Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dumps65

Microsoft SC-400 Dumps

Page: 1 / 32
Total 323 questions

Microsoft Information Protection Administrator Questions and Answers

Question 1

You plan to implement a sensitive information type based on a trainable classifier. The sensitive information type will identify employment contracts.

You need to copy the required files to Microsoft SharePoint Online folders to train the classifier.

What should you use to seed content and test the classifier? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 2

You have a Microsoft 365 E5 subscription.

You plan to implement insider risk management for users that manage sensitive data associated with a project.

You need to create a protection policy for the users. The solution must meet the following requirements:

• Minimize the impact on users who are NOT part of the project.

• Minimize administrative effort.

What should you do first?

Options:

A.

From the Microsoft Entra admin center, create a security group.

B.

From the Microsoft Purview compliance portal, create a priority user group.

C.

From the Microsoft Entra admin center, create a User risk policy.

D.

From the Microsoft Purview compliance portal, create an insider risk management policy.

Question 3

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 E5 subscription.

You need to identify resumes that are stored in the subscription by using a built-in trainable classifier.

Solution: You create an auto-labeling policy for a sensitivity label.

Does this meet the goal?

Options:

A.

Yes

B.

NO

Question 4

You create a data loss prevention (DLP) policy. The Advanced DLP rules page is shown in the Rules exhibit.

as

The Review your settings page is shown in the review exhibit.

as

You need to review the potential impact of enabling the policy without applying the actions.

What should you do?

Options:

A.

Edit the policy, remove all the actions in DLP rule 1, and select I'd like to test it out first.

B.

Edit the policy, remove the Restrict access to the content and Send incident report to Administrator actions,

and then select Yes, turn it on right away.

C.

Edit the policy, remove all the actions in DLP rule 1, and select Yes, turn it on right away.

D.

Edit the policy, and then select I'd like to test it out first.

Question 5

You have a Microsoft 365 subscription that has Enable Security defaults set to No in Azure AD.

You have a custom compliance manager template named Regulation1.

You have the assessments shown in the following table.

as

Assessment1 has the improvement actions shown in the following table.

as

Assessment2 has the improvement actions shown in the following table.

as

You perform the following actions:

• For Assessment2, change the Test status of Establish a threat intelligence program to Implemented.

• Enable multi-factor authentication (MFA) for all users.

• Configure a privileged access policy.

For each of the following statements, select Yes if the statement is true. Otherwise select No.

NOTE: Each correct selection is worth one point.

as

Options:

Question 6

You have a Microsoft 365 subscription.

You need to ensure that users can apply retention labels to individual documents in their Microsoft SharePoint libraries.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

From the Microsoft Purview compliance portal, create a label.

B.

From Microsoft Defender for Cloud Apps, create a file policy.

C.

From the Microsoft Purview compliance portal, publish a label.

D.

From the SharePoint admin center, modify the Site Settings.

E.

From the SharePoint admin center, modify the records management settings.

Question 7

You have a Microsoft 365 E5 subscription.

You need to ensure that encrypted email messages sent to an external recipient can be revoked or will expire within seven days.

What should you configure first?

Options:

A.

a custom branding template

B.

a mail flow rule

C.

a Conditional Access policy

D.

a sensitivity label

Question 8

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

as

You have a Privacy Risk Management policy named Policy1 based on the Data transfers template as shown in the Privacy Risk Management policy exhibit (Select the Privacy Risk Management policy tab and scroll to review the entire policy.)

User1 sends the following email messages that contain credit card information

• Message1 Sent to User2.

• Message2: Sent to User 3.

• Message3: Sent to User4

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

as

Options:

Question 9

You have a Microsoft 365 E5 tenant that contains the objects shown in the following table.

as

You need to restore a Microsoft Word document that was deleted from the Sales channel by User 1.

From where can the document be restored, and how long will the document be retained? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 10

ON NO: 5

You have a Microsoft 365 E5 tenant and the Windows 10 devices shown in the following table.

as

To which devices can you apply Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings?

Options:

A.

Device1, Device3, and Device4 only

B.

Device1, Device2, Device3, and Device4

C.

Device1 and Device2 only

D.

Device1 and Device3 only

E.

Device1 only

Question 11

You have a Microsoft 365 tenant that uses data loss prevention (DLP) to protect sensitive information.

You create a new custom sensitive info type that has the matching element shown in the following exhibit.

as

The supporting elements are configured as shown in the following exhibit.

as

The confidence level and character proximity are configured as shown in the following exhibit.

as

For each of the following statements, select Yes if statement is true. Otherwise, select No

NOTE: Each correct selection is worth one point.

as

Options:

Question 12

You have a data loss prevention (DLP) policy that has the advanced DLP rules shown in the following table.

as

You need to identify which rules will apply when content matches multiple advanced DLP rules.

Which rules should you identify? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 13

You have a Microsoft 365 ES subscription.

You plan to create a custom trainable classifier by uploading 1,000 machine-generated files as seed content.

The files have sequential names and are uploaded in one-minute intervals as shown in the following table.

as

Which files were processed first and last when you created the custom trainable classifier? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 14

You have a Microsoft 365 subscription.

You have a user named User1. Several users have full access to the mailbox of User1.

Some email messages sent to User1 appear to have been read and deleted before the user viewed them.

When you search the audit log in the Microsoft Purview compliance portal to identify who signed in to the mailbox of User1, the results are blank.

You need to ensure that you can view future sign-ins to the mailbox of User1.

YOU run the Set-Mailbox -Identity "User1" -AuditEnabled $true command.

Does that meet the goal?

Options:

A.

Yes

B.

No

Question 15

You have a Microsoft 365 tenant.

You create the following:

    A sensitivity label

    An auto-labeling policy

You need to ensure that the sensitivity label is applied to all the data discovered by the auto-labeling policy.

What should you do first?

Options:

A.

Enable insider risk management.

B.

Create a trainable classifier.

C.

Run the Enable-TransportRule cmdlet.

D.

Run the policy in simulation mode.

Question 16

You implement Microsoft 365 Endpoint data loss prevention (Endpoint DLP).

You have computers that run Windows 10 and have Microsoft 365 Apps installed. The computers are joined to Azure Active Directory (Azure AD).

You need to ensure that Endpoint DLP policies can protect content on the computers.

Solution: You deploy the unified labeling client to the computers.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 17

You have a Microsoft 365 E5 subscription that contains four Microsoft SharePoint Online sites named Site1, Site2, Site3, and Site4.

You have the retention policies shown in the following table.

as

You have the documents shown in the following table.

as

User1 moves Doc3 to Site4.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

as

Options:

Question 18

You are creating an advanced data loss prevention (DLP) rule in a DLP policy named Policy 1 that will have all

locations selected.

Which two conditions can you use in the rule? Each correct answer presents a complete solution. (Choose

two.)

NOTE: Each correct selection is worth one point.

Options:

A.

Content contains

B.

Content is shared from Microsoft 365

C.

Document size equals or is greater than

D.

Attachment's file extension is

E.

Document property is

Question 19

You have a Microsoft 365 E5 subscription.

You plan to update the overall compliance score for the Microsoft 365 environment.

You resolve improvement actions that have a Testing type of Manual and discover that the compliance score fails to update.

You need to ensure that the compliance score for manual improvement actions is updated.

Which three actions should you perform in sequence from Microsoft Purview Compliance Manager? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

as

Options:

Question 20

At the end of a project you upload project documents to a Microsoft SharePoint Online library that contains many fifes. Files that have the following naming format must be labeled as Project I

• aei_AA989.docx

• bd_WSOgadocx

• cei_DLF112-docx

• ebc_QQ4S4.docx

• ecc_BB565.docx

You plan to create an auto-apply retention label policy.

What should you use to identify the files, and which regular expression should you use? To answer, select the appropriate options in the answer area.

as

Options:

Question 21

You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.

You create a sensitivity label that has the following settings:

• Name: Sensitivity1

• Define the scope for this label: Items

• Choose protection settings for files and emails: Mark the content of files

o Add custom headers, footers, and watermarks to files and emails that have this label applied

You make Sensitivity1 available to User1. User1 performs the following actions:

• Creates a new email

• Adds a file named File1 .docx as an attachment to the email

• Applies Sensitivity1 to the email

• Sends the email to User2

How will the email and the attachment be marked? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 22

You have a Microsoft 365 subscription.

You have a team named Team! in Microsoft Teams.

You plan to place all the content in Team1 on hold.

You need to identify which mailbox and which Microsoft SharePoint site collection are associated to Team1.

Which cmdlet should you use?

Options:

A.

Get-UnifiedGroup

B.

Get-MalUser

C.

Get-TeamChannel

D.

Get-Team

Question 23

Your company has two departments named department1 and department2 and a Microsoft 365 E5 subscription.

You need to prevent communication between the users in department1 and the users in department.

How should you complete the PowerShell script? To answer, drag the appropriate values to the correct targets. Each value may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

as

Options:

Question 24

You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.

You need to implement insider risk management. The solution must meet the following requirements:

• Ensure that User1 can create insider risk management policies.

• Ensure that User2 can use content captured by using insider risk management policies.

• Follow the principle of least privilege.

To which role group should you add each user? To answer, drag the appropriate role groups to the correct users. Each role group may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

NOTE: Each correct selection is worth one point.

as

Options:

Question 25

You need to implement a solution that meets the compliance requirements for the Windows 10 computers.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each coned selection is worth one point.

Options:

A.

Deploy a Microsoft 36S Endpoint data loss prevention (Endpoint DLP) configuration package to the computers.

B.

Configure hybrid Azure AD join for all the computers.

C.

Configure the Microsoft Intune device enrollment settings.

D.

Configure a compliance policy in Microsoft Intune.

E.

auto in Microsoft Defender for Endpoint protection.

Question 26

You need to recommend a solution that meets the executive requirements. What should you recommend?

Options:

A.

From the Microsoft 365 compliance center, create a retention policy.

B.

From the Exchange admin center, enable archive mailboxes.

C.

From the Microsoft 365 compliance center, create a retention label.

D.

From the Microsoft 365 compliance center, create a DLP policy.

Question 27

You need to recommend a solution that meets the Data Loss Prevention requirements for the HR department.

Which three actions should you perform? Each correct answer presents part of the solution. (Choose three.)

NOTE: Each correct selection is worth one point.

Options:

A.

Schedule EdmUploadAgent.exe to hash and upload a data file that contains employee information.

B.

Create a sensitive info type rule package that contains the EDM classification.

C.

Define the sensitive information database schema in the XML format.

D.

Create a sensitive info type rule package that contains regular expressions.

E.

Define the sensitive information database schema in the CSV format.

Question 28

You need to recommend an information governance solution that meets the HR requirements for handling employment applications and resumes.

What is the minimum number of information governance solution components that you should create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 29

You need to recommend a solution that meets the compliance requirements for viewing DLP tooltip

justifications.

What should you recommend?

Options:

A.

Instruct the compliance department users to review the False positive and override report.

B.

Configure a Microsoft Power Automate workflow to route DLP notification emails to the compliance

department.

C.

Instruct the compliance department users to review the DLP incidents report.

D.

Configure an Azure logic app to route DLP notification emails to the compliance department.

Question 30

You need to recommend a solution to configuration the Microsoft 365 Records management settings by using the CSV file must meet the compliance requirements.

What should you recommend?

Options:

A.

From the Microsoft 365 compliance center, import the CSV file to a file plan.

B.

Use EdmUploadAgent.exe to upload a hash of the CSV to a datastore.

C.

Use a PowerShell command that pipes the import csv cmdlet to the New-RetentionPolicy cmdlet.

D.

Use a PowerShell command that pipes the import-csv cmdlet to the New-Label cmdlet.

Question 31

You need to recommend a solution that meets the sales requirements.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

as

Options:

Question 32

You need to recommend a solution that meets the compliance requirements for Dropbox.

What should you recommend?

Options:

A.

Create a DLP policy that applies to devices.

B.

Create a file policy in Microsoft Defender for Cloud Apps that uses the built-in DLP inspection method.

C.

Create a retention label that enforces the item deletion settings.

D.

Edit an existing retention label that enforces the item deletion settings.

Question 33

You need to recommend a solution that meets the compliance requirements for protecting the documents in the Data shared folder. What should you recommend?

Options:

A.

From the Microsoft 365 compliance center, configure a DLP policy.

B.

From the Microsoft 365 compliance center, configure a Content Search query.

C.

From the Microsoft 365 compliance center, configure an auto-labeling policy.

D.

From Azure Information Protection, configure a content scan job.

Question 34

You need to recommend a solution that meets the compliance requirements for Dropbox.

What should you recommend?

Options:

A.

Create a DLP policy that applies to Cloud App Security.

B.

Edit an existing retention label that enforces the item deletion settings.

C.

Create a retention label that enforces the item deletion settings.

D.

Create a DLP policy that applies to devices.

Question 35

You need to recommend a solution that meets the compliance requirements for protecting the documents in the Data shared folder.

What should you configure in the Microsoft Purview compliance portal?

Options:

A.

a content scan job

B.

a Content Search query

C.

an auto-labeling policy

D.

a DLP policy

Question 36

You need to implement a solution to encrypt email. The solution must meet the compliance requirements.

What should you create in the Exchange admin center and the Microsoft 36.S compliance center? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

as

Options:

Question 37

Task 1

You need to provide users with the ability to manually classify files that contain product information that are stored in SharePoint Online sites. The solution must meet the following requirements:

• The users must be able to apply a classification of Product1 to the files.

• Any authenticated user must be able to open files classified as Product1.

• files classified as Product1 must be encrypted.

Options:

Question 38

Task 4

You need to block users from sending emails containing information that is subject to Payment Card Industry Data Security Standard (PCI OSS). The solution must affect only emails.

Options:

Question 39

Task 9

You are investigating a data breach.

You need to retain all Microsoft Exchange items in the mailbox of Alex Wilber that contain the word Falcon and were created in the year 2021.

Options:

Question 40

Task 8

You need to retain Microsoft SharePoint files that contain the word Falcon for two years from the date they were created, and then delete them.

Options:

Question 41

Task 2

You discover that all users can apply the Confidential - Finance label.

You need to ensure that the Confidential - Finance label is available only to the members of the Finance Team group.

Options:

Question 42

Task 5

You need to ensure that a group named U.S. Sales can store files containing information subject to General Data Protection Regulation (GDPR) in their OneDrive accounts. All other current GDPR restrictions must remain in effect.

Options:

Question 43

Task 10

You plan to create a data loss prevention (DLP) policy that will apply to content containing the following keywords:

• Tailspin

• litware

• Falcon

You need to create a keyword list that can be used in the DLP policy. You do NOT need to create the DLP policy at this time.

Options:

Question 44

Task 7

You need to create a retention policy that meets the following requirements:

• Applies to Microsoft Teams chat and Teams channel messages of users that have a department attribute of Sales.

• Retains item for five years from the date they are created, and then deletes them.

Options:

Question 45

Task 6

You plan to implement Endpoint data loss prevention (Endpoint DLP) policies for computers that run Windows.

Users have an application named App1 that stores data locally in a folder named C:\app1\data.

You need to prevent the folder from being monitored by Endpoint DLP.

Options:

Question 46

Task 3

You plan to automatically apply a watermark to the document1 of a project named Falcon.

You need to create a label that will add a watermark of "Project falcon' in red. size-12 font diagonally across the documents.

Options:

Question 47

You need to meet the technical requirements for the creation of the sensitivity labels.

To which user or users must you grant the Sensitivity label administrator role?

Options:

A.

Admin1, Admin2, Admin4, and Admin5 only

B.

Admin1, Admin2, and Admin3 only

C.

Admin1 only

D.

Admin1 and Admin4 only

E.

Admin1 and Admin5 only

Question 48

You need to meet the technical requirements for the Site3 documents.

What should you create?

Options:

A.

a retention label policy and a retention label that uses an event

B.

a sensitive info type that uses a dictionary and a sensitivity label

C.

a sensitive info type that uses a regular expression and a sensitivity label

D.

a retention policy that has Only delete items when they reach a certain age selected

Page: 1 / 32
Total 323 questions