New Year Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Microsoft SC-400 Microsoft Information Protection Administrator Exam Practice Test

Page: 1 / 32
Total 323 questions

Microsoft Information Protection Administrator Questions and Answers

Question 1

You are reviewing policies for the SharePoint Online environment.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 1

Options:

Question 2

You need to meet the technical requirements for the Site3 documents.

What should you create?

Options:

A.

a retention label policy and a retention label that uses an event

B.

a sensitive info type that uses a dictionary and a sensitivity label

C.

a sensitive info type that uses a regular expression and a sensitivity label

D.

a retention policy that has Only delete items when they reach a certain age selected

Question 3

You are evaluating the technical requirements for the DLP reports.

Which user can currently view the DLP reports?

Options:

A.

Admin4

B.

Admin1

C.

Admin5

D.

Admin2

E.

Admin3

Question 4

You need to meet the technical requirements for the confidential documents.

What should you created first, and what should you use for the detection method? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 4

Options:

Question 5

You need to meet the technical requirements for the Site1 documents.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Question # 5

Options:

Question 6

How many files in Site2 will be visible to User1 and User2 after you turn on DLPpolicy1? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 6

Options:

Question 7

You need to meet the technical requirements for the creation of the sensitivity labels.

To which user or users must you grant the Sensitivity label administrator role?

Options:

A.

Admin1, Admin2, Admin4, and Admin5 only

B.

Admin1, Admin2, and Admin3 only

C.

Admin1 only

D.

Admin1 and Admin4 only

E.

Admin1 and Admin5 only

Question 8

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth is worth one point.

Question # 8

Options:

Question 9

You need to meet the technical requirements for the creation of the sensitivity labels. Which administrative users are currently missing the Sensitivity label administrator role?

Options:

A.

Admin1 only

B.

Admm1, Admin2, Admin4, and Admin5 only

C.

Admin 1. Admin2, and Admin3 only

D.

Admin 1 and Admin5 only

E.

Admin 1 and Admin4 only

Question 10

Task 6

You plan to implement Endpoint data loss prevention (Endpoint DLP) policies for computers that run Windows.

Users have an application named App1 that stores data locally in a folder named C:\app1\data.

You need to prevent the folder from being monitored by Endpoint DLP.

Options:

Question 11

Task 2

You discover that all users can apply the Confidential - Finance label.

You need to ensure that the Confidential - Finance label is available only to the members of the Finance Team group.

Options:

Question 12

Task 9

You are investigating a data breach.

You need to retain all Microsoft Exchange items in the mailbox of Alex Wilber that contain the word Falcon and were created in the year 2021.

Options:

Question 13

Task 1

You need to provide users with the ability to manually classify files that contain product information that are stored in SharePoint Online sites. The solution must meet the following requirements:

• The users must be able to apply a classification of Product1 to the files.

• Any authenticated user must be able to open files classified as Product1.

• files classified as Product1 must be encrypted.

Options:

Question 14

Task 3

You plan to automatically apply a watermark to the document1 of a project named Falcon.

You need to create a label that will add a watermark of "Project falcon' in red. size-12 font diagonally across the documents.

Options:

Question 15

Task 5

You need to ensure that a group named U.S. Sales can store files containing information subject to General Data Protection Regulation (GDPR) in their OneDrive accounts. All other current GDPR restrictions must remain in effect.

Options:

Question 16

Task 8

You need to retain Microsoft SharePoint files that contain the word Falcon for two years from the date they were created, and then delete them.

Options:

Question 17

Task 4

You need to block users from sending emails containing information that is subject to Payment Card Industry Data Security Standard (PCI OSS). The solution must affect only emails.

Options:

Question 18

Task 10

You plan to create a data loss prevention (DLP) policy that will apply to content containing the following keywords:

• Tailspin

• litware

• Falcon

You need to create a keyword list that can be used in the DLP policy. You do NOT need to create the DLP policy at this time.

Options:

Question 19

Task 7

You need to create a retention policy that meets the following requirements:

• Applies to Microsoft Teams chat and Teams channel messages of users that have a department attribute of Sales.

• Retains item for five years from the date they are created, and then deletes them.

Options:

Question 20

You need to recommend a solution that meets the compliance requirements for Dropbox.

What should you recommend?

Options:

A.

Create a DLP policy that applies to Cloud App Security.

B.

Edit an existing retention label that enforces the item deletion settings.

C.

Create a retention label that enforces the item deletion settings.

D.

Create a DLP policy that applies to devices.

Question 21

You need to implement a solution that meets the compliance requirements for the Windows 10 computers.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each coned selection is worth one point.

Options:

A.

Deploy a Microsoft 36S Endpoint data loss prevention (Endpoint DLP) configuration package to the computers.

B.

Configure hybrid Azure AD join for all the computers.

C.

Configure the Microsoft Intune device enrollment settings.

D.

Configure a compliance policy in Microsoft Intune.

E.

auto in Microsoft Defender for Endpoint protection.

Question 22

You need to recommend a solution that meets the compliance requirements for Dropbox.

What should you recommend?

Options:

A.

Create a DLP policy that applies to devices.

B.

Create a file policy in Microsoft Defender for Cloud Apps that uses the built-in DLP inspection method.

C.

Create a retention label that enforces the item deletion settings.

D.

Edit an existing retention label that enforces the item deletion settings.

Question 23

You need to recommend a solution that meets the sales requirements.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Question # 23

Options:

Question 24

You need to recommend a solution to configuration the Microsoft 365 Records management settings by using the CSV file must meet the compliance requirements.

What should you recommend?

Options:

A.

From the Microsoft 365 compliance center, import the CSV file to a file plan.

B.

Use EdmUploadAgent.exe to upload a hash of the CSV to a datastore.

C.

Use a PowerShell command that pipes the import csv cmdlet to the New-RetentionPolicy cmdlet.

D.

Use a PowerShell command that pipes the import-csv cmdlet to the New-Label cmdlet.

Question 25

In Microsoft Exchange Online, you have a retention policy named Policy1 that applies a retention tag named

Tag1.

You plan to remove Tag1 from Policy1.

What will occur when you remove the tag from Policy1?

Options:

A.

The content will remain tagged and the Managed Folder Assistant will process Tag1.

B.

Tag1 will be removed if Policy1 applied the tag to the content.

C.

The content will remain tagged, but the Managed Folder Assistant will ignore Tag1.

Question 26

You have a Microsoft 365 E5 subscription that contains a trainable classifier named Trainable1. You plan to create the items shown in the following table.

Question # 26

Which items can use Trainable1?

Options:

A.

Label2 only

B.

Label1 and Label2 only

C.

Label1 and Policy1 only

D.

Label2 Policy1, and DLP1 only

E.

Label1, Label2, Policy1, and DLP1

Question 27

You have a Microsoft 365 tenant that uses trainable classifiers.

You are creating a custom trainable classifier.

You collect 300 sample file types to use as seed content Some of the file samples are encrypted.

You organize the files into categories as shown in the following table.

Question # 27

Which file categories can be used as seed content?

Options:

A.

Category3 only

B.

Category1 and Category3 only

C.

Category3 and Category5 only

D.

Category3, Category4 and Category5 only

E.

Category1, Category2, Category3. Category4 and Category5

Question 28

You have a Microsoft 365 subscription.

You identify the following data loss prevention (DLP) requirements:

• Send notifications to users if they attempt to send attachments that contain an EU Social Security Number (SSN) or Equivalent ID.

• Prevent any email messages that contain credit card numbers from being sent outside your organization.

• Block the external sharing of Microsoft OneDrive content that contains EU passport numbers.

• Send administrators email alerts if any rule matches occur.

What is the minimum number of DLP policies and rules you must create to meet the requirements? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 28

Options:

Question 29

You have a Microsoft 365 tenant that has data loss prevention (DLP) policies.

You need to review DLP policy matches for the tenant.

What should you use?

Options:

A.

Content explorer

B.

Activity explorer

C.

Compliance Manager

D.

records management events

Question 30

You have a Microsoft 365 E5 subscription that uses Microsoft Teams and contains the users shown in the following table.

Question # 30

You have the retention policies shown in the following table.

Question # 30

The users perform the actions shown in the following table.

Question # 30

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 30

Options:

Question 31

You have a Microsoft 365 E5 subscription that contains a user named User1.

You need to ensure that all email messages that contain attachments are encrypted automatically by using Microsoft Purview Message Encryption.

What should you create?

Options:

A.

a sensitivity label

B.

an information barrier segment

C.

a data loss prevention (DLP) policy

D.

a mail flow rule

Question 32

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.

You plan to deploy a Defender for Cloud Apps file policy that will be triggered when the following conditions are met:

• A file is shared externally.

• A file is labeled as internal only.

Which filter should you use for each condition? To answer, drag the appropriate filters to the correct conditions. Each filter may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

Question # 32

Options:

Question 33

You have a Microsoft 365 subscription that contains a Microsoft 365 group named Group1. Group 1 contains 100 users and has dynamic user membership.

All users have Windows 10 devices and use Microsoft SharePoint Online and Exchange Online.

You create a sensitivity label named Label! and publish Label! as the default label for Group1.

You need to ensure that the users in Group! must apply Label! to their email and documents.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

From the Microsoft Purview compliance portal, modify the settings of the Label! policy.

B.

From the Azure Active Directory admin center, set Membership type for Group! to Assigned.

C.

Install the Azure Information Protection unified labeling client on the Windows 10 devices.

D.

Install the Active Directory Rights Management Services (AD RMS) client on the Windows 10 devices.

E.

From the Microsoft Purview compliance portal, create an auto-labeling policy.

Question 34

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You recently discovered that the developers at your company emailed Azure Storage keys in plain text to third parties.

You need to ensure that when Azure Storage keys are emailed, the emails are encrypted.

Solution: You configure a mail flow rule that matches the text patterns.

Does this meet the goal?

Options:

A.

Yes

B.

No

Question 35

You have a Microsoft 365 E5 subscription.

You create a role group named Rote1.

You need to add a role to Role1 that will enable group members to view the metadata of records that were tagged for deletion automatically at the end of the records' retention period. The solution must use the principle of least privilege.

Which role should you add?

Options:

A.

Review

B.

View-Only Retention Management

C.

Retention Management

D.

Disposition Management

E.

Record Management

Question 36

You need to protect documents that contain credit card numbers from being opened by users outside your company. The solution must ensure that users at your company can open the documents.

What should you use?

Options:

A.

a retention policy

B.

a sensitivity label policy

C.

a sensitivity label

D.

a data loss prevention (DLP) policy

Question 37

You have a Microsoft 365 E5 tenant that uses a domain named contoso.com.

A user named User1 sends link-based, branded emails that are encrypted by using Microsoft Office 365

Advanced Message Encryption to the recipients shown in the following table.

Question # 37

For which recipients can User1 revoke the emails?

Options:

A.

Recipient4 only

B.

Recipient1 only

C.

Recipient1, Recipient2, Recipient3, and Recipient4

D.

Recipient3 and Recipient4 only

E.

Recipient1 and Recipient2 only

Question 38

You need to implement an information compliance policy to meet the following requirements:

    Documents that contain passport numbers from the United States, Germany, Australia, and Japan must be identified automatically.

    When a user attempts to send an email or an attachment that contains a passport number, the user must receive a tooltip in Microsoft Outlook.

    Users must be blocked from using Microsoft SharePoint Online or OneDrive for Business to share a document that contains a passport number.

What is the minimum number of sensitivity labels and auto-labeling policies you should create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 38

Options:

Question 39

You have a Microsoft 365 E5 subscription that contains a security group named Group1 and the users shown in the following table.

Question # 39

You assign the Compliance Manager roles to the users as shown in the following table.

Question # 39

You add two assessments to Compliance Manager as shown in the following exhibit.

Question # 39

For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Question # 39

Options:

Question 40

You plan to implement sensitivity labels for Microsoft Teams.

You need to ensure that you can view and apply sensitivity labels to new Microsoft Teams sites.

What should you do first?

Options:

A.

Run the Set-sposite cmdlet.

B.

Configure the EnableMTPLabels Azure Active Directory (Azure AD) setting.

C.

Create a new sensitivity label scoped to Groups & sites.

D.

Run the Execute-AzureAdLabelSync cmdtet.

Question 41

You have a Microsoft 365 subscription.

You create a retention label named Label! as shown in the following exhibit.

Question # 41

You publish Label1 to SharePoint sites.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

NOTE: Each correct selection is worth one point.

Question # 41

Options:

Question 42

You have the retention label policy shown in the Policy exhibit. (Click the Policy tab.)

Question # 42

Users apply the retention label policy to files and set the asset ID as shown in the following table.

Question # 42

On December 1, 2020, you create the event shown in the Event exhibit. (Click the Event tab.)

Question # 42

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Question # 42

Options:

Question 43

You need to create a retention policy to retain all the files from Microsoft Teams channel conversations and private chats.

Which two locations should you select in the retention policy? Each correct answer present part of the solution.

NOTE: Each correct selection is worth one point.

Options:

A.

Team channel messages

B.

OneDrive accounts

C.

SharePoint sites

D.

Exchange email

E.

Office 365 groups

F.

Team chats

Question 44

While creating a retention label, you discover that the Mark items as a regulatory record option is unavailable.

You need to ensure that the option is available when you create retention labels in the Microsoft Purview compliance portal.

How should you complete the PowerShell script? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Question # 44

Options:

Question 45

You have a data loss prevention (DLP) policy that applies to the Devices location. The policy protects documents that contain States passport numbers.

Users reports that they cannot upload documents to a travel management website because of the policy.

You need to ensure that the users can upload the documents to the travel management website. The solution must prevent the protected content from being uploaded to other locations.

Which Microsoft 365 Endpoint data loss prevention (Endpoint DLP) setting should you configure?

Options:

A.

Unallowed apps

B.

File path exclusions

C.

Service domains

D.

Unallowed browsers

Question 46

You have a Microsoft 365 E5 subscription that contains a retention policy named RP1 as shown in the following table.

Question # 46

You place a preservation lock on RP1. You need to modify RP1.

Which two actions can you perform? Each correct answer NOTE: Each correct selection is worth one point.

Options:

A.

Decrease the retention period of the policy.

B.

Delete the policy.

C.

Increase the retention period of the policy.

D.

Disable the policy.

E.

Remove locations from the policy.

F.

Add locations to the policy.

Question 47

You have a Microsoft 365 tenant that uses trainable classifiers.

You are creating a custom trainable classifier.

You collect 300 sample file types from various geographical locations to use as seed content. Some of the file samples are encrypted.

You organize the files into categories as shown in the following table.

Question # 47

Which file categories can be used as seed content?

Options:

A.

Category4 and Category5 only

B.

Category4 and Category6 only

C.

Category3. and Category5 only

D.

Category1 and Category3 only

Question 48

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 tenant and 500 computers that run Windows 10. The computers are onboarded to the Microsoft 365 compliance center.

You discover that a third-party application named Tailspin_scanner.exe accessed protected sensitive information on multiple computers. Tailspin_scanner.exe is installed locally on the computers.

You need to block Tailspin_scanner.exe from accessing sensitive documents without preventing the application from accessing other documents.

Solution: From the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings, you add a folder path to the file path exclusions.

Does this meet the goal?

Options:

A.

Yes

B.

No

Page: 1 / 32
Total 323 questions