(2026) PASS SC-401 Exam Free Practice Test with 100% Accurate Answers [Q135-Q153]

Share

(2026) PASS SC-401 Exam Free Practice Test with 100% Accurate Answers

SC-401 dumps Free Test Engine Verified By It Certified Experts

NEW QUESTION # 135
You have a Microsoft 365 E5 subscription that contains a Microsoft Teams channel named Channel1. Channel1 contains research and development documents.
You plan to implement Microsoft 365 Copilot for the subscription.
You need to prevent the contents of files stored in Channel1 from being included in answers generated by Copilot and shown to unauthorized users.
What should you use?

  • A. Microsoft Purview insider risk management
  • B. sensitivity labels
  • C. Microsoft Purview Information Barriers (IBs)
  • D. data loss prevention (DLP)

Answer: B

Explanation:
To prevent the contents of files stored in Channel1 from being included in Microsoft 365 Copilot responses and ensure unauthorized users cannot access them, you should use Microsoft Purview Sensitivity Labels.
Sensitivity labels allow you to classify, protect, and restrict access to sensitive files. You can configure label-based encryption and access control policies to ensure that only authorized users can access or interact with the files in Channel1. Microsoft 365 Copilot respects sensitivity labels, meaning if a file is labeled with restricted permissions, Copilot will not use it in generated responses for unauthorized users.


NEW QUESTION # 136
You have a Microsoft 365 E5 subscription that contains the resources shown in the following table.

You have a retention label configured as shown in the following exhibit.

You publish the retention label and set the scope as shown in the following exhibit.

You apply the label to the resources.
Which items can you delete?

  • A. Mail1 and File2.xlsx only
  • B. Mail1 only
  • C. Mail1 and File1.docx only
  • D. Mail1, File1.docx, and File2.xlsx
  • E. File1.docx and File2.xlsx only

Answer: D

Explanation:
In the exhibit we see:
During the retention period
* Retain items even if users delete
Choose locations
* All locations. Includes content in Exchange email, Office 365 Groups, OneDrive and SharePoint documents.


NEW QUESTION # 137
HOTSPOT
You have a Microsoft 365 E5 subscription that has data loss prevention (DLP) implemented.
You plan to export DLP activity by using Activity explorer.
The exported file needs to display the sensitive info type detected for each DLP rule match.
What should you do in Activity explorer before exporting the data, and in which file format is the file exported? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: To include the sensitive info type detected for each DLP rule match, you need to add a custom column in Activity Explorer. This ensures that the exported file contains specific details about the detected sensitive information types.
Box 2: DLP activity exports from Activity Explorer are always in CSV (Comma-Separated Values) format.
This format allows for easy data analysis and reporting in Excel or other data-processing tools.


NEW QUESTION # 138
You have a Microsoft 365 E5 subscription that uses Microsoft Purview.
You create a sensitive information type (SIT) named SIT1.
You plan to create the communication compliance polices shown in the following table.

To which policies can you add SIT1 as a condition?

  • A. Policy1 only
  • B. Policy3 only
  • C. Policy1 and Policy2 only
  • D. Policy1 and Policy3 only
  • E. Policy1, Policy 2, and Policy3

Answer: D


NEW QUESTION # 139
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. Site1 contains the files shown in the following table.

In the Microsoft Purview portal, you create a content search named Content1 and configure the search conditions as shown in the following exhibit.

Which files will be returned by Content1?

  • A. File1.docx and File2.docx only
  • B. File2.docx only
  • C. Filet.docx, File2.docx, and File3.docx
  • D. File1.docx and File3.docx only
  • E. File3.docx only

Answer: D

Explanation:
Microsoft Purview, Keyword queries and search conditions for eDiscovery Values aren't case-sensitive. Both User1 (File1.docx) and USER1 (File3.docx) will match the Search condition -Author:USER1.
Reference:
https://learn.microsoft.com/en-us/purview/ediscovery-keyword-queries-and-search-conditions


NEW QUESTION # 140
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.
You need to ensure that you receive an alert when a user uploads a document to a third-party cloud storage service.
What should you use?

  • A. an activity policy
  • B. a file policy
  • C. an insider risk policy
  • D. a sensitivity label

Answer: B

Explanation:
Reference:
https://learn.microsoft.com/en-us/defender-cloud-apps/data-protection-policies
https://learn.microsoft.com/en-us/defender-cloud-apps/policies-information-protection


NEW QUESTION # 141
You have a Microsoft 365 tenant that uses Microsoft Purview Message Encryption.
You need to ensure that any emails containing attachments and sent to [email protected] are encrypted automatically by using Microsoft Purview Message Encryption.
What should you do?

  • A. From the Exchange admin center, create a mail flow rule.
  • B. From the Microsoft Defender portal, create a Safe Attachments policy.
  • C. From the Microsoft Purview portal, configure an auto-apply retention label policy.
  • D. From the Exchange admin center, create a new sharing policy.

Answer: A


NEW QUESTION # 142
Hotspot Question
You have a Microsoft 365 E5 tenant that contains a trainable classifier named Classifier1.
You need to increase the accuracy of Classifier1. The solution must use the principle of least privilege.
Which feature should you use and to which role group should you be added? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Content Explorer
Increase classifier accuracy
Classifiers, like sensitive information types (SIT) and trainable classifiers are used in various kinds of policies to identify sensitive information. Like most such models, sometimes they identify an item as being sensitive that isn't. Or, they may not identify an item as being sensitive when it actually is. These are called false positives and false negatives.
Box 2: Compliance data administrator
Permissions
In order to get access to the content explorer tab, an account must be assigned membership in any one of these roles or role groups.
Microsoft 365 role groups
Global administrator
Compliance administrator
Security administrator
*-> Compliance data administrator
Reference:
https://learn.microsoft.com/en-us/microsoft-365/compliance/data-classification-increase-accuracy
https://learn.microsoft.com/en-us/microsoft-365/compliance/data-classification-content-explorer


NEW QUESTION # 143
Hotspot Question
You have a Microsoft 365 E5 subscription that contains two Windows devices named Device1 and Device2. Device1 has the default browser set to Microsoft Edge. Device2 has the default browser set to Google Chrome.
You need to ensure that Microsoft Purview insider risk management can collect signals when a user copies files to a USB device by using their default browser.
What should you deploy to each device? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: The Microsoft Purview Information protection client
Device1 has the default browser set to Microsoft Edge.
The Microsoft Purview Information Protection client, now integrated with Microsoft Edge, enables organizations to apply data security policies and protect sensitive information within the browser.
Specifically, Microsoft Purview Information Protection features like sensitivity labels and data loss prevention (DLP) can be leveraged in Edge for Business to control access and usage of sensitive documents and data.
Box 2: Microsoft Purview extension
Device2 has the default browser set to Google Chrome.
After the installation of the Microsoft Purview extension for Google Chrome, on Windows devices, organizations get the ability to also monitor attempts to access or upload sensitive items to a Cloud service when using the Google Chrome browser, and to actually enforce protective actions via data loss prevention.
The Microsoft Purview extension is used with Google Chrome, but it's not required for Microsoft Edge because Edge has built-in Endpoint DLP capabilities. The extension enhances data loss prevention for non-native applications, particularly for Chrome and other browsers where DLP needs to be explicitly extended.
Reference:
https://learn.microsoft.com/en-us/purview/dlp-chrome-get-started


NEW QUESTION # 144
You have a Microsoft 565 E5 tenant that uses Microsoft Teams and contains two users named User1 and User2. You create a data Joss prevention (DIP) policy that is applied to the Teams chat and channel messages location for User1 and User?
Which Teams entities will have DLP protection?

  • A. 1:1/n chats, general channels, and private channels
  • B. 1:1/n chats and private channels only
  • C. 1:1/n chats and general channels only

Answer: A

Explanation:
When you configure Microsoft Purview DLP policies for the Teams chat and channel messages location, the following entities are protected:
1:1 and n:n chats (private chats between two or more users).
Team channel messages (including the General channel and all standard channels).
Private channel messages.
This means that if a DLP policy is applied to User1 and User2, it will monitor and enforce rules across:
Chats between User1 and User2 (1:1 or group chats).
Any channel conversations they participate in (General or other channels).
Private channels they belong to.
Incorrect options:
A (1:1/n chats and general channels only) # Excludes private channels, but DLP supports them.
B (1:1/n chats and private channels only) # Excludes general channels, but DLP supports them too.
Reference:
Microsoft Learn: Learn about data loss prevention in Microsoft Teams
Quote: "When DLP policies are applied to Teams chat and channel messages, they protect messages in 1:1 chats, group chats, channel messages (including private channels)."


NEW QUESTION # 145
You have a data loss prevention (DIP) policy that has the advanced DIP rules shown in the following table.

You need to identity which rules will apply when content matches multiple advanced DIP rules.
Which rules should you identify? To answer, select the appropriate options in the answer area.

Answer:

Explanation:

Explanation:


NEW QUESTION # 146
You have a Microsoft 365 tenant that uses Microsoft Purview Message Encryption.
You need to ensure that any emails containing attachments and sent to [email protected] are encrypted automatically by using Microsoft Purview Message Encryption.
What should you do?

  • A. From the Exchange admin center, create a mail flow rule.
  • B. From the Microsoft Defender portal, create a Safe Attachments policy.
  • C. From the Microsoft Purview portal, configure an auto-apply retention label policy.
  • D. From the Exchange admin center, create a new sharing policy.

Answer: A

Explanation:
To automatically encrypt email messages using Microsoft Purview Message Encryption (OME), administrators must configure mail flow rules (also known as transport rules) in the Exchange admin center.
These rules can be configured to check conditions, such as when a recipient is a specific user or when an email contains attachments, and then apply encryption automatically. Sharing policies, Safe Attachments policies, and retention label policies are not used for OME encryption.
Reference: Define mail flow rules to encrypt email messages


NEW QUESTION # 147
You have a data loss prevention (DLP) policy configured for endpoints as shown in the following exhibit.

From a computer named Computer1, a user can sometimes upload files to cloud services and sometimes cannot. Other users experience the same issue.
What are two possible causes of the issue? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  • A. The computers are NOT onboarded to Microsoft Purview.
  • B. There are file path exclusions in the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings.
  • C. The Access by restricted apps action is set to Audit only.
  • D. The Copy to clipboard action is set to Audit only.
  • E. The unallowed browsers in the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings are NOT configured.

Answer: B,E

Explanation:
The issue where users sometimes can upload files to cloud services and sometimes cannot suggests inconsistent enforcement of Endpoint DLP policies. This can be caused by the unallowed browsers in the Microsoft 365 Endpoint DLP settings are NOT configured. Also, there are file path exclusions in the Microsoft 365 Endpoint DLP settings.
Endpoint DLP can block uploads only when using unallowed browsers. If unallowed browsers are not configured, users might be able to bypass restrictions by switching to a different browser. This could explain why uploads sometimes work and sometimes don't, depending on which browser is used.
File path exclusions allow certain files or folders to be exempt from DLP restrictions. If a specific file location is excluded, files stored there won't trigger DLP policies, leading to inconsistent behavior. This could result in some uploads being blocked while others are allowed.


NEW QUESTION # 148
You have a Microsoft 36S subscription that contains the sensitive information types (SITs) shown in the following exhibit.

Use the drop-down menus To select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct flection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 149
You have a Microsoft 365 E5 subscription.
You need to implement a compliance solution that meets the following requirements:
*Captures clips of key security-related user activities, such as the exfiltration of sensitive company data.
*Integrates data loss prevention (DLP) capabilities with insider risk management.
What should you use for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 150
XYZ firm handles sensitive legal and financial data, and you need to design Data Loss Prevention (DLP) policies to prevent unauthorized sharing and leakage. What is the first step in designing an effective DLP policy for your organization?

  • A. Enable auditing for all users
  • B. Block external sharing across the board
  • C. Configure retention policies
  • D. Analyze the types of sensitive data your organization handlesright

Answer: D

Explanation:
The first step in designing a DLP (Data Loss Prevention) policy for your organization is to analyze the types of sensitive data your organization handles. Understanding what sensitive data exists and where it is located is crucial for creating effective DLP policies tailored to your organization's specific needs.
References:
https://learn.microsoft.com/en-us/purview/dlp-policy-design
https://learn.microsoft.com/en-us/purview/dlp-create-deploy-policy?tabs=purview


NEW QUESTION # 151
HOTSPOT
You have a Microsoft 365 E5 subscription.
You need to implement a compliance solution that meets the following requirements:
# Captures clips of key security-related user activities, such as the exfiltration of sensitive company data.
# Integrates data loss prevention (DLP) capabilities with insider risk management.
What should you use for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 152
You have Microsoft 365 E5 tenant that has a domain name of 86s40q.ofimicrosoft.com. The tenant contains the users shown in the following table.

You have a published sensitivity label.
The Access control settings for the sensitivity label are configured as shown in the exhibit (Click the Exhibit tab.)

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Answer:

Explanation:

Explanation:

Comprehensive Detailed Explanation with References
We are given a sensitivity label with the following Access control settings:
Assign permissions now # meaning admins define permissions, not end users.
User access to content expires = Never.
Allow offline access = Always.
Permissions explicitly assigned:
LegalTeam@... # Co-Author
USSales@... # Reviewer
Dynamic watermarking and Double Key Encryption are not enabled.
Reference: Restrict access to content with sensitivity labels
Statement 1: Only users at your company can view an email that has the sensitivity label applied.
False, because permissions are explicitly assigned to two groups (LegalTeam, USSales).
If any external users were added, they would also get access. The configuration does not inherently restrict to only internal users.
The answer: NO
Statement 2: The owner of an email can assign permissions when applying the sensitivity label.
False, because the sensitivity label was configured with "Assign permissions now".
This means permissions are fixed by admins and cannot be modified by the email sender.
If "Let users assign permissions" was enabled, this would be YES.
The answerr: NO
# Statement 3: [email protected]
can print an email that has the sensitivity label applied.
USSales group has the Reviewer role.
Reviewer = Can view, read, and save, but cannot print, copy, or export.
Reference: Usage rights and role mapping for sensitivity labels
The answer: NO


NEW QUESTION # 153
......


Microsoft SC-401 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Manage Risks, Alerts, and Activities: This section assesses Security Operations Analysts on insider risk management, monitoring alerts, and investigating security activities. It covers configuring risk policies, handling forensic evidence, and responding to alerts using Microsoft Purview and Defender tools. Candidates must also analyze audit logs and manage security workflows.
Topic 2
  • Implement Data Loss Prevention and Retention: This section evaluates Data Protection Officers on designing and managing data loss prevention (DLP) policies and retention strategies. It includes setting policies for data security, configuring Endpoint DLP, and managing retention labels and policies. Candidates must understand adaptive scopes, policy precedence, and data recovery within Microsoft 365.
Topic 3
  • Implement Information Protection: This section measures the skills of Information Security Analysts in classifying and protecting data. It covers identifying and managing sensitive information, creating and applying sensitivity labels, and implementing protection for Windows, file shares, and Exchange. Candidates must also configure document fingerprinting, trainable classifiers, and encryption strategies using Microsoft Purview.
Topic 4
  • Protect Data Used by AI Services: This section evaluates AI Governance Specialists on securing data in AI-driven environments. It includes implementing controls for Microsoft Purview, configuring Data Security Posture Management (DSPM) for AI, and monitoring AI-related security risks to ensure compliance and protection.

 

Latest Microsoft SC-401 Practice Test Questions: https://torrentpdf.validvce.com/SC-401-exam-collection.html