SC-401 Exam Dumps Pass with Updated 2026 Certified Exam Questions [Q110-Q127]

Share

SC-401 Exam Dumps Pass with Updated 2026 Certified Exam Questions

SC-401 Exam Questions - Real & Updated Questions PDF


Microsoft SC-401 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Implement Data Loss Prevention and Retention: This section evaluates Data Protection Officers on designing and managing data loss prevention (DLP) policies and retention strategies. It includes setting policies for data security, configuring Endpoint DLP, and managing retention labels and policies. Candidates must understand adaptive scopes, policy precedence, and data recovery within Microsoft 365.
Topic 2
  • Manage Risks, Alerts, and Activities: This section assesses Security Operations Analysts on insider risk management, monitoring alerts, and investigating security activities. It covers configuring risk policies, handling forensic evidence, and responding to alerts using Microsoft Purview and Defender tools. Candidates must also analyze audit logs and manage security workflows.
Topic 3
  • Implement Information Protection: This section measures the skills of Information Security Analysts in classifying and protecting data. It covers identifying and managing sensitive information, creating and applying sensitivity labels, and implementing protection for Windows, file shares, and Exchange. Candidates must also configure document fingerprinting, trainable classifiers, and encryption strategies using Microsoft Purview.
Topic 4
  • Protect Data Used by AI Services: This section evaluates AI Governance Specialists on securing data in AI-driven environments. It includes implementing controls for Microsoft Purview, configuring Data Security Posture Management (DSPM) for AI, and monitoring AI-related security risks to ensure compliance and protection.

 

NEW QUESTION # 110
Your company has a Microsoft 365 tenant.
The company performs annual employee assessments. The assessment results are recorded in a document named AssessmentTemplate.docx that is created by using a Microsoft Word template. Copies of the employee assessments are sent to employees and their managers.
The assessment copies are stored in mailboxes, Microsoft SharePoint Online sites, and OneDrive folders. A copy of each assessment is also stored in a SharePoint Online folder named Assessments.
You need to create a data loss prevention (DLP) policy that prevents the employee assessments from being emailed to external users. You will use a document fingerprint to identify the assessment documents. The solution must minimize effort.
What should you include in the solution?

  • A. Create a fingerprint of 100 sample documents in the Assessments folder.
  • B. Create a fingerprint of AssessmentTemplate.docx.
  • C. Create a sensitive info type that uses Exact Data Match (EDM).
  • D. Import 100 sample documents from the Assessments folder to a seed folder.

Answer: B

Explanation:
It is just created document fingerprint using the template, this will be used as "Sensitive Info Type" to discover any employee assessment and apply the control over this file as required.


NEW QUESTION # 111
You need to meet the technical requirements for the Site1 documents.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation:
A screenshot of a questionnaire AI-generated content may be incorrect.

The goal is to automatically label documents in Site1 that contain credit card numbers. To achieve this, we need a sensitivity label with an auto-labeling policy based on a sensitive info type that detects credit card numbers.
Step 1: Create a Sensitive Info Type
# A sensitive info type is needed to detect credit card numbers in documents.
# Microsoft Purview includes built-in sensitive info types for credit card numbers, but we can also create a custom one if necessary.
Step 2: Create a Sensitivity Label
# A sensitivity label is required to classify and protect documents containing sensitive information.
# This label can apply encryption, watermarking, or access controls to credit card data.
Step 3: Create an Auto-Labeling Policy
# An auto-labeling policy ensures that the sensitivity label is applied automatically when credit card numbers are detected in Site1.
# This policy is configured to scan files and automatically apply the correct sensitivity label.
Topic 1, Contoso, Ltd Case Study 1
Instructions
This is a case study. Case studies are not timed separately from other exam sections. You can use as much exam time as you would like to complete each case study. However, there might be additional case studies or other exam sections. Manage your time to ensure that you can complete all the exam sections in the time provided. Pay attention to the Exam Progress at the top of the screen so you have sufficient time to complete any exam sections that follow this case study.
To answer the case study questions, you will need to reference information that is provided in the case. Case studies and associated questions might contain exhibits or other resources that provide more information about the scenario described in the case. Information provided in an individual question does not apply to the other questions in the case study.
A Review Screen will appear at the end of this case study. From the Review Screen, you can review and change your answers before you move to the next exam section. After you leave this case study, you will NOT be able to return to it.
To start the case study
To display the first question in this case study, select the "Next" button. To the left of the question, a menu provides links to information such as business requirements, the existing environment, and problem statements. Please read through all this information before answering any questions. When you are ready to answer a question, select the "Question" button to return to the question.
Overview
Contoso, Ltd. is a consulting company that has a main office in Montreal and three branch offices in Seattle, Boston, and Johannesburg.
Existing Environment
Microsoft 365 Environment
Contoso has a Microsoft 365 E5 tenant. The tenant contains the administrative user accounts shown in the following table.

Users store data in the following locations:
# SharePoint sites
# OneDrive accounts
# Exchange email
# Exchange public folders
# Teams chats
# Teams channel messages
When users in the research department create documents, they must add a 10-digit project code to each document. Project codes that start with the digits 999 are confidential.
SharePoint Online Environment
Contoso has four Microsoft SharePoint Online sites named Site1, Site2, Site3, and Site4.
Site2 contains the files shown in the following table.

Two users named User1 and User2 are assigned roles for Site2 as shown in the following table.

Site3 stores documents related to the company's projects. The documents are organized in a folder hierarchy based on the project.
Site4 has the following two retention policies applied:
# Name: Site4RetentionPolicy1
# Locations to apply the policy: Site4
# Delete items older than: 2 years
# Delete content based on: When items were created
# Name: Site4RetentionPolicy2
# Locations to apply the policy: Site4
# Retain items for a specific period: 4 years
# Start the retention period based on: When items were created
# At the end of the retention period: Do nothing
Problem Statements
Management at Contoso is concerned about data leaks. On several occasions, confidential research department documents were leaked.
Requirements
Planned Changes
Contoso plans to create the following data loss prevention (DLP) policy:
# Name: DLPpolicy1
# Locations to apply the policy: Site2
# Conditions:
# Content contains any of these sensitive info types: SWIFT Code
# Instance count: 2 to any
# Actions: Restrict access to the content
Technical Requirements
Contoso must meet the following technical requirements:
# All administrative users must be able to review DLP reports.
# Whenever possible, the principle of least privilege must be used.
# For all users, all Microsoft 365 data must be retained for at least one year.
# Confidential documents must be detected and protected by using Microsoft 365.
# Site1 documents that include credit card numbers must be labeled automatically.
# All administrative users must be able to create Microsoft 365 sensitivity labels.
# After a project is complete, the documents in Site3 that relate to the project must be retained for 10 years.


NEW QUESTION # 112
You have a Microsoft 365 E5 subscription that has a sensitivity label named Sensitivity1.
You plan to create an auto-labeling policy that will apply Sensitivity1 to Microsoft Exchange Online mailboxes.
On February 1, you create the auto-labeling policy and enable simulation mode by using the default settings.
No modifications are made to the policy in simulation mode.
When will the policy first be turned on?

  • A. February 15
  • B. never
  • C. February 2
  • D. February 6

Answer: A

Explanation:
When you create an auto-labeling policy for sensitivity labels and start it in simulation mode using the default settings, Microsoft Purview will automatically turn on the policy after 14 days if you make no changes during simulation. A policy created on February 1 would therefore be turned on on February 15.
References used:
Microsoft Purview Data Access Governance custom assessments item limits.
Exchange Online Managed Folder Assistant and Start-ManagedFolderAssistant.
Auto-labeling simulation mode behavior and automatic enable timeline.


NEW QUESTION # 113
You are creating a custom trainable classifier to identify organizational product codes referenced in Microsoft 365 content.
You identify 300 files to use as seed content.
Where should you store the seed content?

  • A. a Microsoft Exchange Online shared mailbox
  • B. a Microsoft SharePoint Online folder
  • C. an Azure file share
  • D. a Microsoft OneDrive folder

Answer: B

Explanation:
Seed content files for a custom trainable classifier should be stored in a SharePoint Online folder (or folders) that is dedicated to holding only that seed content. You'll need to create a separate folder for positive examples and another for negative examples. After placing the files, make note of the full URL of the SharePoint site, library, and folder for each set of content.
Note: How to create a trainable classifier: The following process automates the testing of trainable classifiers and shortens the creation workflow from 12 days to two days. In some cases, the process can take only a few hours.
1. Collect between 50 and 500 seed content items that strongly represent the data you want the classifier to positively identify as being in the category. For a list of supported file types, see Default crawled file name extensions and parsed file types in SharePoint Server.
2. Collect a second set of seed content (from 150 to 1,500 items) that represents data that don't belong in the category.
3. Place the positive and negative seed content in separate SharePoint folders. Each folder must be dedicated to holding only the seed content. Make note of the site, library, and folder URL for each set.
4. Sign in to the Microsoft Purview portal with either Compliance admin or Security admin role access and navigate to Data loss prevention > Data classification > Classifiers.
Reference:
https://learn.microsoft.com/en-us/purview/trainable-classifiers-get-started-with


NEW QUESTION # 114
You plan to implement Microsoft Purview Advanced Message Encryption.
You need to ensure that encrypted email sent to external recipients expires after seven days.
What should you create first?

  • A. a mail flow rule
  • B. a remote domain in Microsoft Exchange
  • C. an X.509 version 3 certificate
  • D. a custom branding template
  • E. a connector in Microsoft Exchange

Answer: D

Explanation:
You can use message expiration on emails that your users send to external recipients who use the OME Portal to access encrypted emails. You force recipients to use the OME portal to view and reply to encrypted emails sent by your organization by using a *custom branded template* that specifies an expiration date in PowerShell.
Reference:
https://learn.microsoft.com/en-us/purview/ome-advanced-expiration


NEW QUESTION # 115
SIMULATION
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
[email protected]
Microsoft 365 Password: XXXXXXXXX
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL "https://admin.microsoft.com", and press Enter.
The following information is for technical support purposes only:
Lab Instance: XXXXXXXXX
Task 6
You plan to create an Endpoint data loss prevention (Endpoint DLP) policy that will restrict browsers from uploading files to fabrikam.com.
You need to configure the Endpoint DLP settings so that fabrikam.com can be restricted by the Endpoint DLP policy.
You do NOT need to create an Endpoint DLP policy at this time.

Answer:

Explanation:
To configure an Endpoint DLP policy that restricts browser uploads to a specific domain, first create a "Sensitive service domain group" with the domain you want to block. Then, create a new DLP policy [not needed], select "Devices" as the location, and in the rule's action, choose "Upload to a restricted cloud service domain" and select "Block.". Finally, in the rule's conditions, select the "Content contains" activity and add sensitive labels or other conditions as needed.
Create a sensitive service domain group
Step 1: Go to the Microsoft Purview portal and navigate to Data loss prevention > Settings (gear icon).
Step 2: Select Sensitive service domain groups and click Create sensitive service domain group.
Step 3: Give the group a name (e.g., "Restricted Upload Domains").
Step 4: Enter the specific domain you want to block in the "Sensitive service domain" field. [Enter fabrikam.com] You can use wildcards for subdomains (e.g., *.contoso.com) and can add multiple domains to the group.
Step 5: Select Save.
Reference:
https://learn.microsoft.com/en-us/purview/dlp-configure-endpoint-settings


NEW QUESTION # 116
You have a data loss prevention (DIP) policy that applies to the Devices location. The policy protects documents that contain United States passport numbers Users report that they cannot upload documents to a travel management website because of the pokey.
You need to ensure that the users can upload the documents to the travel management website. The solution must prevent the protected content from being uploaded to other locations.
Which Microsoft 365 Endpoint data loss prevention (Endpoint DIP) setting should you configure?

  • A. Service domains
  • B. Unallowed browsers
  • C. Unallowed apps
  • D. File path exclusions

Answer: A

Explanation:
The issue: Users cannot upload documents with U.S. passport numbers to a legitimate travel management website because Endpoint DLP is blocking it.
Solution: Configure Service domains in Endpoint DLP # this allows defining specific trusted domains where uploads of sensitive information are permitted while still blocking uploads to other, non-approved domains.
Why not others?
Unallowed browsers: Restricts/blocklists browsers, not the issue here.
File path exclusions: Excludes local folders/paths from monitoring, irrelevant to web uploads.
Unallowed apps: Restricts desktop apps, not browser-based sites.
Reference:
Microsoft Learn: Configure service domains for Endpoint DLP


NEW QUESTION # 117
Hotspot Question
You create a retention policy as shown in the following exhibit.

A user named User1 deletes a file named File1.docx from a Microsoft SharePoint Online site named Site1.
A user named User2 deletes an email and empties the Deleted Items folder in Microsoft Outlook.
Where is the content retained one year after deletion? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/retention?view=o365-worldwide


NEW QUESTION # 118
Hotspot Question
You have a Microsoft 365 E5 subscription that contains three users named User, User2, and User3. The subscription contains the groups shown in the following table.

The subscription contains the devices shown in the following table.

All the devices are onboarded to Microsoft Purview.
You have the data loss prevention (DLP) policies shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Yes
User1 is member of Group1 and of Group3.
Device1 is Windows.
Policy1 is assigned to Group1, and restrict copying to USB [assume this is the intended word] devices.
Note:
Supported actions: Devices
You can tell DLP to Allow, Audit only, Block with override, or Block (the actions) these user activities for onboarded Windows devices.
Box 2: No
User2 is member of Group2 and of Group3.
Device1 is Android.
The device actions do not apply for Android devices.
Box 3: Yes
User3 is member of Group 1, Group2 and of Group3.
Device1 is macOS.
Policy3 is assigned to Group3, and restricts accessing corporate content in Microsoft 365 locations.
Reference:
https://learn.microsoft.com/en-us/purview/dlp-policy-reference


NEW QUESTION # 119
You have a Microsoft 365 sensitivity label that is published to all the users in your Microsoft Entra tenant as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Answer:

Explanation:


NEW QUESTION # 120
You have a Microsoft 36S subscription that contains the sensitive information types (SITs) shown in the following exhibit.

Use the drop-down menus To select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct flection is worth one point.

Answer:

Explanation:

Explanation:

Step 1 - Understanding the scenario
The screenshot shows multiple Sensitive Information Types (SITs) in Microsoft Purview, including:
ABA Routing Number (Microsoft-built)
ASP.NET Machine Key (Microsoft-built)
Adatum document patterns (custom, Fingerprint type)
Adatum numbers (custom, Entity type)
Bundled SITs (like All Credential Types, All Full Names)
The question is asking:
Which SITs can you copy to create a new SIT?
Which SITs can you edit directly without copying?
Step 2 - Microsoft rules for SITs
Built-in SITs (published by Microsoft Corporation):
These cannot be edited directly. To modify them, you must create a copy first.
Custom SITs (created in your tenant, e.g., Contoso):
These can be edited directly without making a copy.
Reference: Create a custom sensitive information type
Step 3 - Apply to the exhibit
"Adatum numbers" is published by Contoso (the organization), so it is a custom SIT. This means it can be edited directly.
All SITs, whether built-in or custom, can be copied to form a new SIT.


NEW QUESTION # 121
You have a Microsoft 565 subscription that contains 100 users and a Microsoft 365 group named Group1. All users have Windows 11 devices and use Microsoft SharePoint Online and Exchange Online. A sensitivity label named Label! is published as the default label for Group1. You add two sublabels named Sublabel1 and Sublabel2 lo Label1. You need to ensure that the settings in Sublabel 1 are applied by default to Group 1.
What should you do?

  • A. Modify the policy of Label1.
  • B. Delete the policy of Label1 and publish Sublabel1.
  • C. Duplicate all the settings from Sublabel! to Label1.
  • D. Change the order of Sublabel!

Answer: A

Explanation:
Step 1 - Scenario
Microsoft 365 E5 subscription with 100 users and a Microsoft 365 group (Group1).
A sensitivity label (Label1) is published as the default label for Group1.
Label1 contains two sublabels: Sublabel1 and Sublabel2.
Requirement: Ensure Sublabel1 settings are applied by default to Group1.
Step 2 - Understanding label hierarchy
In Microsoft Purview Information Protection, a parent label (Label1) is a container.
Sublabels (Sublabel1, Sublabel2) inherit the parent name but represent distinct configurations (encryption, watermarking, access, etc.).
A parent label itself cannot have a sublabel's settings automatically applied unless policy configuration specifies which sublabel is used as the default publishing option.
Step 3 - Why "Modify the policy of Label1" is correct
To apply Sublabel1 by default, the published policy for Label1 must be modified so that Sublabel1 is the default label within the policy.
Simply reordering sublabels (Option A) does not change the default assignment.
Duplicating Sublabel1's settings into Label1 (Option B) defeats the purpose of having sublabels and adds redundancy.
Deleting the policy of Label1 and publishing Sublabel1 (Option D) would remove flexibility and is unnecessary.
Step 4 - Microsoft Reference
Microsoft Docs: "If you want a sublabel to be applied by default, configure the label policy to select that sublabel as the default label for documents and emails."


NEW QUESTION # 122
You are reviewing policies for the SharePoint Online environment.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 123
You have 4 Microsoft 565 E5 subscription that contains two Microsoft SharePoint Online sites named Site1 and Site2. You plan to configure a retention label named Labe1 and apply label1 to all the files in Site1 You need to ensure that two years after a file is created in Site1. the file moves automatically to Site2. How should you configure the Choose what happens after the retention period setting for Label1?

  • A. Deactivate retention settings
  • B. Start a disposition review
  • C. Run a Power Automate flow
  • D. Change the label

Answer: C

Explanation:
You want files in Site1 that are labeled with Label1 to automatically move to Site2 two years after creation.
In Microsoft Purview Retention Labels, under "Choose what happens after the retention period", the available options are:
Deactivate retention settings - Ends retention but does not move files.
Start a disposition review - Sends items to reviewers for approval (manual process, not auto-move).
Change the label - Applies a new retention label (but does not move files to another site).
Run a Power Automate flow - Executes an automated workflow such as moving the file to another SharePoint library or site, notifying users, or applying custom business processes.
Since the requirement is automatic movement of files from Site1 to Site2 after 2 years, the only valid choice is Run a Power Automate flow.
Reference:
Microsoft Learn: Actions after a retention period for retention labels
Quote: "For retention labels, you can choose to trigger a Power Automate flow when the retention period


NEW QUESTION # 124
You have a Microsoft 365 ES subscription.
A security manager receives an email message every time a data loss prevention (DIP) policy match occurs.
You need to limit alert notifications to actionable DLP events. What should you do?

  • A. From the Microsoft Purview portal, modify the User overrides settings of a DLP policy.
  • B. From the Microsoft Purview portal, modify the Policy Tips settings of a DLP policy.
  • C. From the Microsoft Defender portal, apply a filter to the alerts.
  • D. From the Microsoft Purview portal, modify the matched activities threshold of an alert policy.

Answer: D

Explanation:
Step 1 - Understand the scenario
The security manager is receiving an email every time a Data Loss Prevention (DLP) policy match occurs.
The requirement is to reduce the number of unnecessary alerts and only notify for meaningful or actionable violations.
Step 2 - Analyze each option
A). From the Microsoft Defender portal, apply a filter to the alerts.
This action would only filter what is displayed in the portal. It does not prevent the security manager from receiving email notifications each time a DLP match occurs. This does not solve the problem.
B). From the Microsoft Purview portal, modify the Policy Tips settings of a DLP policy.
Policy Tips are intended for end users inside Outlook, Word, Excel, or PowerPoint to guide them about sensitive information before they send or share content. They do not change how or when admin alert notifications are triggered.
C). From the Microsoft Purview portal, modify the matched activities threshold of an alert policy.
DLP alert policies allow configuration of thresholds such as the number of matches, severity levels, and repeated activity counts. By adjusting the matched activities threshold, alerts can be generated only when a violation reaches a significant level, which reduces unnecessary alerts and ensures that notifications are sent only for actionable events. This matches the requirement.
D). From the Microsoft Purview portal, modify the User overrides settings of a DLP policy.
User override settings allow end users to bypass a DLP restriction if they provide a justification, but this does not impact the number of alert notifications sent to the security manager.
Step 3 - Microsoft Reference
According to Microsoft documentation: "You can configure alert policies with thresholds to reduce the number of alert notifications and focus only on actionable DLP events." Reference: DLP alert management in Microsoft Purview


NEW QUESTION # 125
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.
You need to ensure that you receive an alert when a user uploads a document to a third-party cloud storage service.
What should you use?

  • A. an insider risk policy
  • B. an activity policy
  • C. a file policy
  • D. a sensitivity label

Answer: C


NEW QUESTION # 126
HOTSPOT
You are reviewing policies for the SharePoint Online environment.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
A white paper with black text AI-generated content may be incorrect.

Understanding Site4's Retention Policies:
# Site4RetentionPolicy1 deletes items older than 2 years from creation. If a file was created on January 1,
2021, it would be deleted after January 1, 2023.
# Site4RetentionPolicy2 retains files for 4 years from creation. If a file was created on January 1, 2021, it will be kept until January 1, 2025, but not deleted after that (policy states "Do nothing").
Statement 1 - Yes, because Site4RetentionPolicy2 ensures files are retained for 4 years.
Statement 2 - Yes, because Site4RetentionPolicy2 retains the file for 4 years (until January 1, 2025).
Statement 3 - No, because retention is only for 4 years (until January 1, 2025). After that, the policy does
"nothing," meaning the file is no longer recoverable after that period.


NEW QUESTION # 127
......

Pass Guaranteed Quiz 2026 Realistic Verified Free Microsoft: https://exam-labs.exam4tests.com/SC-401-pdf-braindumps.html