Free SC-401 Questions for Microsoft Administering Information Security in Microsoft 365 SC-401 Exam as PDF & Practice Test Engine
SIMULATION
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
[email protected]
Microsoft 365 Password: XXXXXXXXX
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL "https://admin.microsoft.com", and press Enter.
The following information is for technical support purposes only:
Lab Instance: XXXXXXXXX
Task 3
You need to create a retention label that retains items for 10 years starting from June 1, 2025.
The items must be deleted after the retention period.
You do NOT need to publish or auto-apply the label at this time.
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
[email protected]
Microsoft 365 Password: XXXXXXXXX
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL "https://admin.microsoft.com", and press Enter.
The following information is for technical support purposes only:
Lab Instance: XXXXXXXXX
Task 3
You need to create a retention label that retains items for 10 years starting from June 1, 2025.
The items must be deleted after the retention period.
You do NOT need to publish or auto-apply the label at this time.
Correct Answer:
To create a retention label, sign in to the Microsoft Purview portal and navigate to Solutions > Records management > Policies. Select Publish labels and follow the prompts to configure the label's settings, retention period, and what happens after the period ends.
Step 1: Sign in to the Microsoft Purview portal. You can access it by going to the Microsoft 365 app launcher and selecting "Compliance".
Step 2: In the Microsoft Purview portal, go to Solutions > Records management > Policies and click on Publish labels.
Step 3: Create and configure the retention label
Make the following choices:
Retain items for a specific period: Select 10 years
Start the retention period based: Select June 1, 2025 as start date
At the end of the retention period: Delete items automatically.

Reference:
https://learn.microsoft.com/en-us/purview/retention-settings
Step 1: Sign in to the Microsoft Purview portal. You can access it by going to the Microsoft 365 app launcher and selecting "Compliance".
Step 2: In the Microsoft Purview portal, go to Solutions > Records management > Policies and click on Publish labels.
Step 3: Create and configure the retention label
Make the following choices:
Retain items for a specific period: Select 10 years
Start the retention period based: Select June 1, 2025 as start date
At the end of the retention period: Delete items automatically.

Reference:
https://learn.microsoft.com/en-us/purview/retention-settings
XYZ needs to assign permissions to compliance officers so they can create and manage Data Loss Prevention (DLP) policies but prevent other users from altering these settings. Which permission level should be assigned?
Correct Answer: A
Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
Hotspot Question
You have a Microsoft 365 tenant that uses Microsoft Teams.
You create a data loss prevention (DLP) policy to prevent Microsoft Teams users from sharing sensitive information, You need to identify which locations must be selected to meet the following requirements:
- Documents that contain sensitive information must not be shared
inappropriately in Microsoft Teams.
- If a user attempts to share sensitive information during a Microsoft
Teams chat session, the message must be deleted immediately.
Which three locations should you select? To answer, select the appropriate locations in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 tenant that uses Microsoft Teams.
You create a data loss prevention (DLP) policy to prevent Microsoft Teams users from sharing sensitive information, You need to identify which locations must be selected to meet the following requirements:
- Documents that contain sensitive information must not be shared
inappropriately in Microsoft Teams.
- If a user attempts to share sensitive information during a Microsoft
Teams chat session, the message must be deleted immediately.
Which three locations should you select? To answer, select the appropriate locations in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Reference:
https://learn.microsoft.com/en-us/microsoft-365/compliance/retention
Drag and Drop Question
You have a Microsoft 365 E5 subscription that has data loss prevention (DLP) implemented.
You need to create a custom sensitive info type. The solution must meet the following requirements:
- Match product serial numbers that contain a 10-character alphanumeric string.
- Ensure that the abbreviation of SN appears within six characters of
each product serial number.
- Exclude a test serial number of 1111111111 from a match.
Which pattern settings should you configure for each requirement? To answer, drag the appropriate settings to the correct requirements. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription that has data loss prevention (DLP) implemented.
You need to create a custom sensitive info type. The solution must meet the following requirements:
- Match product serial numbers that contain a 10-character alphanumeric string.
- Ensure that the abbreviation of SN appears within six characters of
each product serial number.
- Exclude a test serial number of 1111111111 from a match.
Which pattern settings should you configure for each requirement? To answer, drag the appropriate settings to the correct requirements. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Microsoft custom sensitive info types use pattern settings to refine detection accuracy for data loss prevention (DLP) policies.
The Primary element defines the main pattern that must be detected. Since we need to match a
10-character alphanumeric string, this should be defined in the primary element.
Character proximity determines how close a supporting keyword (e.g., "SN") must be to the detected data. Since "SN" must be within six characters of the product serial number, this setting ensures a valid match.
Additional checks allow for exceptions and exclusions in the detection logic. This ensures that
1111111111 (a test serial number) is excluded from triggering a match.
You have a Microsoft 365 subscription that contains 100 users and a Microsoft 365 group named Group1.
All users have Windows 11 devices and use Microsoft SharePoint Online and Exchange Online.
A sensitivity label named Label1 is published as the default label for Group1.
You add two sublabels named Sublabel1 and Sublabel2 to Label1.
You need to ensure that the settings in Sublabel1 are applied by default to Group1.
What should you do?
All users have Windows 11 devices and use Microsoft SharePoint Online and Exchange Online.
A sensitivity label named Label1 is published as the default label for Group1.
You add two sublabels named Sublabel1 and Sublabel2 to Label1.
You need to ensure that the settings in Sublabel1 are applied by default to Group1.
What should you do?
Correct Answer: B
Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
Hotspot Question
You create a retention policy as shown in the following exhibit.

A user named User1 deletes a file named File1.docx from a Microsoft SharePoint Online site named Site1.
A user named User2 deletes an email and empties the Deleted Items folder in Microsoft Outlook.
Where is the content retained one year after deletion? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You create a retention policy as shown in the following exhibit.

A user named User1 deletes a file named File1.docx from a Microsoft SharePoint Online site named Site1.
A user named User2 deletes an email and empties the Deleted Items folder in Microsoft Outlook.
Where is the content retained one year after deletion? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/retention?view=o365-worldwide
You have a Microsoft 365 E5 subscription.
You create a sensitivity label named Label1 and publish Label1 to all users and groups.
You have the following files on a computer:
- File1.doc
- File2.docx
- File3.xlsx
- File4.txt
You need to identify which files can have Label1 applied.
Which files should you identify?
You create a sensitivity label named Label1 and publish Label1 to all users and groups.
You have the following files on a computer:
- File1.doc
- File2.docx
- File3.xlsx
- File4.txt
You need to identify which files can have Label1 applied.
Which files should you identify?
Correct Answer: C
Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
Hotspot Question
You have a Microsoft 365 tenant named contoso.com that contains two users named User1 and User2. The tenant uses Microsoft Purview Message Encryption.
User1 plans to send emails that contain attachments as shown in the following table.

User2 plans to send emails that contain attachments as shown in the following table.

For which emails will the attachments be encrypted? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 tenant named contoso.com that contains two users named User1 and User2. The tenant uses Microsoft Purview Message Encryption.
User1 plans to send emails that contain attachments as shown in the following table.

User2 plans to send emails that contain attachments as shown in the following table.

For which emails will the attachments be encrypted? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Box 1: Mail3 only
Box 2: Mail4 and Mail6 only
Reference:
https://support.microsoft.com/en-gb/office/introduction-to-irm-for-email-messages-bb643d33-4a3f-4ac7-9770-fd50d95f58dc?ui=en-us&rs=en-gb&ad=gb#FileTypesforIRM
https://docs.microsoft.com/en-us/microsoft-365/compliance/ome?view=o365-worldwide
https://docs.microsoft.com/en-us/office365/servicedescriptions/exchange-online-service-description/exchange-online-limits#message-limits-1
Hotspot Question
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1 and a sensitivity label named Label1.
The external sharing settings for Site1 are configured as shown in the Site1 exhibit. (Click the Site1 tab.)

The external sharing settings for Label1 are configured as shown in the Label1 exhibit. (Click the Label1 tab.)

Label1 is applied to Site1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1 and a sensitivity label named Label1.
The external sharing settings for Site1 are configured as shown in the Site1 exhibit. (Click the Site1 tab.)

The external sharing settings for Label1 are configured as shown in the Label1 exhibit. (Click the Label1 tab.)

Label1 is applied to Site1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Correct Answer:

Hotspot Question
You plan to implement Microsoft 365 Endpoint data loss prevention (Endpoint DLP).
You need to identify which end user activities can be audited on the endpoints, and which activities can be restricted on the endpoints.
What should you identify for each activity? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You plan to implement Microsoft 365 Endpoint data loss prevention (Endpoint DLP).
You need to identify which end user activities can be audited on the endpoints, and which activities can be restricted on the endpoints.
What should you identify for each activity? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-learn-about
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1.
You need to implement Microsoft Purview data lifecycle management.
What should you create first?
You need to implement Microsoft Purview data lifecycle management.
What should you create first?
Correct Answer: A
Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
Hotspot Question
You have a Microsoft 365 subscription that contains the sensitive information types (SITs) shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 subscription that contains the sensitive information types (SITs) shown in the following exhibit.

Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Box 1: all of the SITs
There are two methods for creating a new SIT:
Create a new SIT from scratch
Copy and modify an existing SIT
Copy and modify an existing SIT
These SITs can't be copied:
Canada driver's license number
EU driver's license number
EU national identification number
EU passport number
EU social security number or equivalent identification
EU tax identification number
International classification of diseases (ICD-10-CM)
International classification of diseases (ICD-9-CM)
U.S. driver's license number
Box 2: Adatum document patterns and Adaturm numbers only
Reference:
https://learn.microsoft.com/en-us/purview/sit-create-a-custom-sensitive-information-type
You have a Microsoft 365 E5 tenant and the Windows Client devices shown in the following table.

To which devices can you apply Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings?

To which devices can you apply Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings?
Correct Answer: D
Vote an answer
Explanation: Only visible for ExamDiscuss members. You can sign-up / login (it's free).
SIMULATION
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
[email protected]
Microsoft 365 Password: XXXXXXXXX
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL "https://admin.microsoft.com", and press Enter.
The following information is for technical support purposes only:
Lab Instance: XXXXXXXXX
Task 4
You need reduce the number of false-positives generated by the General Data Protection Regulation (GDPR) data loss prevention (DLP) policy.
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
[email protected]
Microsoft 365 Password: XXXXXXXXX
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL "https://admin.microsoft.com", and press Enter.
The following information is for technical support purposes only:
Lab Instance: XXXXXXXXX
Task 4
You need reduce the number of false-positives generated by the General Data Protection Regulation (GDPR) data loss prevention (DLP) policy.
Correct Answer:
To reduce false-positives with a GDPR DLP policy, run the policy in audit-only mode first to identify issues, continuously refine the rules based on this data, and train employees on proper data handling.
To run an existing GDPR DLP policy in audit mode, you need to edit the policy in your Microsoft Purview portal and set the policy mode to "simulation" or "test". In the policy configuration, select the option to "Run the policy in simulation mode" or "Test mode" instead of enabling enforcement immediately. This will log any violations without blocking them, allowing you to review the results before a full deployment.
Steps to run a policy in audit (simulation) mode
Step 1: Navigate to DLP policies: Sign in to the Microsoft Purview portal and go to Data loss prevention > Policies.
Step 2: Edit the policy: Select the existing GDPR policy you want to run and choose to edit it.
Step 3: Locate the policy mode settings: In the policy configuration workflow, find the page for policy mode, which may be labeled as "Policy Mode" or "Simulate or turn on the policy".
Step 4: Enable simulation mode: Choose the option to "Run the policy in simulation mode".
Step 5: Configure optional settings: You can also choose to "Show policy tips" in simulation mode to help educate users about potential violations without actually blocking them. [Skip] Step 6: Save and submit: Proceed through the rest of the wizard and select Next and Submit to save your changes.
Reference:
https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp
To run an existing GDPR DLP policy in audit mode, you need to edit the policy in your Microsoft Purview portal and set the policy mode to "simulation" or "test". In the policy configuration, select the option to "Run the policy in simulation mode" or "Test mode" instead of enabling enforcement immediately. This will log any violations without blocking them, allowing you to review the results before a full deployment.
Steps to run a policy in audit (simulation) mode
Step 1: Navigate to DLP policies: Sign in to the Microsoft Purview portal and go to Data loss prevention > Policies.
Step 2: Edit the policy: Select the existing GDPR policy you want to run and choose to edit it.
Step 3: Locate the policy mode settings: In the policy configuration workflow, find the page for policy mode, which may be labeled as "Policy Mode" or "Simulate or turn on the policy".
Step 4: Enable simulation mode: Choose the option to "Run the policy in simulation mode".
Step 5: Configure optional settings: You can also choose to "Show policy tips" in simulation mode to help educate users about potential violations without actually blocking them. [Skip] Step 6: Save and submit: Proceed through the rest of the wizard and select Next and Submit to save your changes.
Reference:
https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp
Hotspot Question
You are implementing Microsoft Purview Advanced Message Encryption for a Microsoft 365 tenant named contoso.com.
You need to meet the following requirements:
- All email to a domain named fabrikam.com must be encrypted
automatically.
- Encrypted emails must expire seven days after they are sent.
What should you configure for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You are implementing Microsoft Purview Advanced Message Encryption for a Microsoft 365 tenant named contoso.com.
You need to meet the following requirements:
- All email to a domain named fabrikam.com must be encrypted
automatically.
- Encrypted emails must expire seven days after they are sent.
What should you configure for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Box 1: A mail flow rule in Exchange admin center
To automatically encrypt all emails sent to a specific domain with Microsoft Purview Advanced Message Encryption, an administrator must first configure a sensitivity label with the desired encryption settings and then create an Exchange mail flow rule (also called a transport rule) in the Microsoft Purview portal to apply that sensitivity label to messages meeting the condition of being sent to the target domain.
Box 2: A custom branded template in Microsoft Exchange Online PowerShell You can use message expiration on emails that your users send to external recipients who use the OME Portal to access encrypted emails. You force recipients to use the OME portal to view and reply to encrypted emails sent by your organization by using a *custom branded template* that specifies an expiration date in PowerShell.
Reference:
https://learn.microsoft.com/en-us/exchange/security-and-compliance/mail-flow-rules/manage-mail-flow-rules
https://learn.microsoft.com/en-us/purview/ome-advanced-expiration
0
0
0
10
