[Q93-Q117] Free Sales Ending Soon - Use Real SC-401 PDF Questions [Dec 10, 2025]

Share

Free Sales Ending Soon - Use Real SC-401 PDF Questions [Dec 10, 2025]

Updated Dec-2025 Exam SC-401 Dumps - Pass Your Certification Exam


Microsoft SC-401 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Manage Risks, Alerts, and Activities: This section assesses Security Operations Analysts on insider risk management, monitoring alerts, and investigating security activities. It covers configuring risk policies, handling forensic evidence, and responding to alerts using Microsoft Purview and Defender tools. Candidates must also analyze audit logs and manage security workflows.
Topic 2
  • Implement Information Protection: This section measures the skills of Information Security Analysts in classifying and protecting data. It covers identifying and managing sensitive information, creating and applying sensitivity labels, and implementing protection for Windows, file shares, and Exchange. Candidates must also configure document fingerprinting, trainable classifiers, and encryption strategies using Microsoft Purview.
Topic 3
  • Protect Data Used by AI Services: This section evaluates AI Governance Specialists on securing data in AI-driven environments. It includes implementing controls for Microsoft Purview, configuring Data Security Posture Management (DSPM) for AI, and monitoring AI-related security risks to ensure compliance and protection.
Topic 4
  • Implement Data Loss Prevention and Retention: This section evaluates Data Protection Officers on designing and managing data loss prevention (DLP) policies and retention strategies. It includes setting policies for data security, configuring Endpoint DLP, and managing retention labels and policies. Candidates must understand adaptive scopes, policy precedence, and data recovery within Microsoft 365.

 

NEW QUESTION # 93
You have a Microsoft J65 ES subscription.
You need to create a Microsoft Defender for Cloud Apps policy that will detect data loss prevention (DIP) violations. What should you create?

  • A. an access policy
  • B. a session policy
  • C. a file policy
  • D. an activity policy

Answer: C


NEW QUESTION # 94
You have 4 Microsoft 565 E5 subscription that contains two Microsoft SharePoint Online sites named Site1 and Site2. You plan to configure a retention label named Labe1 and apply label1 to all the files in Site1 You need to ensure that two years after a file is created in Site1. the file moves automatically to Site2. How should you configure the Choose what happens after the retention period setting for Label1?

  • A. Deactivate retention settings
  • B. Change the label
  • C. Start a disposition review
  • D. Run a Power Automate flow

Answer: D

Explanation:
You want files in Site1 that are labeled with Label1 to automatically move to Site2 two years after creation.
In Microsoft Purview Retention Labels, under "Choose what happens after the retention period", the available options are:
Deactivate retention settings - Ends retention but does not move files.
Start a disposition review - Sends items to reviewers for approval (manual process, not auto-move).
Change the label - Applies a new retention label (but does not move files to another site).
Run a Power Automate flow - Executes an automated workflow such as moving the file to another SharePoint library or site, notifying users, or applying custom business processes.
Since the requirement is automatic movement of files from Site1 to Site2 after 2 years, the only valid choice is Run a Power Automate flow.
Reference:
Microsoft Learn: Actions after a retention period for retention labels
Quote: "For retention labels, you can choose to trigger a Power Automate flow when the retention period


NEW QUESTION # 95
You have a Microsoft 36515 subscription tha1 contains a Microsoft SharePoint Online site named Site1 Site1 contains three tiles named File1. File2 and File3.
You create the data loss prevention (DIP) policies shown in the following table.

The DIP rule matches for each tile are shown in the following table.

How many DIP policy matches events will be added to Activity explorer, and how many policy matches will be added to the DLP incidents report? To answer, select the appropriate options m the answer area.

Answer:

Explanation:

Explanation:


NEW QUESTION # 96
HOTSPOT
You have a Microsoft 365 E5 subscription that contains the device configurations shown in the following table.

Each configuration uses either Google Chrome or Firefox as a default browser.
You need to implement Microsoft Purview and deploy the Microsoft Purview browser extension to the configurations.
To which configuration can each extension be deployed? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

Microsoft Purview browser extensions for Endpoint DLP are supported on:
# Windows 10/11 (Config1)
# macOS (Config2)
# Not supported on Android (Config3)
Since Microsoft Purview does not support browser extensions on Android, Config3 is excluded from both Google Chrome and Firefox.


NEW QUESTION # 97
You have a Microsoft 365 E5 subscription that uses Microsoft Purview Audit (Premium) with the 10-Year Audit Log Retention add-on license.
The subscription contains the audit retention policies shown in the following table.

From the SharePoint Online admin center, User1 performs the actions shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE; Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 98
You need to meet the retention requirement for the users' Microsoft 365 data.
What is the minimum number of retention policies required to achieve the goal?

  • A. 0
  • B. 1
  • C. 2
  • D. 3
  • E. 4

Answer: D

Explanation:
The requirement states that all Microsoft 365 data for users must be retained for at least one year. In Microsoft
365, retention policies must be configured for each type of data storage.
Step 1: Identifying Where Data is Stored
From the case study, users store data in the following locations:
# SharePoint Online sites
# OneDrive accounts
# Exchange email
# Exchange public folders
# Teams chats
# Teams channel messages
Since these locations fall under two broad categories:
# Microsoft Exchange data (Emails, Public folders)
# SharePoint, OneDrive, and Teams data
Step 2: Required Retention Policies
1#. A single retention policy can cover:
# SharePoint Online
# OneDrive
# Microsoft Teams
2. A second retention policy is required for:
# Exchange (Emails & Public Folders)
Thus, the minimum number of retention policies required to meet the requirement is 2.
Microsoft 365 retention policies can be applied broadly across multiple services with just two policies:
# One for Exchange & Public Folders
# One for SharePoint, OneDrive, and Teams
There's no need for separate policies for each individual workload unless different retention durations are required, which is not stated in the requirement.


NEW QUESTION # 99
You have a Microsoft 365 alert named Alert2 as shown in the following exhibit.

You need to manage the status of Alert? To which status can you change Alette?

  • A. Investigating only
  • B. The status cannot be changed.
  • C. Dismissed only
  • D. Active or Investigating only
  • E. Investigating. Active, or Dismissed

Answer: D


NEW QUESTION # 100
You have a Microsoft 365 tenant.
You have a database that stores customer details. Each customer has a unique 13-digit identifier that consists of a fixed pattern of numbers and letters.
You need to implement a data loss prevention (DLP) solution that meets the following requirements:
*Email messages that contain a single customer identifier can be sent outside your company.
*Email messages that contain two or more customer identifiers must be approved by the company's data privacy team.
Which two components should you include in the solution? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. a mail flow rule
  • B. a retention label
  • C. a sensitivity label
  • D. a sensitive information type
  • E. a DLP policy

Answer: D,E

Explanation:
You need to define a custom sensitive information type that recognizes the unique 13-digit identifier format for customer records. Microsoft Purview DLP policies use these types to identify and protect sensitive data.
A Data Loss Prevention (DLP) policy is required to enforce the rules. It will allow emails with a single identifier but trigger an approval workflow when two or more identifiers are detected.


NEW QUESTION # 101
You have a Microsoft 36S ES subscription that contains the devices shown in the following table.

You publish Microsoft Purview Information Protection sensitivity labels.
You plan to deploy the information protection client to the devices. The solution must ensure that the labels can be applied to sensitive images and documents On which devices can you install the information protection client, and what should users use to apply labels?
To answer, select the appropriate options in the answer area.

Answer:

Explanation:

Explanation:


NEW QUESTION # 102
You have a Microsoft 365 E5 tenant that contains a user named User1. User1 is assigned the Compliance Administrator role. User1 cannot view the regular expression in the IP Address sensitive info type. You need to ensure that User! can view the regular expression. What should you do?

  • A. Instruct User1 to use the Test function on the sensitive info type.
  • B. Create a copy of the IP Address sensitive info type and instruct User1 to edit the copy.
  • C. Assign Used to the Reviewer role group
  • D. Assign User1 the Global Reader role.

Answer: B

Explanation:
Step 1 - Problem statement
User1 has the Compliance Administrator role but cannot view the regular expression in the built-in IP Address sensitive info type.
This is expected because:
Microsoft provides a large set of built-in sensitive info types (SITs).
For these built-in SITs, the underlying regular expressions, keywords, or detection logic are not exposed to administrators for security reasons.
As a result, even with Compliance Administrator privileges, User1 cannot directly see or modify the regex in the built-in IP Address SIT.
Step 2 - Microsoft solution
To view or modify the regex:
You must create a copy of the built-in SIT.
Once copied, the new custom SIT allows you to edit and view the regex and supporting elements.
This is the only supported way to customize or examine the detection logic.
# Reference: Create a custom sensitive information type
"You can't directly modify the definitions of built-in sensitive information types, but you can create a copy of an existing SIT and then edit it." Step 3 - Why not the other options?
A). Reviewer role group # Reviewers are for records management/discovery, not SIT regex visibility.
C). Test function # Allows you to test SIT detection but does not reveal the regex.
D). Global Reader role # Read-only access, does not expose regex definitions either.


NEW QUESTION # 103
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site! and the data loss prevention (DLP) policies shown in the following table.

The DLP rules are configured as shown In the following table.

All the policies are assigned to Site1.
You need to ensure that if a user uploads a document to Site1 that matches all the rules, the user will be shown the Tip 2 policy tip. What should you do?

  • A. Prevent additional processing of the policies if there is a match for Rule2
  • B. Enable additional processing of the policies if there is a match for Rule1.
  • C. Change the priority of DLP2 to 3.
  • D. Change the priority of DLP2 to 0.

Answer: D

Explanation:
Current setup:
DLP1 (priority 0, Rule1) # Stop processing additional rules enabled # means if Rule1 matches, later rules (including Rule2 with Tip2) will never be evaluated.
Requirement: Ensure that if all rules match, the user sees Tip2 (Rule2's policy tip).
To fix this: Move DLP2 above DLP1 in priority (i.e., set DLP2 = priority 0). Then Rule2 will be evaluated first, and its policy tip (Tip2) will be displayed.
Why not others?
B). Prevent additional processing of the policies if there is a match for Rule2: That would stop processing later, but DLP1 would still block earlier due to its higher priority.
C). Change the priority of DLP2 to 3: That pushes it even lower, making it worse.
D). Enable additional processing for Rule1: Rule1 already has stop processing enabled. Changing that does not ensure Rule2 runs before Rule1, because priority is evaluated first.
Reference:
Microsoft Learn: Order of rule processing in DLP
# Policies with lower priority numbers run first, and "Stop processing" ends evaluation.


NEW QUESTION # 104
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

Which users will Microsoft Purview insider risk management flag as potential high-impact users?

  • A. User2 and User3 only
  • B. User1, User2, and User3 only
  • C. User1 and User2 only
  • D. User1, User2, User3, and User4

Answer: D

Explanation:
Microsoft Purview Insider Risk Management flags high-impact users based on various risk factors, including role, access to confidential data, and influence within an organization. Let's analyze each user:
User1 (Regional Manager, assigned Reader role, manages department managers) Risk Factors:
# Holds a managerial position (regional manager).
# Manages multiple department managers, indicating organizational influence.
# Access to critical business information.
Flagged? -Yes (Managerial role and access to confidential data).
User2 (HR department manager, no Microsoft Entra roles, manages HR department users) Risk Factors:
# Manages HR department users, meaning they likely handle sensitive employee data.
# HR roles are often considered high-risk due to access to personal and payroll data.
Flagged? -Yes (HR role and access to sensitive employee data).
User3 (Developer, reports to User2, only user in compliance, assigned Compliance Administrator role) Risk Factors:
# Compliance Administrator role grants access to sensitive security and regulatory data.
# Only person in the compliance department, meaning they hold a critical role.
# Potentially high impact on compliance and security settings.
Flagged? -Yes (Privileged Compliance Administrator role).
User4 (Assistant to User1, no Entra roles, handles confidential data on behalf of User1) Risk Factors:
# Handles a high volume of confidential data on behalf of a regional manager.
# Assistants with access to sensitive data are considered insider risk candidates.
Flagged? -Yes (High access to sensitive information).
Since all four users fit high-impact criteria (managerial roles, privileged compliance access, handling sensitive data), Microsoft Purview Insider Risk Management will flag all of them.


NEW QUESTION # 105
You have a Microsoft 365 E5 subscription that contains a Microsoft Teams channel named Channel1. Channel1 contains research and development documents.
You plan to implement Microsoft 365 Copilot for the subscription.
You need to prevent the contents of files stored in Channel1 from being included in answers generated by Copilot and shown to unauthorized users.
What should you use?

  • A. data loss prevention (DLP)
  • B. Microsoft Purview insider risk management
  • C. sensitivity labels
  • D. Microsoft Purview Information Barriers

Answer: C

Explanation:
To prevent the contents of files stored in Channel1 from being included in Microsoft 365 Copilot responses and ensure unauthorized users cannot access them, you should use Microsoft Purview Sensitivity Labels.
Sensitivity labels allow you to classify, protect, and restrict access to sensitive files. You can configure label-based encryption and access control policies to ensure that only authorized users can access or interact with the files in Channel1. Microsoft 365 Copilot respects sensitivity labels, meaning if a file is labeled with restricted permissions, Copilot will not use it in generated responses for unauthorized users.


NEW QUESTION # 106
You have a Microsoft SharePoint Online site named Site1 that has the users shown in the following table.

You create the retention labels shown in the following table.

You publish the retention labels to Site1.
On March 1,2023, you assign the retention labels to the files shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

User1 can delete File1 on March 10, 2023.
No - File1 has Retention1 applied, which retains it for 4 years with a "Retain only" action. This means it cannot be deleted during the retention period, which ends on March 1, 2027.
User2 can delete File1 on March 10, 2027.
No - User2 is a Member and does not have the Owner role, which is required to delete files under retention policies during the retention period. Additionally, the "Retain only" action prevents deletion until the retention period ends on March 1, 2027.
User2 can edit File2 on March 15, 2025.
No - File2 has Retention2 applied, which retains it for 2 years with a "Retain and delete" action. This means the file is protected from edits or deletions during the retention period, which ends on March 1, 2025. Since March 15, 2025, is after the retention period, the file would be eligible for deletion, but the question specifies editing, which is restricted during the retention period.


NEW QUESTION # 107
You have a Microsoft 365 E5 subscription.
Users access their mailbox by using the following apps.
* Outlook for Microsoft 365
* Outlook on the web
* Outlook Mobile fiOS. Android)
You create a data loss prevention (DLP) policy named DLP1 that has the following settings:
* Location; Exchange email
* Status: On
* User notifications: On
* Notify users with a policy tip: Enabled
Which apps display a policy tip when content is matched by using DIP1 ?

  • A. Outlook for Microsoft 365 only
  • B. Outlook for Microsoft 365 and Outlook Mobile (iOS. Android) only
  • C. Outlook for Microsoft 365. Outlook on the web, and Outlook Mobile (iOS. Android)
  • D. Outlook on the web only
  • E. Outlook for Microsoft 365 and Outlook on the web only

Answer: E

Explanation:
Policy tips in DLP: Policy tips are messages shown to users when their action (such as sending sensitive content via email) conflicts with a DLP policy.
For Exchange email location, policy tips are supported in the following apps:
Outlook for Microsoft 365 (desktop client) #
Outlook on the web (OWA) #
Outlook Mobile (iOS/Android) # Policy tips are not shown in mobile apps. Instead, DLP actions (block/restrict
/send incident report) still apply, but the user does not see a policy tip notification.
Therefore:
Supported: Outlook for Microsoft 365, Outlook on the web.
Not supported: Outlook Mobile apps.
Reference:
Microsoft Learn: Policy tips in DLP
Quote: "Policy tips are supported in Outlook on the web and Outlook 2013 and later. Policy tips are not supported in Outlook mobile apps."


NEW QUESTION # 108
You have a Microsoft 365 E5 subscription that uses Microsoft Purview.
You are creating an exact data match (EDM) classifier named EDM1.
For EDM1, you upload a schema file that contains the fields shown in the following table.

What is the maximum number of primary elements that EDM1 can have?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: C

Explanation:
In Microsoft Purview Exact Data Match (EDM) classifiers, a primary element is a unique, identifying field used for data matching. EDM allows up to two primary elements per schema.
From the provided table, the Match mode indicates how data is analyzed:
*PP (EU Passport Number) → Likely a primary element because it's unique.
*Name (All Full Names) → Typically not a primary element as names are common.
*DateOfBirth (Single-token) → Usually a secondary element, not unique.
*AccountNumber (Multi-token) → Can be a primary element, as it's a unique identifier.
*Since EDM supports a maximum of two primary elements, the correct answer is 2.


NEW QUESTION # 109
You have a data loss prevention (DIP) policy that has the advanced DIP rules shown in the following table.

You need to identity which rules will apply when content matches multiple advanced DIP rules.
Which rules should you identify? To answer, select the appropriate options in the answer area.

Answer:

Explanation:

Explanation:


NEW QUESTION # 110
You have a Microsoft 365 E5 tenant that uses a domain named contoso.com.
A user named User 1 sends link based, branded emails that are encrypted by using Microsoft Purview Advanced Message Encryption to the recipients shown in the following table.

For which recipients Can User1 revoke the emails?

  • A. Recipient4 only
  • B. Reclpient3 and Recipients only
  • C. Reciptent1, Recipient2. Recipient3, and Recipient4
  • D. Recipient1 only
  • E. Reciptent1 and Recipient^ only

Answer: B


NEW QUESTION # 111
You have a Microsoft 365 E5 subscription that uses Microsoft Purview and just-in-time (JIT) protection. The subscription contains the users shown in the following table.

The subscription contains the devices shown in the following table.

The devices contain the files shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 112
DRAG DROP
You have a Microsoft 365 subscription that contains 20 data loss prevention (DLP) policies.
You need to identify the following:
# Rules that are applied without triggering a policy alert
# The top 10 files that have matched DLP policies
# Alerts that are miscategorized
Which report should you use for each requirement? To answer, drag the appropriate reports to the correct requirements. Each report may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

The False positive and override report helps identify rules that were applied but did not generate an actual policy alert, which means they were overridden or deemed false positives.
The DLP policy matches report provides details on files that matched DLP policies, including the top 10 files.
The Incident reports report helps analyze and review alerts, including those that may have been miscategorized.


NEW QUESTION # 113
You have a Microsoft 365 E5 tenant that has devices onboarded to Microsoft Defender for Endpoint as shown in the following table.

You plan to start using Microsoft 365 Endpoint data loss protection (Endpoint DLP).
Which devices support Endpoint DLP?

  • A. Device1, Device2, Device3, and Device4
  • B. Device1, Device2, and Device4 only
  • C. Device1 and Device2 only
  • D. Device1 only
  • E. Device1 and Device4 only

Answer: C

Explanation:
Microsoft 365 Endpoint data loss prevention (Endpoint DLP) is supported only on Windows 10 and Windows 11 devices. It does not support macOS or iOS at this time.
From the provided table:
*Device1 (Windows 11) - Supported
*Device2 (Windows 10) - Supported
*Device3 (iOS) - Not supported
*Device4 (macOS) - Not supported
Thus, only Device1 and Device2 support Endpoint DLP.


NEW QUESTION # 114
Your company has offices in multiple countries.
The company has a Microsoft 365 E5 subscription that uses Microsoft Purview insider risk management.
You plan to perform the following actions:
*In a new country, open an office named Office1.
*Create a new user named User1.
*Deploy insider risk management to Office1.
*Add User1 to the Insider Risk Management Admins role group.
You need to ensure that User1 can perform insider risk management tasks for only the users and the devices in Office1.
What should you create first?

  • A. a dynamic device group
  • B. an administrative unit
  • C. a dynamic user group
  • D. a management group

Answer: B

Explanation:
To ensure User1 can perform insider risk management tasks only for the users and devices in Office1, the first step is to create an administrative unit in Microsoft Entra ID (formerly Azure AD).
Administrative units allow you to scope permissions to specific users, devices, and locations. By creating an administrative unit for Office1 and assigning User1 to the Insider Risk Management Admins role group within that unit, User1 will only have access to users and devices in Office1.


NEW QUESTION # 115
HOTSPOT
You have a Microsoft 365 E5 subscription.
You need to implement a compliance solution that meets the following requirements:
# Captures clips of key security-related user activities, such as the exfiltration of sensitive company data.
# Integrates data loss prevention (DLP) capabilities with insider risk management.
What should you use for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 116
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.
You plan to deploy a Defender for Cloud Apps file policy that will be triggered when the following conditions are met:
# A file is shared externally.
# A file is labeled as internal only.
Which filter should you use for each condition? To answer, drag the appropriate filters to the correct conditions. Each filter may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 117
......

SC-401 Dumps To Pass Microsoft Certified: Information Security Administrator Associate Exam in One Day: https://www.passreview.com/SC-401_exam-braindumps.html

Latest Real Microsoft SC-401 Exam Dumps Questions: https://drive.google.com/open?id=1AKFQkqSddECAgPZ96NL5_yaP1a1pneJq