern Office file types that support protection:
Supported: .docx, .xlsx, .pptx, etc.
Not supported: Legacy formats like .doc or non-Office formats like .txt.
Therefore, only File2.docx and File3.xlsx can have Label1 applied.
Reference: File types supported for sensitivity labels
NEW QUESTION # 45
You have Microsoft 365 E5 tenant that has a domain name of 86s40q.ofimicrosoft.com. The tenant contains the users shown in the following table.
You have a published sensitivity label.
The Access control settings for the sensitivity label are configured as shown in the exhibit (Click the Exhibit tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Answer:
Explanation:
Explanation:
Comprehensive Detailed Explanation with References
We are given a sensitivity label with the following Access control settings:
Assign permissions now # meaning admins define permissions, not end users.
User access to content expires = Never.
Allow offline access = Always.
Permissions explicitly assigned:
LegalTeam@... # Co-Author
USSales@... # Reviewer
Dynamic watermarking and Double Key Encryption are not enabled.
Reference: Restrict access to content with sensitivity labels
Statement 1: Only users at your company can view an email that has the sensitivity label applied.
False, because permissions are explicitly assigned to two groups (LegalTeam, USSales).
If any external users were added, they would also get access. The configuration does not inherently restrict to only internal users.
answer: NO
Statement 2: The owner of an email can assign permissions when applying the sensitivity label.
False, because the sensitivity label was configured with "Assign permissions now".
This means permissions are fixed by admins and cannot be modified by the email sender.
If "Let users assign permissions" was enabled, this would be YES.
answer: NO
# Statement 3: [email protected]
can print an email that has the sensitivity label applied.
USSales group has the Reviewer role.
Reviewer = Can view, read, and save, but cannot print, copy, or export.
Reference: Usage rights and role mapping for sensitivity labels
answer: NO
NEW QUESTION # 46
You have a Microsoft 365 subscription.
You configure a Microsoft Purview insider risk management policy named Policy1.
You need to ensure that you will receive real-time recommendations on how to configure the indicator thresholds for Policy1. The solution must ensure that the recommendations are based on a user's activity from the past 10 days.
What should you do first?
- A. Create a data loss prevention (DLP) policy.
- B. Enable insider risk management analytics.
- C. Create an Insider Risk Indicators connector.
- D. Configure the Insider Risk Management Data sharing settings.
Answer: B
NEW QUESTION # 47
You have a Microsoft 365 E5 subscription.
You plan to implement Microsoft Purview Insider Risk Management.
You obtain a file named File1.csv that contains employee resignation data.
You need to implement the HR data connector and upload File1.csv by using the connector.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation:
NEW QUESTION # 48
Hotspot Question
You have a Microsoft 365 E5 subscription that contains four users named User1, User2, User3, and User4 and a file named File1.docx.
To File1, you apply a sensitivity label that has the permissions shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Box 1: User1 and User2 only
For File1:
User1 is Co-Owner. User1 - Yes
User2 is Co-Author. User2 - Yes.
User3 is Reviewer. User3 - No.
A user with "Reviewer" permissions on a document, folder, or site does not have extract permissions.
User4 is Viewer. User4 - No.
A user with "Vewer" permissions on a document, folder, or site does not have extract permissions.
Note: For Microsoft 365 Copilot to summarize data within a file, the user must have both the EXTRACT and VIEW usage rights on the sensitivity label applied to that file, according to Microsoft Learn. This ensures that Copilot can access and process the file's content for summarization purposes. If a file is encrypted using Azure Rights Management without a sensitivity label, the same permissions (EXTRACT and VIEW) are still required for Copilot to function.
Box 2: User1, User2, User3 and User4.
User1 is Co-Owner. User1 - Yes
User2 is Co-Author. User2 - Yes.
User3 is Reviewer. User3 - Yes.
In Microsoft 365, a Reviewer of a file can reference that file, and potentially other files, within their comments or suggestions. Reviewers can use @mentions to tag individuals, including the file's author or other reviewers, to draw attention to specific points or sections within the document.
Additionally, Microsoft 365 Copilot allows reviewers to reference files, emails, and meetings when creating, reviewing, or finalizing documents.
User4 is Viewer. User4 - Yes.
In Microsoft 365, a user with Viewer permissions for a file can indeed reference that file in various ways, including using it as a source for Microsoft Copilot, or simply copying and pasting the link to share with others.
Reference:
https://techcommunity.microsoft.com/blog/microsoft365insiderblog/expanding-reference- capabilities-with-microsoft-365-copilot-in-word/4406054
NEW QUESTION # 49
You have a Microsoft 365 ES subscription that uses Microsoft Teams and contains the users shown in the following table.
You have the retention policies shown in the following table.
The users perform the actions shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point
Answer:
Explanation:
Explanation:
NEW QUESTION # 50
You need to be alerted when users share sensitive documents from Microsoft OneDrive to any users outside your company. What should you do?
- A. From the Exchange admin center, create a data loss prevention (DLP) policy.
- B. From the Microsoft Entra admin center, configure an Identity Protection policy.
- C. From the Microsoft Defender portal, create a file policy.
- D. From the Microsoft Defender portal, create an activity policy.
Answer: D
Explanation:
Correct:
* From the Microsoft Defender portal, create an activity policy.
An activity policy in Microsoft Defender for Cloud Apps (Microsoft Defender portal) allows you to track and alert on specific user actions, such as sharing sensitive documents externally from OneDrive. This policy can detect file-sharing activities and send alerts when files are shared with external users, which meets the requirement.
Incorrect:
* From the Exchange admin center, create a data loss prevention (DLP) policy.
From the Exchange admin center you can only configure mail flow rules to detect sensitive info and apply actions like encryption or blocking, which are essentially DLP functions within Exchange.
* From the Microsoft Defender portal, create a file policy.
Is correct only if sensitive documents already have been shared.
* From the Microsoft Entra admin center, configure an Identity Protection policy.
* From the Microsoft Purview portal, create an insider risk policy.
* From the Microsoft Purview portal, start a data investigation.
* From the Microsoft Purview portal, start an Advanced eDiscovery search.
Reference:
https://learn.microsoft.com/en-us/purview/dlp-create-policy-spo-odb-external
NEW QUESTION # 51
At the end of a project, you upload project documents to a Microsoft SharePoint Online library that contains many files. The following is a sample of the project document file names:
- aei_AA989.docx
- bci_WS098.docx
- cei_DF112.docx
- ebc_QQ454.docx
- ecc_BB565.docx
All documents that use this naming format must be labeled as Project Documents:
You need to create an auto-apply retention label policy.
What should you use to identify the files?
- A. A trainable classifier
- B. A retention label
- C. A sensitive info type
Answer: C
NEW QUESTION # 52
You are creating a DLP policy named Policy1 that will be applied to the locations as shown in the following exhibit.
Policy1 contains an advanced data loss prevention (DLP) rule named Rule1.
Which two conditions can you use in Rule1? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
- A. Document property is
- B. Content is shared from Microsoft 365
- C. Document size equals or is greater than
- D. Content contains
- E. Attachment's file extension is
Answer: B,D
Explanation:
You are creating a Data Loss Prevention (DLP) policy in Microsoft 365 with advanced rules. Advanced DLP rules provide more granular conditions and actions than standard DLP rules.
Conditions available in advanced DLP
According to Microsoft Docs on Conditions in DLP policies:
* # Content contains # Used to detect sensitive information types, keywords, or exact data matches.
This is one of the most common and fundamental DLP conditions.
* # Content is shared from Microsoft 365 # Used to detect whether content has been shared externally or with specific domains/users. This is a modern advanced DLP condition.
Why the others are not correct:
* A. Document property is # This condition applies to information governance retention policies /labels (not DLP). Not available in DLP rules.
* B. Attachment's file extension is # This is supported in Exchange mail flow rules (transport rules) but not in advanced DLP rules.
* C. Document size equals or is greater than # Also applies in Exchange transport rules and certain SharePoint restrictions, but not available as a DLP rule condition.
NEW QUESTION # 53
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
The subscription contains the groups shown in the following table.
You plan to create a priority user group named Priority1.
You need to identify the following:
. Which users and groups can be added to Priority1?
. Which users can be enabled to view alerts that involve the members of Priority1?
What should you identify? To answer, select the appropriate options in the answer area.
Answer:
Explanation:
Explanation:
NEW QUESTION # 54
You need to meet the technical requirements for the confidential documents.
What should you create first, and what should you use for the detection method? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 55
You are creating a data loss prevention (DLP) policy that will apply to all available locations except Fabric and Power BI workspaces.
You configure an advanced DLP rule in the policy.
Which type of condition can you use in the rule?
- A. Content search query
- B. Keywords
- C. Sensitive label
- D. Sensitive info type
Answer: D
Explanation:
When configuring an advanced DLP rule in Microsoft Purview Data Loss Prevention (DLP), you can use a Sensitive Information Type (SIT) condition to detect and classify specific types of sensitive data, such as credit card numbers, Social Security numbers, or custom sensitive data patterns. This allows you to apply protection and trigger actions based on the identified content.
NEW QUESTION # 56
You have a Microsoft 365 E5 subscription. The subscription contains a user named User1 and the sensitivity labels shown in the following table.
You publish the labels to User1.
The subscription contains the files shown in the following table.
Which files can Microsoft 365 Copilot summarize for User1?
- A. File2only
- B. File2 and File3 only
- C. File1, File2. and File3
- D. File3 only
Answer: A
Explanation:
Microsoft 365 Copilot can only process (summarize, answer questions about) a labeled file when the user has the Copy and extract content (EXTRACT) usage right granted by the applied sensitivity label.
From the table of labels:
* Label1 # VIEW only (no EXTRACT) # Copilot cannot summarize.
* Label2 # VIEW and EXTRACT granted # Copilot can summarize.
* Label3 # VIEW and EXPORT (no EXTRACT) # Copilot cannot summarize.
Since File2 is labeled Label2, it's the only file for which User1 has the required EXTRACT permission, so it' s the only file Copilot can summarize.
References:
Microsoft Learn - Sensitivity labels and Copilot for Microsoft 365: Copilot requires the Copy and extract content (EXTRACT) permission to process labeled content.https://learn.microsoft.com/microsoft-365
/compliance/sensitivity-labels-copilot
Microsoft Learn - Usage rights for encryption with sensitivity labels (VIEW, EXTRACT, EXPORT definitions)https://learn.microsoft.com/microsoft-365/compliance/encryption-sensitivity-labels#usage-rights- and-permissions
NEW QUESTION # 57
You have a Microsoft 365 E5 subscription.
You need to create a sensitivity label named Label1. The solution must ensure that users can use Microsoft
365 Copilot to summarize files that have Label1 applied.
Which permission should you select for Label1?
- A. Copy and extract content(EXTRACT)
- B. Edit content(DOCEDIT)
- C. View rights(VIEW)
- D. Export content(EXPORT)
Answer: A
Explanation:
To allow Microsoft 365 Copilot to summarize files that have Label1 applied, the label must grant permission to extract content from the document. The correct permission for this is Copy and extract content (EXTRACT).
Microsoft 365 Copilot requires access to read and process content in documents to generate summaries. The EXTRACT permission allows users (and AI tools like Copilot) to copy and extract content for processing while still maintaining the protection applied by the sensitivity label.
NEW QUESTION # 58
You have a Microsoft 365 E5 tenant.
You need to add a new keyword dictionary.
What should you create?
- A. a retention policy
- B. a sensitivity label
- C. a sensitive info type
- D. a trainable classifier
Answer: C
Explanation:
To add a new keyword dictionary in Microsoft Purview Data Loss Prevention (DLP), you must create a Sensitive Information Type (SIT).
Sensitive Info Types (SITs) allow you to define custom detection rules, including keyword dictionaries, regular expressions, and functions for identifying sensitive content in emails, documents, and other Microsoft
365 locations. A keyword dictionary is a list of predefined words/phrases that Microsoft Purview can use to identify and classify content for DLP policies.
Steps to add a keyword dictionary:
1. Go to Microsoft Purview compliance portal
2. Navigate to Data classification > Sensitive info types
3. Create a new sensitive info type
4. Add a keyword dictionary
5. Save and use it in a DLP policy
NEW QUESTION # 59
You need to meet the retention requirement for the users' Microsoft 365 data.
What is the minimum number of retention policies required to achieve the goal?
- A. 0
- B. 1
- C. 2
- D. 3
- E. 4
Answer: A
Explanation:
The requirement states that all Microsoft 365 data for users must be retained for at least one year. In Microsoft
365, retention policies must be configured for each type of data storage.
Step 1: Identifying Where Data is Stored
From the case study, users store data in the following locations:
# SharePoint Online sites
# OneDrive accounts
# Exchange email
# Exchange public folders
# Teams chats
# Teams channel messages
Since these locations fall under two broad categories:
# Microsoft Exchange data (Emails, Public folders)
# SharePoint, OneDrive, and Teams data
Step 2: Required Retention Policies
1#. A single retention policy can cover:
# SharePoint Online
# OneDrive
# Microsoft Teams
2. A second retention policy is required for:
# Exchange (Emails & Public Folders)
Thus, the minimum number of retention policies required to meet the requirement is 2.
Microsoft 365 retention policies can be applied broadly across multiple services with just two policies:
# One for Exchange & Public Folders
# One for SharePoint, OneDrive, and Teams
There's no need for separate policies for each individual workload unless different retention durations are required, which is not stated in the requirement.
Topic 1, Contoso, Ltd Case Study 1
Instructions
This is a case study. Case studies are not timed separately from other exam sections. You can use as much exam time as you would like to complete each case study. However, there might be additional case studies or other exam sections. Manage your time to ensure that you can complete all the exam sections in the time provided. Pay attention to the Exam Progress at the top of the screen so you have sufficient time to complete any exam sections that follow this case study.
To answer the case study questions, you will need to reference information that is provided in the case. Case studies and associated questions might contain exhibits or other resources that provide more information about the scenario described in the case. Information provided in an individual question does not apply to the other questions in the case study.
A Review Screen will appear at the end of this case study. From the Review Screen, you can review and change your answers before you move to the next exam section. After you leave this case study, you will NOT be able to return to it.
To start the case study
To display the first question in this case study, select the "Next" button. To the left of the question, a menu provides links to information such as business requirements, the existing environment, and problem statements. Please read through all this information before answering any questions. When you are ready to answer a question, select the "Question" button to return to the question.
Overview
Contoso, Ltd. is a consulting company that has a main office in Montreal and three branch offices in Seattle, Boston, and Johannesburg.
Existing Environment
Microsoft 365 Environment
Contoso has a Microsoft 365 E5 tenant. The tenant contains the administrative user accounts shown in the following table.
Users store data in the following locations:
# SharePoint sites
# OneDrive accounts
# Exchange email
# Exchange public folders
# Teams chats
# Teams channel messages
When users in the research department create documents, they must add a 10-digit project code to each document. Project codes that start with the digits 999 are confidential.
SharePoint Online Environment
Contoso has four Microsoft SharePoint Online sites named Site1, Site2, Site3, and Site4.
Site2 contains the files shown in the following table.
Two users named User1 and User2 are assigned roles for Site2 as shown in the following table.
Site3 stores documents related to the company's projects. The documents are organized in a folder hierarchy based on the project.
Site4 has the following two retention policies applied:
# Name: Site4RetentionPolicy1
# Locations to apply the policy: Site4
# Delete items older than: 2 years
# Delete content based on: When items were created
# Name: Site4RetentionPolicy2
# Locations to apply the policy: Site4
# Retain items for a specific period: 4 years
# Start the retention period based on: When items were created
# At the end of the retention period: Do nothing
Problem Statements
Management at Contoso is concerned about data leaks. On several occasions, confidential research department documents were leaked.
Requirements
Planned Changes
Contoso plans to create the following data loss prevention (DLP) policy:
# Name: DLPpolicy1
# Locations to apply the policy: Site2
# Conditions:
# Content contains any of these sensitive info types: SWIFT Code
# Instance count: 2 to any
# Actions: Restrict access to the content
Technical Requirements
Contoso must meet the following technical requirements:
# All administrative users must be able to review DLP reports.
# Whenever possible, the principle of least privilege must be used.
# For all users, all Microsoft 365 data must be retained for at least one year.
# Confidential documents must be detected and protected by using Microsoft 365.
# Site1 documents that include credit card numbers must be labeled automatically.
# All administrative users must be able to create Microsoft 365 sensitivity labels.
# After a project is complete, the documents in Site3 that relate to the project must be retained for 10 years.
NEW QUESTION # 60
You have a Microsoft $65 subscription.
You plan to retain the following audit log record types and activities for the next three years.
* Copilotlnteraction: All activities selected (1/1)
o Interacted with Copilot
* Compliance DLP endpoint: All activities selected {2/2)
o Matched DIP rule
o Removed Dl P rule from document
* AzureActiveDirectory 2 of 25 activities selected (2/25)
o Reset user password o Changed user password
What is the minimum number of audit retention policies you should create to retain only the selected record types and activities?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
Explanation:
Step 1 - Understanding the requirement
You want to retain specific audit log record types and activities for 3 years:
CopilotInteraction # All activities (1/1)
Compliance DLP endpoint # All activities (2/2)
Azure Active Directory # Only 2 out of 25 activities selected (Reset user password, Changed user password) The goal is to minimize the number of audit retention policies while meeting the requirement to store only the selected record types and activities.
Step 2 - Audit retention policies in Microsoft Purview
Audit retention policies let you define which activities and record types are retained and for how long.
A single retention policy can include multiple record types and multiple activities.
Limitation: Each policy can only define one set of retention settings per included record types/activities.
If you want to retain different subsets of activities (e.g., only 2 out of 25 in Azure AD), you must create a separate policy for that.
# Reference: Set up audit (Premium) retention policies in Microsoft Purview Step 3 - Applying to the scenario CopilotInteraction: Since you need all activities, you can include them in one policy.
Compliance DLP endpoint: Since you also need all activities, they can be added to the same policy as CopilotInteraction.
# These two can be covered by 1 policy.
Azure Active Directory: You only need 2 out of 25 activities. Since this requires activity-level filtering, it must be placed in a separate policy.
Thus:
Policy 1 # CopilotInteraction (all) + Compliance DLP endpoint (all)
Policy 2 # Azure AD "Reset user password"
Policy 3 # Azure AD "Changed user password"
That equals 3 total policies.
NEW QUESTION # 61
HOTSPOT
You are reviewing policies for the SharePoint Online environment.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
A white paper with black text AI-generated content may be incorrect.
Understanding Site4's Retention Policies:
# Site4RetentionPolicy1 deletes items older than 2 years from creation. If a file was created on January 1,
2021, it would be deleted after January 1, 2023.
# Site4RetentionPolicy2 retains files for 4 years from creation. If a file was created on January 1, 2021, it will be kept until January 1, 2025, but not deleted after that (policy states "Do nothing").
Statement 1 - Yes, because Site4RetentionPolicy2 ensures files are retained for 4 years.
Statement 2 - Yes, because Site4RetentionPolicy2 retains the file for 4 years (until January 1, 2025).
Statement 3 - No, because retention is only for 4 years (until January 1, 2025). After that, the policy does
"nothing," meaning the file is no longer recoverable after that period.
NEW QUESTION # 62
You have a Microsoft 365 E5 subscription that contains a trainable classifier named Trainable1.
You plan to create the items shown in the following table.
Which items can use Trainable 1?
- A. Label1 and Label2 only
- B. Label2 only
- C. Label1, Label2, Policy1, and DLP1
- D. Label2, Policy1, and DLP1 only
- E. Label1 and Policy1 only
Answer: D
Explanation:
A trainable classifier in Microsoft Purview is used to automatically identify and classify unstructured data based on content patterns. The classifier can be used in:
1. Retention Labels (Label2) Supported
Trainable classifiers can be linked to retention labels to automatically classify and apply retention policies to documents.
2. Retention Label Policies (Policy1) Supported
Retention label policies define how and where retention labels are applied, including automatically using trainable classifiers.
3. Data Loss Prevention (DLP) Policies (DLP1) Supported
Trainable classifiers can be used in DLP policies to detect and protect sensitive content automatically.
NEW QUESTION # 63
You have a Microsoft 365 E5 subscription that contains 500 Windows devices.
You plan to deploy Microsoft Purview Data Security Posture Management for AI (DSPM for AI).
You need to ensure that you can monitor user activities on third-party generative AI websites.
Which two prerequisites should you complete for DSPM for AI? Each correct answer presents part of the solution, NOTE: Each correct selection is worth one point.
- A. Enroll the devices in Microsoft Intune.
- B. Create a communication compliance policy.
- C. Install the Microsoft Purview extension on the devices.
- D. Create a data leaks policy.
- E. Create an Endpoint data loss prevention (Endpoint DLP) policy.
- F. Onboard the devices to Microsoft Purview.
Answer: E,F
Explanation:
Required for monitoring interactions with third-party generative AI sites:
[B] * Devices are onboarded to Microsoft Purview, required for:
- Gaining visibility into sensitive information that's shared with third-party generative AI sites. For example, a user pastes credit card numbers into ChatGPT.
[A]- Applying endpoint DLP policies to warn or block users from sharing sensitive information with third-party generative AI sites. For example, a user identified as elevated risk in Adaptive Protection is blocked with the option to override when they paste credit card numbers into ChatGPT.
Reference:
https://learn.microsoft.com/en-us/purview/dspm-for-ai-considerations
NEW QUESTION # 64
You have a Microsoft 365 E5 subscription that contains the device configurations shown in the following table.
Each configuration uses either Google Chrome or Firefox as a default browser.
You need to implement Microsoft Purview and deploy the Microsoft Purview browser extension to the configurations.
To which configuration can each extension be deployed? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 65
How many files in Site2 can User1 and User2 access after you turn on DLPpolicy1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION # 66
You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.
The subscription contains the resources shown in the following table.
You create a sensitivity label named Label1.
You need to publish Label1 and have the label apply automatically.
To what can you publish Label1, and to what can Label1 be auto-applied? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Topic 1, Contoso, Ltd
Instructions
This is a case study. Case studies are not timed separately from other exam sections. You can use as much exam time as you would like to complete each case study. However, there might be additional case studies or other exam sections. Manage your time to ensure that you can complete all the exam sections in the time provided. Pay attention to the Exam Progress at the top of the screen so you have sufficient time to complete any exam sections that follow this case study.
To answer the case study questions, you will need to reference information that is provided in the case. Case studies and associated questions might contain exhibits or other resources that provide more information about the scenario described in the case. Information provided in an individual question does not apply to the other questions in the case study.
A Review Screen will appear at the end of this case study. From the Review Screen, you can review and change your answers before you move to the next exam section. After you leave this case study, you will NOT be able to return to it.
To start the case study
To display the first question in this case study, select the "Next" button. To the left of the question, a menu provides links to information such as business requirements, the existing environment, and problem statements. Please read through all this information before answering any questions. When you are ready to answer a question, select the "Question" button to return to the question.
Overview
Contoso, Ltd. is a consulting company that has a main office in Montreal and three branch offices in Seattle, Boston, and Johannesburg.
Existing Environment
Microsoft 365 Environment
Contoso has a Microsoft 365 E5 tenant. The tenant contains the administrative user accounts shown in the following table.
Users store data in the following locations:
*SharePoint sites
*OneDrive accounts
*Exchange email
*Exchange public folders
*Teams chats
*Teams channel messages
When users in the research department create documents, they must add a 10-digit project code to each document. Project codes that start with the digits 999 are confidential.
SharePoint Online Environment
Contoso has four Microsoft SharePoint Online sites named Site1, Site2, Site3, and Site4.
Site2 contains the files shown in the following table.
Two users named User1 and User2 are assigned roles for Site2 as shown in the following table.
Site3 stores documents related to the company's projects. The documents are organized in a folder hierarchy based on the project.
Site4 has the following two retention policies applied:
*Name: Site4RetentionPolicy1
*Locations to apply the policy: Site4
*Delete items older than: 2 years
*Delete content based on: When items were created
*Name: Site4RetentionPolicy2
*Locations to apply the policy: Site4
*Retain items for a specific period: 4 years
*Start the retention period based on: When items were created
*At the end of the retention period: Do nothing
Problem Statements
Management at Contoso is concerned about data leaks. On several occasions, confidential research department documents were leaked.
Requirements
Planned Changes
Contoso plans to create the following data loss prevention (DLP) policy:
*Name: DLPpolicy1
*Locations to apply the policy: Site2
*Conditions:
*Content contains any of these sensitive info types: SWIFT Code
*Instance count: 2 to any
*Actions: Restrict access to the content
Technical Requirements
Contoso must meet the following technical requirements:
*All administrative users must be able to review DLP reports.
*Whenever possible, the principle of least privilege must be used.
*For all users, all Microsoft 365 data must be retained for at least one year.
*Confidential documents must be detected and protected by using Microsoft 365.
*Site1 documents that include credit card numbers must be labeled automatically.
*All administrative users must be able to create Microsoft 365 sensitivity labels.
*After a project is complete, the documents in Site3 that relate to the project must be retained for 10 years.
NEW QUESTION # 67
......
SC-401 Practice Test Pdf Exam Material: https://www.guidetorrent.com/SC-401-pdf-free-download.html
SC-401 Questions Pass on Your First Attempt Dumps for Microsoft Certified: Information Security Administrator Associate Certified: https://drive.google.com/open?id=16BKrHkFlp79E9atHT6PlQSJM7soFyKaR