[Jun 22, 2026] Pass Your SC-401 Dumps Free Latest Microsoft Practice Tests [Q45-Q70]

Share

[Jun 22, 2026] Pass Your SC-401 Dumps Free Latest Microsoft Practice Tests

Get Top-Rated Microsoft SC-401 Exam Dumps Now


Microsoft SC-401 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Implement Data Loss Prevention and Retention: This section evaluates Data Protection Officers on designing and managing data loss prevention (DLP) policies and retention strategies. It includes setting policies for data security, configuring Endpoint DLP, and managing retention labels and policies. Candidates must understand adaptive scopes, policy precedence, and data recovery within Microsoft 365.
Topic 2
  • Protect Data Used by AI Services: This section evaluates AI Governance Specialists on securing data in AI-driven environments. It includes implementing controls for Microsoft Purview, configuring Data Security Posture Management (DSPM) for AI, and monitoring AI-related security risks to ensure compliance and protection.
Topic 3
  • Implement Information Protection: This section measures the skills of Information Security Analysts in classifying and protecting data. It covers identifying and managing sensitive information, creating and applying sensitivity labels, and implementing protection for Windows, file shares, and Exchange. Candidates must also configure document fingerprinting, trainable classifiers, and encryption strategies using Microsoft Purview.
Topic 4
  • Manage Risks, Alerts, and Activities: This section assesses Security Operations Analysts on insider risk management, monitoring alerts, and investigating security activities. It covers configuring risk policies, handling forensic evidence, and responding to alerts using Microsoft Purview and Defender tools. Candidates must also analyze audit logs and manage security workflows.

 

NEW QUESTION # 45
You have a Microsoft 365 tenant that is opt-in for trainable classifiers.
You need to ensure that a user named User1 can create custom trainable classifiers. The solution must use the principle of least privilege.
Which role should you assign to User1?

  • A. Compliance Administrator
  • B. Global Administrator
  • C. Security Operator
  • D. Security Administrator

Answer: A

Explanation:
To create custom trainable classifiers in Microsoft Purview, the user must have rights in the compliance portal. The Compliance Administrator role provides the necessary permissions to create and manage trainable classifiers. Security roles focus on threat management, and Global Administrator is excessive (not least privilege).
Reference: Trainable classifiers in Microsoft Purview


NEW QUESTION # 46
You implement Microsoft 36S Endpoint data loss pi event ion (Endpoint DIP).
You have computer that run Windows 11 and have Microsoft 365 Apps instated The computers are joined to a Microsoft Entra tenant You need to ensure that endpoint DIP policies can protect content on the computers.
Solution: You deploy the Microsoft Purview Information Protection client to the computers.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

Explanation:
Step 1 - Scenario
Endpoint Data Loss Prevention (Endpoint DLP) is implemented in Microsoft 365.
Computers: Windows 11, joined to Microsoft Entra (Azure AD), with Microsoft 365 Apps installed.
Goal: Ensure Endpoint DLP policies can protect local content on these devices.
Step 2 - How Endpoint DLP works
Endpoint DLP builds on the same policy framework as Microsoft Purview DLP, but specifically extends coverage to Windows 10/11 devices.
Requirements:
Devices must be onboarded to Microsoft Purview (via Microsoft Defender for Endpoint or via Purview device onboarding).
Endpoint DLP does not require the Microsoft Purview Information Protection (MIP) client.
The MIP client is only required for sensitivity labeling and AIP functionality, not for Endpoint DLP.
Step 3 - Why the proposed solution is incorrect
Deploying the Microsoft Purview Information Protection client does not enable Endpoint DLP.
Endpoint DLP requires device onboarding into Microsoft Purview compliance.
Therefore, this solution does not meet the goal.
Step 4 - Microsoft Reference
Microsoft Docs states:
"To use Endpoint data loss prevention (Endpoint DLP), devices must be onboarded to the Microsoft Purview compliance portal. Installing the Microsoft Information Protection client is not required." Reference: Get started with Endpoint DLP Final Answer No - deploying the Microsoft Purview Information Protection client alone does not meet the goal.
Would you like me to also provide the correct solution (the exact steps required to onboard devices for Endpoint DLP protection)?


NEW QUESTION # 47
You have Microsoft 365 E5 tenant that uses Microsoft Teams and contains two users named User1 and User2.
You create a data loss prevention (DLP) policy that is applied to the Teams chat and channel messages location for User1 and User2.
Which Teams entities will have DLP protection?

  • A. 1:1/n chats, general channels, and private channels
  • B. 1:1/n chats and general channels only
  • C. 1:1/n chats and private channels only

Answer: C

Explanation:
Scope of DLP protection
DLP protection is applied differently to Teams entities.
Reference:
https://learn.microsoft.com/en-us/microsoft-365/compliance/dlp-microsoft-teams


NEW QUESTION # 48
You have a Microsoft 365 subscription that contains the devices shown in the following table.

From which devices can Microsoft Purview Insider Risk Management capture forensic evidence?

  • A. Device1 and Device2 only
  • B. Device2 only
  • C. Device2 and Device3 only
  • D. Device1, Device2 and Device3
  • E. Device only

Answer: B

Explanation:
Forensic evidence in Microsoft Purview Insider Risk Management allows capturing screenshots/clips of user activity on endpoints.
Requirements for forensic evidence capture:
The device must be onboarded to Microsoft Purview (via Defender for Endpoint).
The Microsoft Purview client must be installed.
Supported platforms: Windows 10 and Windows 11 (macOS is not supported for forensic evidence).
Now check each device:
Device1 (Windows 11) # Client installed, but not onboarded # # Not eligible.
Device2 (Windows 10) # Onboarded and client installed # # Eligible.
Device3 (macOS) # Onboarded, but client not installed and macOS is not supported # # Not eligible.
Therefore, only Device2 qualifies.
Reference:
Microsoft Learn: Forensic evidence in insider risk management
Microsoft Learn: Onboard devices for insider risk management forensic evidence


NEW QUESTION # 49
Hotspot Question
You have a Microsoft 365 E5 tenant that contains the users shown in the following table.

You need to implement sensitivity labels.
Which users can create sensitivity labels, and which portal should the users use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Reference:
https://learn.microsoft.com/en-us/purview/get-started-with-sensitivity-labels
https://learn.microsoft.com/en-us/purview/create-sensitivity-labels


NEW QUESTION # 50
You have a Microsoft 365 E5 subscription that contains a data loss prevention (DLP) policy named DLP1. DLP1 contains the DLP rules shown in the table.

You need to ensure that when a document matches all the rules, users will see Tip 2.
What should you change?

  • A. the if there's a match for this rule, stop processing additional DLP policies and rules setting for Rule3 to Enabled
  • B. the priority setting of Rule3 and Rule4 to 0
  • C. the priority setting of Rule2 to 0
  • D. the priority setting of Rule2 to 2

Answer: C

Explanation:
Make Rule2 have the highest priority, lowest value of 0, to ensure it will be processed.
Note: The Priority parameter specifies a priority value for the policy that determines the order of policy processing. A lower integer value indicates a higher priority, the value 0 is the highest priority.
Reference:
https://techcommunity.microsoft.com/discussions/microsoft-365/dlp-policy-order/2197427


NEW QUESTION # 51
You have a Microsoft 365 subscription.
You need to ensure that users can apply retention labels to individual documents in their Microsoft SharePoint libraries.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. From the SharePoint admin center, modify the Site Settings.
  • B. From the Microsoft Purview portal, create a label.
  • C. From Microsoft Defender for Cloud Apps, create a file policy.
  • D. From the SharePoint ad min center, modify the records management settings.
  • E. From the Microsoft Purview portal, publish a label.

Answer: B,E

Explanation:
To allow users to apply retention labels to individual documents in Microsoft SharePoint libraries, you need to create a retention label and publish the label.
In Microsoft Purview, retention labels define how long content should be retained or deleted. You must first create a label that specifies the retention rules. After creating the label, you must publish it so that it becomes available for users in SharePoint document libraries. Once published, users can manually apply the retention label to individual documents.


NEW QUESTION # 52
HOTSPOT
You have a Microsoft SharePoint Online site that contains the following files.

Users are assigned roles for the site as shown in the following table.

Which files can User1 and User2 open? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

Let's break it down:
File1.docx # DLP action = None
No DLP restrictions, so it is fully accessible to both User1 (owner) and User2 (member).
File2.docx # DLP action = Matched by DLP
"Matched" means the DLP policy detected sensitive content but has not blocked access. Instead, it may generate an alert or policy tip.
Both User1 and User2 can still open this file.
File3.docx # DLP action = Blocked by DLP
"Blocked" means the DLP policy actively restricts access or sharing of the file.
User2 (member) cannot open this file.
However, User1 (site owner) can open it because site collection admins and owners always retain full control over content, even if a DLP rule applies.
Ref: Microsoft Purview DLP policy tips and enforcement
# DLP policies do not prevent SharePoint/OneDrive site collection admins (owners) from accessing content.
# Final Answer Table:
User1 (Site Owner): File1.docx, File2.docx, File3.docx
User2 (Site Member): File1.docx, File2.docx


NEW QUESTION # 53
You have a Microsoft 365 E5 subscription.
You need to identify documents that contain patent application numbers containing the letters PA followed by eight digits, for example, PA 12345678. The solution must minimize administrative effort.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

Box 1: Since you are looking for a specific pattern (PA followed by eight digits, e.g., PA 12345678), the best classification method is Sensitive Info Type. Sensitive Info Types allow pattern-based matching to identify structured data. Exact Data Match (EDM) is not needed because you're not comparing against a fixed dataset.
Trainable classifier is not appropriate because this is a structured pattern, not an unstructured document classification.
Box 2: Since PA 12345678 follows a structured pattern, the most effective method is Regular Expression (Regex). A Regular Expression (Regex) can be written to match "PA" followed by exactly eight digits (e.g., PA\s\d{8}). Keyword dictionary is not ideal because it works for predefined words, not number patterns.
Function is unnecessary because there is no need for checksum validation or predefined validation rules.


NEW QUESTION # 54
You have a Microsoft 36S E5 subscription that has a Microsoft Purview exact data match (EDM) classifier named EDM1.
You plan to create the Microsoft Purview policies shown in the following table.

Which policies can use EDM1?

  • A. Retention 1 only
  • B. DLP1. Insider1, and Retention1
  • C. DLP1 only
  • D. Insider1 and Retention1 only
  • E. DLP1 and Insider1 only

Answer: C


NEW QUESTION # 55
You are creating a DLP policy named Policy1 that will be applied to the locations as shown in the following exhibit.

Policy1 contains an advanced data loss prevention (DLP) rule named Rule1.
Which two conditions can you use in Rule1? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  • A. Content is shared from Microsoft 365
  • B. Document size equals or is greater than
  • C. Attachment's file extension is
  • D. Document property is
  • E. Content contains

Answer: A,E

Explanation:
You are creating a Data Loss Prevention (DLP) policy in Microsoft 365 with advanced rules. Advanced DLP rules provide more granular conditions and actions than standard DLP rules.
Conditions available in advanced DLP
According to Microsoft Docs on Conditions in DLP policies:
* # Content contains # Used to detect sensitive information types, keywords, or exact data matches.
This is one of the most common and fundamental DLP conditions.
* # Content is shared from Microsoft 365 # Used to detect whether content has been shared externally or with specific domains/users. This is a modern advanced DLP condition.
Why the others are not correct:
* A. Document property is # This condition applies to information governance retention policies
/labels (not DLP). Not available in DLP rules.
* B. Attachment's file extension is # This is supported in Exchange mail flow rules (transport rules) but not in advanced DLP rules.
* C. Document size equals or is greater than # Also applies in Exchange transport rules and certain SharePoint restrictions, but not available as a DLP rule condition.


NEW QUESTION # 56
You have a Microsoft 365 E5 subscription.
You need to create a sensitivity label named Label1. The solution must ensure that users can use Microsoft 365 Copilot to summarize files that have Label1 applied.
Which permission should you select for Label1?

  • A. Edit content(DOCEDIT)
  • B. Copy and extract content(EXTRACT)
  • C. Export content(EXPORT)
  • D. View rights(VIEW)

Answer: B

Explanation:
To allow Microsoft 365 Copilot to summarize files that have Label1 applied, the label must grant permission to extract content from the document. The correct permission for this is Copy and extract content (EXTRACT).
Microsoft 365 Copilot requires access to read and process content in documents to generate summaries. The EXTRACT permission allows users (and AI tools like Copilot) to copy and extract content for processing while still maintaining the protection applied by the sensitivity label.


NEW QUESTION # 57
You have a Microsoft 365 tenant.
You have a database that stores customer details. Each customer has a unique 13-digit identifier that consists of a fixed pattern of numbers and letters.
You need to implement a data loss prevention (DLP) solution that meets the following requirements:
- Email messages that contain a single customer identifier can be sent
outside your company.
- Email messages that contain two or more customer identifiers must be
approved by the company's data privacy team.
Which two components should you include in the solution? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. a mail flow rule
  • B. a retention label
  • C. a sensitivity label
  • D. a sensitive information type
  • E. a DLP policy

Answer: D,E

Explanation:
You need to define a custom sensitive information type that recognizes the unique 13-digit identifier format for customer records. Microsoft Purview DLP policies use these types to identify and protect sensitive data.
A Data Loss Prevention (DLP) policy is required to enforce the rules. It will allow emails with a single identifier but trigger an approval workflow when two or more identifiers are detected.


NEW QUESTION # 58
You have a Microsoft 365 E5 subscription that contains a Microsoft Teams channel named Channel1.
Channel1 contains research and development documents.
You plan to implement Microsoft 365 Copilot for the subscription.
You need to prevent the contents of files stored in Channel1 from being included in answers generated by Copilot and shown to unauthorized users.
What should you use?

  • A. Microsoft Purview insider risk management
  • B. Microsoft Purview Information Barriers
  • C. sensitivity labels
  • D. data loss prevention (DLP)

Answer: C

Explanation:
To prevent the contents of files stored in Channel1 from being included in Microsoft 365 Copilot responses and ensure unauthorized users cannot access them, you should use Microsoft Purview Sensitivity Labels.
Sensitivity labels allow you to classify, protect, and restrict access to sensitive files. You can configure label- based encryption and access control policies to ensure that only authorized users can access or interact with the files in Channel1. Microsoft 365 Copilot respects sensitivity labels, meaning if a file is labeled with restricted permissions, Copilot will not use it in generated responses for unauthorized users.


NEW QUESTION # 59
You have a Microsoft 365 E5 subscription.
You need to review a Microsoft 365 Copilot usage report.
From where should you review the report?

  • A. the Microsoft 365 admin center
  • B. DSPM for AI in the Microsoft Purview portal
  • C. Information Protection in the Microsoft Purview portal
  • D. the Microsoft Defender portal

Answer: A

Explanation:
To review the Microsoft 365 Copilot usage report:
- Go to the Microsoft 365 admin center.
- Navigate to Reports > Usage.
- Select Copilot to view adoption and usage metrics.
The admin center provides insights into how Copilot is being used across your organization, helping you track engagement and effectiveness.
Data Security Posture Management (DSPM) for AI in the Microsoft Purview portal provides insights into AI usage, but it focuses on security and compliance rather than standard usage metrics.
https://learn.microsoft.com/en-us/purview/ai-microsoft-purview


NEW QUESTION # 60
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1.
Site1 contains the files shown in the following table.

In the Microsoft Purview portal, you create a content search named Conlent1 and configure the search conditions as shown in the following exhibit.

Which files will be returned by Content1?

  • A. File3.docx only
  • B. File1.docx and File2.docx only
  • C. File1 .docx and File3.docx only
  • D. File1 .docx, File2.docx, and File3.docx
  • E. File2.docx only

Answer: A


NEW QUESTION # 61
Drag and Drop Question
You have a Microsoft 365 5 subscription that uses Microsoft Purview insider risk management and contains three users named User1, User2, and User3.
All insider risk management policies have adaptive protection enabled and the default conditions for insider risk levels configured.
The users perform the following activities, which trigger insider risk policy alerts:
- User1 performs at least one data exfiltration activity that results in a high severity risk score.
- User2 performs at least three risky user activities within seven days, that each results in a high severity risk score.
- User3 performs at least two data exfiltration activities within seven days, that each results in a high severity risk score.
Which insider risk level is assigned to each user? To answer, drag the appropriate levels to the correct users. Each level may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Minor risk level
User1 performs at least one data exfiltration activity that results in a high severity risk score.
Minor:
This is the lowest risk level, assigned to users with low-severity alerts or those with at least one high-severity exfiltration activity.
Box 2: Elevated risk level
User2 performs at least three risky user activities within seven days, that each results in a high severity risk score.
Elevated:
This is the highest risk level, assigned to users with high-severity alerts, multiple high-severity insights, or confirmed high-severity alerts.
Box 3: Moderate risk level
User3 performs at least two data exfiltration activities within seven days, that each results in a high severity risk score.
Moderate:
This level indicates a medium risk, assigned to users with medium-severity alerts or those with at least two high-severity exfiltration activities.
Reference:
https://learn.microsoft.com/en-us/purview/insider-risk-management-adaptive-protection


NEW QUESTION # 62
SIMULATION
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
[email protected]
Microsoft 365 Password: XXXXXXXXX
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL "https://admin microsoft.com", and press Enter.
The following information is for technical support purposes only:
Lab Instance: XXXXXXXX.
Task 7
You need to create a retention policy that meets the following requirements:
- Applies to Microsoft Teams chats and Teams channel messages.
- Retains items for five years from the date they are created, and then deletes them.

Answer:

Explanation:
Stage 1: Create an adaptive scope
Step 1: Sign into Microsoft Purview compliance portal using credentials for an admin account in your Microsoft 365 organization.
Step 2: In the compliance portal, select Roles and Scopes.
Step 3: Select Adaptive scopes, and then + Create scope.
Step 4: Follow the prompts in the configuration where you'll first be asked to assign an administrative unit. If your account has been assigned administrative units, you must select one administrative unit that will restrict the scope membership. (Does not apply here) If you don't want to restrict the adaptive scope by using administrative units, or your organization hasn't configured administrative units, keep the default of Full directory. (Applies here) Step 5: Select the type of scope, and then select the attributes or properties you want to use to build the dynamic membership, and type in the attribute or property values. Select Add attribute (for users and groups).
For example, to configure an adaptive scope that will be used to identify users in Europe, first select Users as the scope type, and then select the Country or region attribute, and type in Europe:
Step 6: For User Attributes select: Department, is equal to, Sales
Stage 2: Create and configure retention policies
Step 1: From the Microsoft Purview compliance portal, select Data lifecycle management > Microsoft 365 > Retention Policies.
Step 2: Select New retention policy to start the Create retention policy configuration, and name your new retention policy.
Step 3: For the Assign admin units page (skip)
Step 4: For the Choose the type of retention policy to create page, select Adaptive or Static.
Select Adaptive.
We need Adaptive scopes.
Step 5: On the Choose adaptive policy scopes and locations page, select Add scopes and select the one you created in Stage 1.

Step 6: Then, select one or more locations. The locations that you can select depend on the scope types added. For example, if you only added a scope type of User, you'll be able to select Teams chats but not Teams channel messages.
Select: Teams chat and Teams channel
Step 7: For Decide if you want to retain content, delete it:
Select: On the Decide if you want to retain content, delete it, or both page, select Retain items for a specific period, specify the retention period [specify 5 years], and then for At end of the retention period select Delete items automatically.
Note: We need to retains item for five years from the date they are created, and then deletes them.
Reference:
https://learn.microsoft.com/en-us/purview/purview-adaptive-scopes
https://learn.microsoft.com/en-us/purview/create-retention-policies
https://learn.microsoft.com/en-us/purview/retention-settings#settings-for-retaining-and-deleting- content


NEW QUESTION # 63
HOTSPOT
You have a Microsoft 365 E5 subscription that has data loss prevention (DLP) implemented.
You plan to export DLP activity by using Activity explorer.
The exported file needs to display the sensitive info type detected for each DLP rule match.
What should you do in Activity explorer before exporting the data, and in which file format is the file exported? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: To include the sensitive info type detected for each DLP rule match, you need to add a custom column in Activity Explorer. This ensures that the exported file contains specific details about the detected sensitive information types.
Box 2: DLP activity exports from Activity Explorer are always in CSV (Comma-Separated Values) format.
This format allows for easy data analysis and reporting in Excel or other data-processing tools.


NEW QUESTION # 64
You create a retention label that has a retention period of seven years.
You need to ensure that documents containing a credit card number are retained for seven years. Other documents must not be retained.
What should you create?

  • A. a retention label policy of type publish
  • B. a retention policy that deletes files automatically
  • C. a retention policy that retains files automatically
  • D. a retention label policy of type auto-apply

Answer: D


NEW QUESTION # 65
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You recently discovered that the developers at your company emailed Azure Storage Account keys in plain text to third parties.
You need to ensure that when Azure Storage Account keys are emailed, the emails are encrypted.
Solution: You create a data loss prevention (DLP) policy that has only the Exchange email location selected.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: A

Explanation:
To ensure Azure Storage Account keys are encrypted when sent via email, you need a Data Loss Prevention (DLP) policy that detects Azure Storage Account keys using a sensitive information type and automatically encrypts emails containing these keys.
A DLP policy with Exchange email as the only location meets this requirement because it identifies sensitive data in email messages and it applies protection actions, such as encryption, blocking, or alerts.


NEW QUESTION # 66
You have a Microsoft J65 subscription linked to a Microsoft Entra tenant that contains a user named User1.
You need to grant User1 permission to search Microsoft 365 audit logs. The solution must use the principle of least privilege. Which role should you assign to User1?

  • A. the Reviewer role in the Microsoft Purview portal
  • B. the Compliance Management role in the Exchange admin center
  • C. the Security Reader role in the Microsoft Entra admin center
  • D. the View Only Audit Logs role in the Exchange admin center

Answer: D

Explanation:
Step 1 - Scenario
You need to grant User1 permission to search Microsoft 365 audit logs while following the principle of least privilege.
Step 2 - Roles that can search audit logs
Audit log search in Microsoft 365 is tied to Exchange Online role groups, because audit log data is stored in Exchange.
The following roles are relevant:
View-Only Audit Logs # Grants the ability to search and view audit logs, but not configure auditing or take other compliance actions. This is the least privilege role.
Audit Logs # Grants broader permissions, including turning auditing on/off.
Compliance Management # A broader role group that includes audit log search and many other compliance functions, violating least privilege.
Security Reader (Entra ID) # Grants read-only access to security features, but not audit logs.
Reviewer (Purview) # Used in eDiscovery, not audit logs.
Step 3 - Why "View-Only Audit Logs" is correct
According to Microsoft documentation:
"Users must be assigned the Audit Logs or View-Only Audit Logs role in Exchange Online to search the audit log. To minimize permissions, assign View-Only Audit Logs."
# Reference: Permissions required to search the audit log
Step 4 - Elimination of other options
A). Security Reader role # Allows reading security-related info in Microsoft 365 Defender, not Purview audit logs.
B). Compliance Management role # Includes more than just audit logs, not least privilege.
C). View-Only Audit Logs role # Correct and least privilege.
D). Reviewer role # For eDiscovery cases, not audit logs.


NEW QUESTION # 67
HOTSPOT
You need to meet the technical requirements for the confidential documents.
What should you create first, and what should you use for the detection method? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

To detect and protect confidential documents, we need a custom rule to identify project codes that start with
999 (since they are classified as confidential).
Box 1: A Sensitive Info Type (SIT) allows Microsoft Purview DLP policies to recognize structured data (e.g., project codes). DLP policies require a sensitive info type to detect content based on patterns, keywords, or dictionary terms. A sensitivity label alone does not define detection logic-it is used for classification and protection after content is identified.
Box 2: Since project codes follow a structured 10-digit pattern, we should use a Regular Expression (Regex) to match project codes that start with 999.
Example Regex pattern:
999\d{7}
This pattern detects a 10-digit number starting with "999".


NEW QUESTION # 68
You have a Microsoft 365 E5 subscription that uses Microsoft Purview.
You are evaluating the use of custom data assessment scans to identify the potential oversharing of data in the subscription.
What is the maximum number of items the data assessments can support per location?

  • A. 200.000
  • B. 500.000
  • C. 50.000
  • D. 100.000

Answer: A

Explanation:
Comprehensive Detailed Explanation with References
Custom Data Access Governance (DAG) data assessment scans in Microsoft Purview can be run on selected SharePoint Online or OneDrive locations to check for oversharing and exposure. Each custom assessment scan supports up to 200,000 items per location. This cap is documented in Microsoft's guidance for custom data access governance assessments.


NEW QUESTION # 69
Hotspot Question
You have a Microsoft 365 E5 subscription.
From the Microsoft Purview Data Security Posture Management for AI portal, you review the recommendations for AI data security.
You plan to create a one-click policy to block elevated risk users from pasting or uploading sensitive data to AI websites.
How will the policy be configured? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Test it out first
To configure the policy that blocks elevated risk users from uploading or pasting sensitive data to AI websites, you will configure the policy in "Test" mode within the Microsoft Purview portal to begin with, and then change it to a block-with-override mode to enforce protection on risky users for the relevant web browsers.
Box 2: Devices only
* Devices - Yes
Policies within Microsoft Purview's Data Security Posture Management for AI (DSPM for AI) can apply to user devices, specifically through Endpoint data loss prevention (DLP), which monitors and can block sensitive data from being pasted or uploaded to third-party AI sites accessed via browsers on those devices. This is achieved by onboarding Windows computers to Microsoft Purview and configuring Endpoint DLP policies to detect and prevent sharing sensitive information through the browser.
Reference:
https://learn.microsoft.com/en-us/purview/dspm-for-ai-considerations


NEW QUESTION # 70
......

Passing Key To Getting SC-401 Certified Exam Engine PDF: https://troytec.getvalidtest.com/SC-401-brain-dumps.html