New Year Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

Microsoft SC-400 Microsoft Information Protection Administrator Exam Practice Test

Demo: 48 questions
Total 323 questions

Microsoft Information Protection Administrator Questions and Answers

Question 1

You need to recommend a solution that meets the executive requirements. What should you recommend?

Options:

A.

From the Microsoft 365 compliance center, create a retention policy.

B.

From the Exchange admin center, enable archive mailboxes.

C.

From the Microsoft 365 compliance center, create a retention label.

D.

From the Microsoft 365 compliance center, create a DLP policy.

Question 2

You need to implement a solution to encrypt email. The solution must meet the compliance requirements.

What should you create in the Exchange admin center and the Microsoft 36.S compliance center? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 3

You need to recommend an information governance solution that meets the HR requirements for handling employment applications and resumes.

What is the minimum number of information governance solution components that you should create? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 4

You need to recommend a solution that meets the compliance requirements for protecting the documents in the Data shared folder.

What should you configure in the Microsoft Purview compliance portal?

Options:

A.

a content scan job

B.

a Content Search query

C.

an auto-labeling policy

D.

a DLP policy

Question 5

You need to recommend a solution that meets the Data Loss Prevention requirements for the HR department.

Which three actions should you perform? Each correct answer presents part of the solution. (Choose three.)

NOTE: Each correct selection is worth one point.

Options:

A.

Schedule EdmUploadAgent.exe to hash and upload a data file that contains employee information.

B.

Create a sensitive info type rule package that contains the EDM classification.

C.

Define the sensitive information database schema in the XML format.

D.

Create a sensitive info type rule package that contains regular expressions.

E.

Define the sensitive information database schema in the CSV format.

Question 6

You need to recommend a solution that meets the compliance requirements for Dropbox.

What should you recommend?

Options:

A.

Create a DLP policy that applies to Cloud App Security.

B.

Edit an existing retention label that enforces the item deletion settings.

C.

Create a retention label that enforces the item deletion settings.

D.

Create a DLP policy that applies to devices.

Question 7

You need to recommend a solution that meets the compliance requirements for Dropbox.

What should you recommend?

Options:

A.

Create a DLP policy that applies to devices.

B.

Create a file policy in Microsoft Defender for Cloud Apps that uses the built-in DLP inspection method.

C.

Create a retention label that enforces the item deletion settings.

D.

Edit an existing retention label that enforces the item deletion settings.

Question 8

You need to recommend a solution that meets the compliance requirements for protecting the documents in the Data shared folder. What should you recommend?

Options:

A.

From the Microsoft 365 compliance center, configure a DLP policy.

B.

From the Microsoft 365 compliance center, configure a Content Search query.

C.

From the Microsoft 365 compliance center, configure an auto-labeling policy.

D.

From Azure Information Protection, configure a content scan job.

Question 9

You need to recommend a solution that meets the sales requirements.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Options:

Question 10

You need to recommend a solution that meets the compliance requirements for viewing DLP tooltip

justifications.

What should you recommend?

Options:

A.

Instruct the compliance department users to review the False positive and override report.

B.

Configure a Microsoft Power Automate workflow to route DLP notification emails to the compliance

department.

C.

Instruct the compliance department users to review the DLP incidents report.

D.

Configure an Azure logic app to route DLP notification emails to the compliance department.

Question 11

You need to recommend a solution to configuration the Microsoft 365 Records management settings by using the CSV file must meet the compliance requirements.

What should you recommend?

Options:

A.

From the Microsoft 365 compliance center, import the CSV file to a file plan.

B.

Use EdmUploadAgent.exe to upload a hash of the CSV to a datastore.

C.

Use a PowerShell command that pipes the import csv cmdlet to the New-RetentionPolicy cmdlet.

D.

Use a PowerShell command that pipes the import-csv cmdlet to the New-Label cmdlet.

Question 12

You need to implement a solution that meets the compliance requirements for the Windows 10 computers.

Which two actions should you perform? Each correct answer presents part of the solution.

NOTE: Each coned selection is worth one point.

Options:

A.

Deploy a Microsoft 36S Endpoint data loss prevention (Endpoint DLP) configuration package to the computers.

B.

Configure hybrid Azure AD join for all the computers.

C.

Configure the Microsoft Intune device enrollment settings.

D.

Configure a compliance policy in Microsoft Intune.

E.

auto in Microsoft Defender for Endpoint protection.

Question 13

Task 7

You need to create a retention policy that meets the following requirements:

• Applies to Microsoft Teams chat and Teams channel messages of users that have a department attribute of Sales.

• Retains item for five years from the date they are created, and then deletes them.

Options:

Question 14

Task 8

You need to retain Microsoft SharePoint files that contain the word Falcon for two years from the date they were created, and then delete them.

Options:

Question 15

Task 9

You are investigating a data breach.

You need to retain all Microsoft Exchange items in the mailbox of Alex Wilber that contain the word Falcon and were created in the year 2021.

Options:

Question 16

Task 5

You need to ensure that a group named U.S. Sales can store files containing information subject to General Data Protection Regulation (GDPR) in their OneDrive accounts. All other current GDPR restrictions must remain in effect.

Options:

Question 17

Task 10

You plan to create a data loss prevention (DLP) policy that will apply to content containing the following keywords:

• Tailspin

• litware

• Falcon

You need to create a keyword list that can be used in the DLP policy. You do NOT need to create the DLP policy at this time.

Options:

Question 18

Task 2

You discover that all users can apply the Confidential - Finance label.

You need to ensure that the Confidential - Finance label is available only to the members of the Finance Team group.

Options:

Question 19

Task 6

You plan to implement Endpoint data loss prevention (Endpoint DLP) policies for computers that run Windows.

Users have an application named App1 that stores data locally in a folder named C:\app1\data.

You need to prevent the folder from being monitored by Endpoint DLP.

Options:

Question 20

Task 4

You need to block users from sending emails containing information that is subject to Payment Card Industry Data Security Standard (PCI OSS). The solution must affect only emails.

Options:

Question 21

Task 3

You plan to automatically apply a watermark to the document1 of a project named Falcon.

You need to create a label that will add a watermark of "Project falcon' in red. size-12 font diagonally across the documents.

Options:

Question 22

Task 1

You need to provide users with the ability to manually classify files that contain product information that are stored in SharePoint Online sites. The solution must meet the following requirements:

• The users must be able to apply a classification of Product1 to the files.

• Any authenticated user must be able to open files classified as Product1.

• files classified as Product1 must be encrypted.

Options:

Question 23

You need to meet the technical requirements for the confidential documents.

What should you created first, and what should you use for the detection method? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 24

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth is worth one point.

Options:

Question 25

You have a Microsoft 365 tenant that uses Microsoft Teams.

You create a data loss prevention (DLP) policy to prevent Microsoft Teams users from sharing sensitive information.

You need to identify which locations must be selected to meet the following requirements:

    Documents that contain sensitive information must not be shared inappropriately in Microsoft Teams.

    If a user attempts to share sensitive information during a Microsoft Teams chat session, the message must be deleted immediately.

Which three locations should you select? To answer, select the appropriate locations in the answer area. (Choose three.)

NOTE: Each correct selection is worth one point.

Options:

Question 26

You have a Microsoft 365 tenant.

All Microsoft OneDrive for Business content is retained roe five years.

A user named User1 left your company a year ago, after which the account of User 1 was deleted from Azure Active Directory (Azure AD)

You need to recover an important file that was stored in the OneDrive of User1.

What should you use?

Options:

A.

the Restore-SPODeletedSite PowerShell cmdlet

B.

the OneDrive recycle bin

C.

the Restore-ADObject PowerShell cmdlet

D.

Deleted users in the Microsoft 365 admin center

Question 27

You have a Microsoft 365 E5 subscription.

You are evaluating Data Protection Baseline compliance by using Compliance Manager.

You need to identify improvement actions that meet the following requirements:

• Provide data loss prevention (DLP) policy recommendations.

• Provide Data Protection Baseline recommendations.

Which filter should you use for each requirement? To answer, select the appropriate options in the answer area.

Options:

Question 28

You have a Microsoft SharePoint Online site that contains employee contracts in a document library named

Contracts.

The contracts must be treated as records in accordance with your company's records management policy.

You need to implement a solution to automatically mark all the contracts as records when they are uploaded to

Contracts.

Which two actions should you perform? Each correct answer presents part of the solution. (Choose two.)

NOTE: Each correct selection is worth one point.

Options:

A.

Create a sensitivity label.

B.

Create a retention label.

C.

Configure a default label on the Contracts document library.

D.

D. Create a retention policy.

E.

Create a SharePoint Records Center.

F.

Create a retention lock.

Question 29

You need to provide a user with the ability to view data loss prevention (DLP) alerts in the Microsoft 365 compliance center. The solution must use the principle of least privilege.

Which role should you assign to the use?

Options:

A.

Compliance data administrator

B.

Security operator

C.

Security reader

D.

Compliance administrator

Question 30

You create a retention label policy named Contoso_policy that contains the following labels.

    10 years then delete

    5 years then delete

    Do not retain

Contoso_Policy is applied to content In Microsoft Sharepoint Online sites.

After a couple of days, yon discover the following messages on the Properties page of the label policy.

* Statue Off (Error)

* It's taking longer than expected to deploy the policy

You need to reinitiate the policy.

How should you complete the command? To answer, select the appropriate options in the; answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 31

You have a Microsoft 365 E5 subscription.

You need to review the compliance of the subscription with the General Data Protection Regulation (GDPR) by using Compliance Manager. The solution must minimize administrative effort.

What should you create first?

Options:

A.

a template

B.

review assessments

C.

an assessment

D.

an alert policy to monitor for score changes

Question 32

You have a Microsoft 365 tenant that uses a domain named canstoso.com.

A user named User1 leaves your company. The mailbox of User1 is placed on Litigation Hold, and then the account of User1 is deleted from Azure Active Directory (Azure AD).

You need to copy the content of the User1 mailbox to a folder in the existing mailbox of another user named User2.

How should you complete the PowerShell command? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 33

Your company has a Microsoft 365 tenant that uses a domain named contoso.com.

You are implementing data loss prevention (DLP).

The company's default browser is Microsoft Edge.

During a recent audit, you discover that some users use Firefox and Google Chrome browsers to upload files labeled as Confidential to a third-party Microsoft SharePoint Online site that has a URL of https://m365x076709.sharepoint.com. Users are blocked from uploading the confidential files to the site from Microsoft Edge.

You need to ensure that the users cannot upload files labeled as Confidential from Firefox and Google Chrome to any cloud services.

Which two actions should you perform? Each correct answer presents part of the solution. (Choose two.)

NOTE: Each correct selection is worth one point.

Options:

A.

From the Microsoft 365 Endpoint data loss prevention (Endpoint) DLP settings, add

m365x076709.sharepoint.com as a blocked service domain.

B.

Create a DLP policy that applies to the Devices location.

C.

From the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings, add Firefox and Google

Chrome to the unallowed browsers list.

D.

From the Microsoft 365 compliance center, onboard the devices.

E.

From the Microsoft 365 Endpoint data loss prevention (Endpoint) DLP settings, add contoso.com as an

allowed service domain.

Question 34

You have a Microsoft 365 tenant.

You have a Microsoft SharePoint Online site that contains employment contracts in a folder named

EmploymentContracts. All the files in EmploymentContracts are marked as records.

You need to recommend a process to ensure that when a record is updated, the previous version of the record

is kept as a version of the updated record.

What should you recommend?

Options:

A.

Upload an updated file plan that contains the record definition.

B.

Unlock the record, modify the record, and then lock the record.

C.

Create a copy of the record and enter a version in the file metadata.

D.

Create a new label policy associated to an event that will apply to the record.

Question 35

You have a Microsoft 365 tenant that has devices onboarded to Microsoft Defender for Endpoint as shown in the following table.

You plan to start using Microsoft 365 Endpoint data loss protection (Endpoint DLP).

Which devices support Endpoint DLP?

Options:

A.

Device5 only

B.

Device2 only

C.

Device 1, Device2, Device3, Device4, and Device5

D.

Device3 and Device4 only

E.

Device1 and Device2 only

Question 36

You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

You need to prevent users in the finance department from sharing files with users in the research department. Which type of policy should you configure?

Options:

A.

communication compliance

B.

information barrier

C.

Conditional Access

D.

insider risk management

Question 37

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1. Site1 contains a file named File1.

You have a retention policy named Retention! that has the following settings:

• Retain items for a specific period

o Retention period: 5 years o At the end of the retention period: Delete items automatically

Retention1 is applied to Site.

You need to ensure that File1 is deleted automatically after seven years. The solution must NOT affect the retention of other files on Site1.

What should you do first?

Options:

A.

Move File1 to a new folder and list the excluded locations for Retention1.

B.

Create a new retention policy.

C.

Create and publish a new retention label

D.

Move File1 to a new folder and configure the access control list (ACL) entries for File1.

Question 38

You have a Microsoft 365 E5 subscription that contains a device named Device1.

You need to enable Endpoint data loss prevention (Endpoint DLP) for Device1.

What should you do first in the Microsoft Purview compliance portal?

Options:

A.

Turn on device onboarding.

B.

Add a Microsoft Purview Information Protection scanner cluster.

C.

Onboard Device1 to Microsoft Purview.

D.

Create a Microsoft Purview Information Barriers (IBs) segment.

E.

Enable Microsoft Priva Privacy Risk Management.

Question 39

You plan to create a custom trainable classifier based on an organizational form template.

You need to identity which role based access control (RBAC ) role is required to create the trainable classifier and where to classifier. The solution must use the principle of least privilege.

What should you identify? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Options:

Question 40

You have a Microsoft 365 subscription.

You have a user named User1. Several users have full access to the mailbox of User1.

Some email messages sent to User1 appear to have been read and deleted before the user viewed them.

When you search the audit log in the Microsoft Purview compliance portal to identify who signed in to the mailbox of User1, the results are blank.

You need to ensure that you can view future sign-ins to the mailbox of User1.

YOU run the Set-MailboxFolderPernission -Identity "User1" -User Userlfcontoso.com -AccessRights Owner command.

Does that meet the goal?

Options:

A.

Yes

B.

No

Question 41

You are creating a custom trainable classifier to identify organizational product codes referenced in Microsoft

365 content.

You identify 300 files to use as seed content.

Where should you store the seed content?

Options:

A.

a Microsoft SharePoint Online folder

B.

a Microsoft OneDrive for Business folder

C.

an Azure file share

D.

Microsoft Exchange Online shared mailbox

Question 42

At the end of a project you upload project documents to a Microsoft SharePoint Online library that contains many fifes. Files that have the following naming format must be labeled as Project I

• aei_AA989.docx

• bd_WSOgadocx

• cei_DLF112-docx

• ebc_QQ4S4.docx

• ecc_BB565.docx

You plan to create an auto-apply retention label policy.

What should you use to identify the files, and which regular expression should you use? To answer, select the appropriate options in the answer area.

Options:

Question 43

You have a Microsoft 365 E5 subscription.

Users access their mailbox by using the following apps:

• Outlook Win32

• Outlook on the web

• Outlook for iOS and Android

You create a data loss prevention (DLP) policy named DLP1 that has the following settings:

• Location: Exchange email

• Status: On

• User notifications: On

• Notify users in Office 365 service with a policy tip: Enabled

Which apps display a policy tip when content is matched by using DLP1?

Options:

A.

Outlook Win32 only

B.

Outlook on the web only

C.

Outlook Win32 and Outlook on the web only

D.

Outlook Win32 and Outlook for iOS and Android only

E.

Outlook Win32, Outlook on the web. and Outlook for iOS and Android

Question 44

You have a Microsoft 365 E5 subscription.

You need to prevent users from uploading data loss prevention (DLP)-protected documents to the following third-party websites;

• web1.contoso.com

• web2.contoso.com

The solution must minimize administrative effort.

To what should you set the Service domains setting for Endpoint DLP?

Options:

A.

contoso.com

B.

web'.contoso.com

C.

*.contoso.com

D.

web1xontoso.com and web2.contoso.com

Question 45

You have a Microsoft 365 subscription that uses Microsoft Exchange Online.

You need to receive an alert if a user emails sensitive documents to specific external domains.

What should you create?

Options:

A.

a data loss prevention (DLP) policy that uses the Privacy category

B.

a Microsoft Cloud App Security activity policy

C.

a Microsoft Cloud App Security file policy

D.

a data loss prevention (DLP) alert filter

Question 46

You have a Microsoft 365 E3 subscription.

You plan to assess compliance with ISO/IEC 27001:2013.

From Compliance Manager, you discover that the ISO/IEC 27001:2013 regulatory template for Microsoft 365 is inactive.

What should you do?

Options:

A.

Add recommended assessments.

B.

Add a data connector.

C.

Create a trainable classifier.

D.

Purchase a Microsoft 365 E5 subscription.

Question 47

You have a Microsoft 365 E5 subscription that contains four Microsoft SharePoint Online sites named Site1, Site2, Site3, and Site4.

You have the retention policies shown in the following table.

You have the documents shown in the following table.

User1 moves Doc3 to Site4.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

NOTE: Each correct selection is worth one point.

Options:

Question 48

You are implementing a data classification solution.

The research department at your company requires that documents containing programming code be labeled

as Confidential. The department provides samples of the code from its document library. The solution must

minimize administrative effort.

What should you do?

Options:

A.

Create a custom classifier.

B.

Create a sensitive info type that uses Exact Data Match (EDM).

C.

Use the source code classifier.

D.

Create a sensitive info type that uses a regular expression.

Demo: 48 questions
Total 323 questions