[2025] Pass Key features of SC-401 Course with Updated 165 Questions
SC-401 Sample Practice Exam Questions 2025 Updated Verified
Microsoft SC-401 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
NEW QUESTION # 10
You have a Microsoft 365 E5 subscription that contains four users named User1. User2, User3, and User4 and a file named File1.docx. File1 has a sensitivity label applied. The label is configured as shown in the following table.
Which users can summarize File1 by using Microsoft 365 Copilot?
- A. User1 only
- B. User1, User2, User3. and User4
- C. User1, User2. and User3 only
- D. User1 and User2 only
Answer: D
NEW QUESTION # 11
You have a Microsoft 565 E5 tenant that uses Microsoft Teams and contains two users named User1 and User2. You create a data Joss prevention (DIP) policy that is applied to the Teams chat and channel messages location for User1 and User?
Which Teams entities will have DLP protection?
- A. 1:1/n chats, general channels, and private channels
- B. 1:1/n chats and general channels only
- C. 1:1/n chats and private channels only
Answer: A
Explanation:
When you configure Microsoft Purview DLP policies for the Teams chat and channel messages location, the following entities are protected:
1:1 and n:n chats (private chats between two or more users).
Team channel messages (including the General channel and all standard channels).
Private channel messages.
This means that if a DLP policy is applied to User1 and User2, it will monitor and enforce rules across:
Chats between User1 and User2 (1:1 or group chats).
Any channel conversations they participate in (General or other channels).
Private channels they belong to.
Incorrect options:
A (1:1/n chats and general channels only) # Excludes private channels, but DLP supports them.
B (1:1/n chats and private channels only) # Excludes general channels, but DLP supports them too.
Reference:
Microsoft Learn: Learn about data loss prevention in Microsoft Teams
Quote: "When DLP policies are applied to Teams chat and channel messages, they protect messages in 1:1 chats, group chats, channel messages (including private channels)."
NEW QUESTION # 12
You have a Microsoft 36S subscription that contains the sensitive information types (SITs) shown in the following exhibit.
Use the drop-down menus To select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct flection is worth one point.
Answer:
Explanation:
Explanation:
Step 1 - Understanding the scenario
The screenshot shows multiple Sensitive Information Types (SITs) in Microsoft Purview, including:
ABA Routing Number (Microsoft-built)
ASP.NET Machine Key (Microsoft-built)
Adatum document patterns (custom, Fingerprint type)
Adatum numbers (custom, Entity type)
Bundled SITs (like All Credential Types, All Full Names)
The question is asking:
Which SITs can you copy to create a new SIT?
Which SITs can you edit directly without copying?
Step 2 - Microsoft rules for SITs
Built-in SITs (published by Microsoft Corporation):
These cannot be edited directly. To modify them, you must create a copy first.
Custom SITs (created in your tenant, e.g., Contoso):
These can be edited directly without making a copy.
Reference: Create a custom sensitive information type
Step 3 - Apply to the exhibit
"Adatum numbers" is published by Contoso (the organization), so it is a custom SIT. This means it can be edited directly.
All SITs, whether built-in or custom, can be copied to form a new SIT.
NEW QUESTION # 13
You have a Microsoft 565 subscription that contains 100 users and a Microsoft 365 group named Group1. All users have Windows 11 devices and use Microsoft SharePoint Online and Exchange Online. A sensitivity label named Label! is published as the default label for Group1. You add two sublabels named Sublabel1 and Sublabel2 lo Label1. You need to ensure that the settings in Sublabel 1 are applied by default to Group 1.
What should you do?
- A. Delete the policy of Label1 and publish Sublabel1.
- B. Duplicate all the settings from Sublabel! to Label1.
- C. Change the order of Sublabel!
- D. Modify the policy of Label1.
Answer: D
Explanation:
Step 1 - Scenario
Microsoft 365 E5 subscription with 100 users and a Microsoft 365 group (Group1).
A sensitivity label (Label1) is published as the default label for Group1.
Label1 contains two sublabels: Sublabel1 and Sublabel2.
Requirement: Ensure Sublabel1 settings are applied by default to Group1.
Step 2 - Understanding label hierarchy
In Microsoft Purview Information Protection, a parent label (Label1) is a container.
Sublabels (Sublabel1, Sublabel2) inherit the parent name but represent distinct configurations (encryption, watermarking, access, etc.).
A parent label itself cannot have a sublabel's settings automatically applied unless policy configuration specifies which sublabel is used as the default publishing option.
Step 3 - Why "Modify the policy of Label1" is correct
To apply Sublabel1 by default, the published policy for Label1 must be modified so that Sublabel1 is the default label within the policy.
Simply reordering sublabels (Option A) does not change the default assignment.
Duplicating Sublabel1's settings into Label1 (Option B) defeats the purpose of having sublabels and adds redundancy.
Deleting the policy of Label1 and publishing Sublabel1 (Option D) would remove flexibility and is unnecessary.
Step 4 - Microsoft Reference
Microsoft Docs: "If you want a sublabel to be applied by default, configure the label policy to select that sublabel as the default label for documents and emails."
NEW QUESTION # 14
You implement Microsoft 36S Endpoint data loss pi event ion (Endpoint DIP).
You have computers that run Windows 11 and have Microsoft 365 Apps instated The computers are joined to a Microsoft Entra tenant.
You need to ensure that Endpoint DIP policies can protect content on the computers.
Solution: You onboard the computers to Microsoft Defender for Endpoint Does this meet the goal?
- A. No
- B. Yes
Answer: B
Explanation:
Microsoft Endpoint DLP relies on Microsoft Defender for Endpoint (MDE) for its enforcement.
Onboarding Windows 10/11 devices to Defender for Endpoint ensures the Endpoint DLP policies can be applied, including monitoring and protecting content across apps and browsers.
Reference: Overview of Endpoint DLP
NEW QUESTION # 15
You have a Microsoft 365 E5 tenant.
You need to add a new keyword dictionary.
What should you create?
- A. a sensitive info type
- B. a retention policy
- C. a trainable classifier
- D. a sensitivity label
Answer: A
Explanation:
To add a new keyword dictionary in Microsoft Purview Data Loss Prevention (DLP), you must create a Sensitive Information Type (SIT).
Sensitive Info Types (SITs) allow you to define custom detection rules, including keyword dictionaries, regular expressions, and functions for identifying sensitive content in emails, documents, and other Microsoft
365 locations. A keyword dictionary is a list of predefined words/phrases that Microsoft Purview can use to identify and classify content for DLP policies.
Steps to add a keyword dictionary:
1. Go to Microsoft Purview compliance portal
2. Navigate to Data classification > Sensitive info types
3. Create a new sensitive info type
4. Add a keyword dictionary
5. Save and use it in a DLP policy
NEW QUESTION # 16
You create a retention label policy named Contoso_Policy that contains the following labels:
* 10 years then delete
* 5 years then delete
* Do not retain
Contoso.Policy is applied to content in Microsoft SharePoint Online sites.
After a couple of days, you discover the following messages on the Properties page of the label policy:
* Status: Off (Error)
* It's taking longer than expected to deploy the policy
You need to reinitiate the policy.
How should you complete the command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 17
Your company has a Microsoft 365 tenant.
The company performs annual employee assessments. The assessment results are recorded in a document named AssessmentTemplate.docx that is created by using a Microsoft Word template. Copies of the employee assessments are sent to employees and their managers.
The assessment copies are stored in mailboxes, Microsoft SharePoint Online sites, and OneDrive folders. A copy of each assessment is also stored in a SharePoint Online folder named Assessments.
You need to create a data loss prevention (DLP) policy that prevents the employee assessments from being emailed to external users. You will use a document fingerprint to identify the assessment documents. The solution must minimize effort.
What should you include in the solution?
- A. Create a fingerprint of 100 sample documents in the Assessments folder.
- B. Create a fingerprint of AssessmentTemplate.docx.
- C. Create a sensitive info type that uses Exact Data Match (EDM).
- D. Import 100 sample documents from the Assessments folder to a seed folder.
Answer: B
Explanation:
Since all employee assessments follow a specific template (AssessmentTemplate.docx), the best way to identify these documents for Data Loss Prevention (DLP) is to create a document fingerprint of that template.
Document fingerprinting allows Microsoft 365 DLP policies to recognize documents based on their structure and format, even when content inside varies (such as different employee names and results). By creating a fingerprint of AssessmentTemplate.docx, any copy derived from that template will be automatically detected by the DLP policy and blocked from being emailed externally.
Steps to implement:
*Create a document fingerprint of AssessmentTemplate.docx using PowerShell and the Microsoft Purview compliance portal.
*Apply a DLP policy to prevent external sharing of documents matching this fingerprint.
*Test the policy by attempting to email an assessment externally.
NEW QUESTION # 18
Your company has offices in multiple countries.
The company has a Microsoft 365 E5 subscription that uses Microsoft Purview insider risk management.
You plan to perform the following actions:
*In a new country, open an office named Office1.
*Create a new user named User1.
*Deploy insider risk management to Office1.
*Add User1 to the Insider Risk Management Admins role group.
You need to ensure that User1 can perform insider risk management tasks for only the users and the devices in Office1.
What should you create first?
- A. a management group
- B. a dynamic user group
- C. an administrative unit
- D. a dynamic device group
Answer: C
NEW QUESTION # 19
HOTSPOT
You have a Microsoft 365 E5 subscription that contains the device configurations shown in the following table.
Each configuration uses either Google Chrome or Firefox as a default browser.
You need to implement Microsoft Purview and deploy the Microsoft Purview browser extension to the configurations.
To which configuration can each extension be deployed? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Microsoft Purview browser extensions for Endpoint DLP are supported on:
# Windows 10/11 (Config1)
# macOS (Config2)
# Not supported on Android (Config3)
Since Microsoft Purview does not support browser extensions on Android, Config3 is excluded from both Google Chrome and Firefox.
NEW QUESTION # 20
You have a Microsoft 365 E5 tenant.
You have sensitivity labels as shown in the Sensitivity Labels exhibit. (Click the Sensitivity Labels tab.)
The Confidential/External sensitivity label is configured to encrypt files and emails when applied to content.
The sensitivity labels ate published as shown in the Published exhibit. (Click the Published tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 21
You have a Microsoft 365 ES subscription that uses Microsoft Teams and contains the users shown in the following table.
You have the retention policies shown in the following table.
The users perform the actions shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point
Answer:
Explanation:
Explanation:
Let's analyze each scenario based on the given retention policies and Microsoft 365 documentation.
# Policies Recap
Policy1
Teams channel messages # All Teams # Retain 7 years # Delete automatically.
Teams chats # User1 # Retain 7 years # Delete automatically.
Policy2
Teams channel messages # Team1 # Retain 5 years # Delete automatically.
Teams chats # User2 # Retain 5 years # Delete automatically.
# Reference: Retention policies in Microsoft Teams
# Statement 1: The message edited by User1 will be deleted after five years.
Location = Team1 channel.
Policy1 applies (7 years for all Teams).
Policy2 applies (5 years for Team1).
Conflict rule: For retention, the longest duration wins.
Therefore, the message stays 7 years, not 5.
# Answer: NO
# Statement 2: User1 can see the message sent by User2 for up to seven years.
Location = Private 1:1 chat (User2 # User1).
For User1's mailbox: Policy1 applies (7 years).
For User2's mailbox: Policy2 applies (5 years).
Retention in Teams chats is per-user, so each participant may have different durations.
For User1, the retention is 7 years.
# Answer: YES
# Statement 3: The message deleted by User1 will be moved to the SubstrateHolds folder.
Location = Team2 channel.
User1 deletes the message, but retention policy (Policy1) applies (7 years).
Retention overrides user deletion: message is moved to the SubstrateHolds folder in the hidden mailbox for preservation.
# Reference: How retention works with SubstrateHolds
# Answer: YES
NEW QUESTION # 22
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You recently discovered that the developers at your company emailed Azure Storage Account keys in plain text to third parties.
You need to ensure that when Azure Storage Account keys are emailed, the emails are encrypted.
Solution: You create a data loss prevention (DLP) policy that has only the Exchange email location selected.
Does this meet the goal?
- A. No
- B. Yes
Answer: B
Explanation:
To ensure Azure Storage Account keys are encrypted when sent via email, you need a Data Loss Prevention (DLP) policy that detects Azure Storage Account keys using a sensitive information type and automatically encrypts emails containing these keys.
A DLP policy with Exchange email as the only location meets this requirement because it identifies sensitive data in email messages and it applies protection actions, such as encryption, blocking, or alerts.
NEW QUESTION # 23
You have a Microsoft 365 ES subscription that uses Microsoft Teams and contains the users shown in the following table.
You have the retention policies shown in the following table.
The users perform the actions shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point
Answer:
Explanation:
Explanation:
NEW QUESTION # 24
You have a Microsoft 36S ES subscription
You plan to create an met data match (EDM) classifier named EDM1.
You need to grant permissions to hash and upload the sensitive ^formation source table for EDMI. What should you create first?
- A. a security group named EDM.DataUploaders
- B. a Microsoft Entra enterprise application named EDM.DataUploaders
- C. a Microsoft Purview role group named EDM.DataUploaders
- D. a Microsoft 365 group named EDM.Datauploaders
- E. a Microsoft Entra app registration named EDM.DataUploaders
Answer: A
Explanation:
Step 1 - Scenario
You are creating an Exact Data Match (EDM) classifier in Microsoft Purview.
EDM requires preparing a sensitive information source table (such as employee IDs, customer account numbers).
This table must be hashed and uploaded into Microsoft Purview.
Only authorized users can perform this sensitive upload operation.
Step 2 - Required permissions for EDM upload
Microsoft's documented process states:
To hash and upload EDM source data, you must assign users to the EDM Data Uploaders security group.
This group is a security group created in Microsoft Entra ID (formerly Azure AD).
Membership in this security group grants permission to perform the upload.
# Reference: Configure Exact Data Match (EDM) in Microsoft Purview
"To upload the hashed data file to Microsoft Purview, you must add users to a security group named EDM_DataUploaders. This group is required to give permissions for EDM uploads." Step 3 - Why not the other options?
A). Microsoft Entra enterprise application # Used for app integration, not EDM uploads.
B). Purview role group # Provides compliance portal permissions but not EDM upload rights.
D). Microsoft Entra app registration # Used for API access, not relevant here.
E). Microsoft 365 group # Collaboration group, not for secure upload rights.
NEW QUESTION # 25
You need to be alerted when users share sensitive documents from Microsoft OneDrive to any users outside your company.
What should you do?
- A. From the Microsoft Defender portal create a file policy
- B. From the Microsoft Purview portal, start a data investigation.
- C. From the Microsoft Defender portal, create an activity policy.
- D. From the Microsoft Purview portal create an insider risk policy
Answer: A
Explanation:
An activity policy in Microsoft Defender for Cloud Apps (Microsoft Defender portal) allows you to track and alert on specific user actions, such as sharing sensitive documents externally from OneDrive. This policy can detect file-sharing activities and send alerts when files are shared with external users, which meets the requirement.
NEW QUESTION # 26
You are creating a custom trainable classifier to Identify organizational product codes referenced in Microsoft
36S content. You identify 300 files to use as seed content When? should you store the seed content?
- A. a Microsoft SharePoint Online folder
- B. an Azure file share
- C. a Microsoft OneDrive folder
- D. a Microsoft Exchange Online shared mailbox
Answer: A
Explanation:
For creating a custom trainable classifier, seed content must be stored in a Microsoft 365 content location that Purview can crawl for training-SharePoint Online (or Exchange mailboxes). OneDrive, Azure Files, or other locations are not supported for training seed sets.
Reference: Microsoft Learn - Trainable classifiers in Microsoft Purview # seed content is uploaded to SharePoint Online or Exchange Online.
https://learn.microsoft.com/microsoft-365/compliance/classifier-get-started-with
NEW QUESTION # 27
You have a Microsoft 365 E5 subscription.
You need to ensure that encrypted email messages sent to an external recipient can be revoked or will expire within seven days.
What should you configure first?
- A. a Conditional Access policy
- B. a custom branding template
- C. a mail flow rule
- D. a sensitivity label
Answer: B
Explanation:
To ensure that encrypted email messages sent to external recipients can be revoked or expire within seven days, you need to configure a sensitivity label with encryption settings in Microsoft Purview Information Protection. A sensitivity label allows you to encrypt emails and documents, set expiration policies (e.g., emails expire after 7 days), and enable email revocation How to configure it?
# Go to Microsoft Purview compliance portal # Information Protection
# Create a sensitivity label
# Enable encryption and configure the content expiration policy
# Publish the label to users
NEW QUESTION # 28
You have a Microsoft 365 sensitivity label that is published to all the users in your Microsoft Entra tenant as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Answer:
Explanation:
Explanation:
Statement 1 - No. The sensitivity label includes content marking (watermark: INTERNAL), but it only applies to documents where the label is manually or automatically applied, not to all documents by default.
Statement 2 - No. The sensitivity label only specifies a watermark, not a header. If a header marking was configured, it would explicitly appear in the label settings.
Statement 3 - No. There is no indication that auto-labeling is configured to apply the label only to documents with the word "rebranding". Auto-labeling is an optional setting that needs explicit configuration.
NEW QUESTION # 29
You have a Microsoft 365 tenant that uses Microsoft Purview Message Encryption.
You need to ensure that any emails containing attachments and sent to [email protected] are encrypted automatically by using Microsoft Purview Message Encryption.
What should you do?
- A. From the Microsoft Defender portal, create a Safe Attachments policy.
- B. From the Exchange admin center, create a new sharing policy.
- C. From the Microsoft Purview portal, configure an auto-apply retention label policy.
- D. From the Exchange admin center, create a mail flow rule.
Answer: D
NEW QUESTION # 30
You have a Microsoft 365 ES subscription.
A security manager receives an email message every time a data loss prevention (DIP) policy match occurs.
You need to limit alert notifications to actionable DLP events. What should you do?
- A. From the Microsoft Purview portal, modify the Policy Tips settings of a DLP policy.
- B. From the Microsoft Purview portal, modify the matched activities threshold of an alert policy.
- C. From the Microsoft Defender portal, apply a filter to the alerts.
- D. From the Microsoft Purview portal, modify the User overrides settings of a DLP policy.
Answer: B
NEW QUESTION # 31
You have a Microsoft 36S ES subscription.
You need to create the Microsoft Purview insider risk management policies shown in the following table.
Which policy template should you use for each policy? To answer, drag the appropriate policy templates to the correct polices Each template may be used once more than once or not at all. You may need to drag the split bar between panes or scroll to view..
Answer:
Explanation:
Explanation:
NEW QUESTION # 32
You are implementing Microsoft Purview Advanced Message Encryption for a Microsoft 365 tenant named contoso.com You need to meet the following requirements:
* All email to a domain named (abrikam.com must be encrypted automatically.
* Encrypted emails must expire seven days after they are sent
What should you configure for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 33
You have a Microsoft 365 E5 subscription.
Users access their mailbox by using the following apps.
* Outlook for Microsoft 365
* Outlook on the web
* Outlook Mobile fiOS. Android)
You create a data loss prevention (DLP) policy named DLP1 that has the following settings:
* Location; Exchange email
* Status: On
* User notifications: On
* Notify users with a policy tip: Enabled
Which apps display a policy tip when content is matched by using DIP1 ?
- A. Outlook for Microsoft 365. Outlook on the web, and Outlook Mobile (iOS. Android)
- B. Outlook for Microsoft 365 and Outlook Mobile (iOS. Android) only
- C. Outlook on the web only
- D. Outlook for Microsoft 365 and Outlook on the web only
- E. Outlook for Microsoft 365 only
Answer: D
NEW QUESTION # 34
......
The New SC-401 2025 Updated Verified Study Guides & Best Courses: https://www.dumpsking.com/SC-401-testking-dumps.html
Exam Study Guide Free Practice Test LAST UPDATED : https://drive.google.com/open?id=1uNYIKMNUPCEcLQGgyq63S311PRjm_CBf
