[Aug-2026] Microsoft SC-401 Actual Questions and Braindumps [Q32-Q53]

Share

[Aug-2026] Microsoft SC-401 Actual Questions and Braindumps

Pass SC-401 Exam with Updated SC-401 Exam Dumps PDF 2026


Microsoft SC-401 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Manage Risks, Alerts, and Activities: This section assesses Security Operations Analysts on insider risk management, monitoring alerts, and investigating security activities. It covers configuring risk policies, handling forensic evidence, and responding to alerts using Microsoft Purview and Defender tools. Candidates must also analyze audit logs and manage security workflows.
Topic 2
  • Implement Data Loss Prevention and Retention: This section evaluates Data Protection Officers on designing and managing data loss prevention (DLP) policies and retention strategies. It includes setting policies for data security, configuring Endpoint DLP, and managing retention labels and policies. Candidates must understand adaptive scopes, policy precedence, and data recovery within Microsoft 365.
Topic 3
  • Protect Data Used by AI Services: This section evaluates AI Governance Specialists on securing data in AI-driven environments. It includes implementing controls for Microsoft Purview, configuring Data Security Posture Management (DSPM) for AI, and monitoring AI-related security risks to ensure compliance and protection.
Topic 4
  • Implement Information Protection: This section measures the skills of Information Security Analysts in classifying and protecting data. It covers identifying and managing sensitive information, creating and applying sensitivity labels, and implementing protection for Windows, file shares, and Exchange. Candidates must also configure document fingerprinting, trainable classifiers, and encryption strategies using Microsoft Purview.

 

NEW QUESTION # 32
You have a Microsoft 365 subscription that uses retention label policies.
You need to identify all the changes made to retention labels during the last 30 days.
What should you use in the Microsoft Purview portal?

  • A. Use data search
  • B. Content search
  • C. Reports
  • D. Activity explorer

Answer: D

Explanation:
Activity explorer rounds out this suite of functionality by allowing you to monitor what's being done with your labeled content. Activity explorer provides a historical view of activities on your labeled content. The activity information is collected from the Microsoft 365 unified audit logs, transformed, and made available in the Activity explorer UI. Activity explorer reports on up to 30 days worth of data.
Reference:
https://learn.microsoft.com/en-us/microsoft-365/compliance/data-classification-activity-explore


NEW QUESTION # 33
You have a Microsoft 365 E5 subscription that uses Microsoft Purview.
You are creating an exact data match (EDM) classifier named EDM1.
For EDM1, you upload a schema file that contains the fields shown in the following table.

What is the maximum number of primary elements that EDM1 can have?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A

Explanation:
In Microsoft Purview Exact Data Match (EDM) classifiers, a primary element is a unique, identifying field used for data matching. EDM allows up to two primary elements per schema.
From the provided table, the Match mode indicates how data is analyzed:
*PP (EU Passport Number) → Likely a primary element because it's unique.
*Name (All Full Names) → Typically not a primary element as names are common.
*DateOfBirth (Single-token) → Usually a secondary element, not unique.
*AccountNumber (Multi-token) → Can be a primary element, as it's a unique identifier.
*Since EDM supports a maximum of two primary elements, the correct answer is 2.


NEW QUESTION # 34
You have a Microsoft 36S ES subscription that contains two Windows devices named Devicel1and Device2 Device1 has the default browser set to Microsoft Edge. Devke2 has the default browser set to Google Chrome.
You need to ensure that Microsoft Purview insider risk management can collect signals when a user copies files to a USB device by using their default browser.
What should you deploy to each device? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

Step 1 - Scenario
The requirement is to ensure Microsoft Purview Insider Risk Management can collect signals when a user copies files to a USB device using their default browser. The devices differ by browser type:
Device1 # Default browser = Microsoft Edge
Device2 # Default browser = Google Chrome
Step 2 - Signal collection methods in Insider Risk Management
Insider Risk Management uses Microsoft Purview Information Protection client and Purview browser extensions to collect activity signals.
For Microsoft Edge (Chromium-based), insider risk signals are collected via the Microsoft Purview Information Protection client.
For Google Chrome, signals are collected through the Microsoft Purview extension (available in the Chrome Web Store).
The Microsoft Defender Browser Protection extension is for web protection against malicious sites, not for insider risk activity signals, so it is irrelevant here.
Step 3 - Microsoft Reference
Microsoft documentation:
"For insider risk signals collection in Microsoft Edge, the Microsoft Purview client must be deployed. For Google Chrome, the Microsoft Purview extension is required." Reference: Insider risk management activity signals


NEW QUESTION # 35
You have a Microsoft 36515 subscription tha1 contains a Microsoft SharePoint Online site named Site1 Site1 contains three tiles named File1. File2 and File3.
You create the data loss prevention (DIP) policies shown in the following table.

The DIP rule matches for each tile are shown in the following table.

How many DIP policy matches events will be added to Activity explorer, and how many policy matches will be added to the DLP incidents report? To answer, select the appropriate options m the answer area.

Answer:

Explanation:

Explanation:

Activity Explorer logs a DLP rule match event each time any DLP rule condition is met on a file.
File1 matches Rule11 and Rule12 # 2 events
File2 matches Rule21 and Rule22 # 2 events
File3 matches Rule11 and Rule22 # 2 events
Total events in Activity Explorer = 2 + 2 + 2 = 6.
Microsoft notes that Activity explorer shows granular DLP activities such as policy rule matches per item.
The DLP incidents report aggregates by policy match per item, not by each rule in that policy. Multiple rules from the same policy on the same item count as one incident; if different policies match the same item, each policy creates its own incident.
File1: Rules from DLP1 only # 1 incident
File2: Rules from DLP2 only # 1 incident
File3: One rule from DLP1 and one from DLP2 # 2 incidents
Total incidents = 1 + 1 + 2 = 4.
References: Microsoft Purview DLP explains that Activity explorer records detailed DLP activities, while DLP incidents are created when a policy match occurs for an item, and multiple rule matches within a single policy are consolidated into a single incident for that item.


NEW QUESTION # 36
You have a Microsoft 365 £5 subscription.
You have a Microsoft Purview Advanced Message Encryption branding template named 0ME1.
You need to create a Microsoft Exchange Online mail flow rule to apply OME1 to email.
How should you configure the rule? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

Step 1 - Requirement
You need to configure a mail flow rule in Exchange Online to apply a Microsoft Purview Advanced Message Encryption (OME) branding template named OME1.
Step 2 - Mail Flow Rule Conditions
In Exchange Online, to trigger encryption based on sensitivity labels (classifications):
You use the condition "Apply this rule if: The sender ... Includes the classification".
This lets the rule detect when the sender applies a particular sensitivity label (classification) to the email.
Step 3 - Mail Flow Rule Action
To apply a custom branding template (such as OME1), you configure the action:
"Modify the message security".
This is the action that allows applying encryption and assigning a specific OME template for branding.


NEW QUESTION # 37
You need to create a trainable classifier that can be used as a condition in an auto-apply retention label policy.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:


NEW QUESTION # 38
You have a Microsoft 365 E5 subscription that contains two users named User! and User2. The subscription has a data loss prevention (DLP) policy named Policy 1.
User2 sends an outbound message that generates a false positive for Policy1.
You need to ensure that User1 can download the message that generated the alert The solution must follow the principle of least privilege.
To which role group should you add User1?

  • A. Security Operator
  • B. eDiscovery Manager
  • C. Data Investigator
  • D. Global Reader

Answer: C


NEW QUESTION # 39
You have a Microsoft 365 E5 subscription that contains a user named User1.
You deploy Microsoft Purview insider risk management.
You need ensure that insider risk management events related to User1 are visible only to specific users.
What should you create?

  • A. a priority user group
  • B. a global exclusion
  • C. a detection group
  • D. an indicator variant

Answer: A

Explanation:
To restrict management of Microsoft Purview Insider Risk Management events to specific users, you can utilize Priority User Groups and Administrative Units. Priority User Groups allow you to designate which users can view data related to specific users in Insider Risk Management, while Administrative Units enable you to scope user permissions to geographical areas or departments.
Priority User Groups (PUGs):
Purpose:
PUGs allow you to create groups of users who are deemed high-risk and designate which users (e.g., investigators, analysts) can view data related to those high-risk users.
How to use:
Create a PUG in the Insider Risk Management settings.
When creating the PUG, you'll designate which users (or Insider Risk Management role groups) can view data related to the users within that PUG.
This ensures that only authorized personnel can access and manage alerts and cases associated with those high-risk users.
Reference:
https://learn.microsoft.com/en-us/purview/insider-risk-management-users


NEW QUESTION # 40
You have a Microsoft 36S ES subscription.
You plan to use the Microsoft Purview portal to map human resources (HR) data for use with insider risk management policies.
You need to add a data connector to import the HR data.
What should you do first and in which format should you import the data? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 41
You have a Microsoft 365 IS subscription that contains the resources shown in the following table.

The subscription contains a Windows 11 device named Device 1 and has the Microsoft Purview Information Protection client installed. Device i contains the resources shown in the following table.

You publish a sensitivity label named Label1 to User1 and Group1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Answer:

Explanation:

Explanation:

Step 1 - Label publishing and scope
The sensitivity label Label1 is published to User1 and Group1.
User1 # Directly included in label publishing.
User2 # Member of Group1, so also included indirectly.
This means both User1 and User2 are eligible to use Label1.
Step 2 - File vs Folder labeling with the Information Protection client The Microsoft Purview Information Protection (AIP unified labeling) client can apply labels to files such as .
docx, .png, .pdf, etc.
It cannot label folders directly. Labels are applied to items (files and emails), not folders.
Reference: Apply sensitivity labels using the AIP client
Step 3 - Analyze each statement
User1 can apply Label1 to File1.png
File1.png is a file type supported by the Information Protection client.
User1 has Label1 published directly.
answer: Yes
User1 can apply Label1 to Folder2
Sensitivity labels cannot be applied to folders in File Explorer.
answer: No
User2 can apply Label1 to File2.docx
File2.docx is a supported file type (Word document).
User2 is a member of Group1, and Label1 is published to Group1.
answer: Yes


NEW QUESTION # 42
Your company has Microsoft 369 E5 subscription and plans to use Microsoft Purview Advanced Message Encryption.
Each product group at your company must show a distinct product logo in encrypted emails instead of the standard Microsoft 365 logo.
What should you do to create the branding templates?

  • A. Run the Set-IRMConfigurationcmdlet.
  • B. Create an RMS template.
  • C. Create a Transport rule.
  • D. Run the New-OMEConfigurationcmdlet.

Answer: D

Explanation:
https://docs.microsoft.com/en-us/microsoft-365/compliance/add-your-organization-brand-to- encrypted-messages


NEW QUESTION # 43
SIMULATION
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
[email protected]
Microsoft 365 Password: XXXXXXXXX
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL "https://admin microsoft.com", and press Enter.
The following information is for technical support purposes only:
Lab Instance: XXXXXXXX.
Task 2
You discover that all users can apply the Confidential - Finance label.
You need to ensure that the Confidential - Finance label is available only to the members of the Leadership group.

Answer:

Explanation:
Assign sensitivity labels to Microsoft 365 groups in Microsoft Entra ID Microsoft Entra ID supports applying sensitivity labels published by the Microsoft Purview compliance portal to Microsoft 365 groups. Sensitivity labels apply to groups across services like Outlook, Microsoft Teams, and SharePoint.
Assign a label to an existing group in the Microsoft Entra admin center Step 1: Sign in to the Microsoft Entra admin center as at least a Global Administrator.
Step 2: Select Microsoft Entra ID.
Step 3: Select Groups
Step 4: From the All groups page, select the group that you want to label.
Step 5: On the selected group's page, select Properties and select a sensitivity label from the list.
Select the Confidential - Finance label

Step 6: Select Save to save your changes.
Reference:
https://learn.microsoft.com/en-us/entra/identity/users/groups-assign-sensitivity-labels


NEW QUESTION # 44
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1.
Site1 contains three files named File1, File2, and File3.
You create the data loss prevention (DLP) policies shown in the following table.

The DLP rule matches for each file are shown in the following table.

How many DLP policy matches events will be added to Activity explorer, and how many policy matches will be added to the DLP incidents report? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 45
You have a Microsoft 365 E5 subscription.
Your company has two departments named department1 and department2.
You configure an information barrier (IB) policy that prevents communication between the users in department1 and department2.
You discover that a user named User1 in department1 can still communicate with the users in department2. You validate that the policy works properly for all other users.
You need to ensure that User1 cannot communicate with the department2 users.
What should you modify?

  • A. the IB segments
  • B. the IB policy
  • C. the group assignments of User1
  • D. the user account attributes of User1

Answer: D

Explanation:
https://learn.microsoft.com/en-us/purview/information-barriers-attributes


NEW QUESTION # 46
Case Study 1 - Contoso, Ltd
Overview
Contoso, Ltd. is a consulting company that has a main office in Montreal and three branch offices in Seattle, Boston, and Johannesburg.
Existing Environment
Microsoft 365 Environment
Contoso has a Microsoft 365 E5 tenant. The tenant contains the administrative user accounts shown in the following table.

Users store data in the following locations:
- SharePoint sites
- OneDrive accounts
- Exchange email
- Exchange public folders
- Teams chats
- Teams channel messages
When users in the research department create documents, they must add a 10-digit project code to each document. Project codes that start with the digits 999 are confidential.
SharePoint Online Environment
Contoso has four Microsoft SharePoint Online sites named Site1, Site2, Site3, and Site4.
Site2 contains the files shown in the following table.

Two users named User1 and User2 are assigned roles for Site2 as shown in the following table.

Site3 stores documents related to the company's projects. The documents are organized in a folder hierarchy based on the project.
Site4 has the following two retention policies applied:
- Name: Site4RetentionPolicy1
Locations to apply the policy: Site4
Delete items older than: 2 years
Delete content based on: When items were created
- Name: Site4RetentionPolicy2
Locations to apply the policy: Site4
Retain items for a specific period: 4 years
Start the retention period based on: When items were created
At the end of the retention period: Do nothing
Problem Statements
Management at Contoso is concerned about data leaks. On several occasions, confidential research department documents were leaked.
Requirements
Planned Changes
Contoso plans to create the following data loss prevention (DLP) policy:
- Name: DLPpolicy1
Locations to apply the policy: Site2
Conditions:
Content contains any of these sensitive info types: SWIFT Code
- Instance count: 2 to any
Actions: Restrict access to the content
Technical Requirements
Contoso must meet the following technical requirements:
- All administrative users must be able to review DLP reports.
- Whenever possible, the principle of least privilege must be used.
- For all users, all Microsoft 365 data must be retained for at least
one year.
- Confidential documents must be detected and protected by using
Microsoft 365.
- Site1 documents that include credit card numbers must be labeled
automatically.
- All administrative users must be able to create Microsoft 365
sensitivity labels.
- After a project is complete, the documents in Site3 that relate to
the project must be retained for 10 years.
Drag and Drop Question
You need to meet the technical requirements for the Site1 documents.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

Explanation:

Explanation:
Create a retention label. -> Has nothing to do with information protection.
Create a sensitive info type. -> Not needed because for credit cards, there is a built-in one.


NEW QUESTION # 47
Hotspot Question
You have a Microsoft 365 E5 subscription that uses Microsoft Teams and contains the users shown in the following table.

You have the retention policies shown in the following table.

The users perform the actions shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: No
It will be retained for seven years.
Both Policy1 and Policy2 apply.
If there is a conflict in how long to retain the same content, it is retained in the secured location for the longest retention period.
Note: If you configure a Teams retention policy to retain chats or channel messages, users Box 2: No User2 creates the message in chat. Policy2 applies. The message will be retained for 5 years.
Box 3: Yes
After a retention policy is configured for chat and channel messages, a timer job from the Exchange service periodically evaluates items in the hidden mailbox folder where these Teams messages are stored. The timer job typically takes 1-7 days to run. When these items have expired their retention period, they are moved to the SubstrateHolds folder-another hidden folder that's in every user or group mailbox to store "soft-deleted" items before they're permanently deleted.
Messages remain in the SubstrateHolds folder for at least 1 day, and then if they're eligible for deletion, the timer job permanently deletes them the next time it runs.
Reference:
https://docs.microsoft.com/en-us/microsoftteams/retention-policies
https://docs.microsoft.com/en-us/microsoft-365/compliance/retention-policies-teams


NEW QUESTION # 48
HOTSPOT
You are reviewing policies for the SharePoint Online environment.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

Understanding Site4's Retention Policies:
# Site4RetentionPolicy1 deletes items older than 2 years from creation. If a file was created on January 1,
2021, it would be deleted after January 1, 2023.
# Site4RetentionPolicy2 retains files for 4 years from creation. If a file was created on January 1, 2021, it will be kept until January 1, 2025, but not deleted after that (policy states "Do nothing").
Statement 1 - Yes, because Site4RetentionPolicy2 ensures files are retained for 4 years.
Statement 2 - Yes, because Site4RetentionPolicy2 retains the file for 4 years (until January 1, 2025).
Statement 3 - No, because retention is only for 4 years (until January 1, 2025). After that, the policy does
"nothing," meaning the file is no longer recoverable after that period.
Exam Topic Breakdown
Exam Topic Number of Questions


NEW QUESTION # 49
You need to create a retention policy to delete content after seven years from the following locations:
* Exchange Online email
* SharePoint Online sites
* OneDrive accounts
* Microsoft 365 Groups
* Teams channel messages
* Teams chats
What is the minimum number of retention policies that you should create?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A


NEW QUESTION # 50
You have a Microsoft 365 subscription. Auditing is enabled.
A user named User1 is a member of a dynamic security group named Group1.
You discover that User1 is no longer a member of Group1.
You need to search the audit log to identify why User1 was removed from Group1.
Which two activities should you use in the search? To answer, select the appropriate activities in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 51
You have a Microsoft 36S ES subscription that contains the devices shown in the following table.

You publish Microsoft Purview Information Protection sensitivity labels.
You plan to deploy the information protection client to the devices. The solution must ensure that the labels can be applied to sensitive images and documents On which devices can you install the information protection client, and what should users use to apply labels?
To answer, select the appropriate options in the answer area.

Answer:

Explanation:

Explanation:

Step 1 - Understanding the requirement
The task is about applying Microsoft Purview Information Protection sensitivity labels to sensitive images and documents using the Azure Information Protection (AIP) unified labeling client.
Sensitivity labels in Purview can be applied in Microsoft 365 apps (Word, Excel, Outlook, PowerPoint), but to label non-Office files like images, PDFs, and other documents, users must use the AIP unified labeling client.
With the AIP client installed, labels can be applied directly in File Explorer by right-clicking the file.
Step 2 - Device compatibility
The AIP unified labeling client runs on Windows devices only.
In the question's context (based on the provided dropdowns), all listed devices (Device1, Device2, Device3) are compatible Windows endpoints.
Therefore, the AIP client can be deployed to all three devices.
Step 3 - How users apply labels
For Office documents # labels can be applied from the ribbon inside Word, Excel, PowerPoint.
For other file types (images, PDFs, text files, etc.) # labels must be applied using File Explorer via the AIP client.
# Reference:
Install and use the Azure Information Protection unified labeling client Apply sensitivity labels to files and emails in Microsoft Purview


NEW QUESTION # 52
HOTSPOT
How many files in Site2 can User1 and User2 access after you turn on DLPpolicy1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
A screenshot of a computer AI-generated content may be incorrect.

Understanding DLP Policy Impact on File Access
The DLP policy (DLPpolicy1) applies to Site2 and restricts access when:
# Content contains SWIFT Codes.
# Instance count is 2 or more.
File Analysis (Based on SWIFT Codes Count)
A screenshot of a computer AI-generated content may be incorrect.

Files that remain accessible (not restricted by DLP):
# File1.docx (Contains only 1 SWIFT Code # Below restriction threshold) User access after DLP policy is applied:
A screenshot of a computer AI-generated content may be incorrect.

User1 (Site Owner):
# Has higher privileges and can override DLP restrictions (through admin intervention).
# Can access 2 files (File1.docx + override access to another file).
User2 (Site Visitor):
# Has read-only access but DLP blocks access to restricted files.
# Can only access 1 file (File1.docx), since all others are restricted.


NEW QUESTION # 53
......

Latest SC-401 Pass Guaranteed Exam Dumps with Accurate & Updated Questions: https://www.prepawayexam.com/Microsoft/braindumps.SC-401.ete.file.html

SC-401 Exam Brain Dumps - Study Notes and Theory: https://drive.google.com/open?id=19cM14AhV-eDdyw2vV0HWJbP07F0FrvTA