Best Preparations of SC-401 Exam 2026 Microsoft Certified: Information Security Administrator Associate Unlimited 275 Questions [Q30-Q48]

Share

Best Preparations of SC-401 Exam 2026 Microsoft Certified: Information Security Administrator Associate Unlimited 275 Questions

Focus on SC-401 All-in-One Exam Guide For Quick Preparation.

NEW QUESTION # 30
You have a Microsoft 365 E5 subscription that contains a user named User1.
You deploy Microsoft Purview insider risk management.
You need ensure that insider risk management events related to User1 are visible only to specific users.
What should you create?

  • A. a global exclusion
  • B. a priority user group
  • C. a detection group
  • D. an indicator variant

Answer: B

Explanation:
To restrict management of Microsoft Purview Insider Risk Management events to specific users, you can utilize Priority User Groups and Administrative Units. Priority User Groups allow you to designate which users can view data related to specific users in Insider Risk Management, while Administrative Units enable you to scope user permissions to geographical areas or departments.
Priority User Groups (PUGs):
Purpose:
PUGs allow you to create groups of users who are deemed high-risk and designate which users (e.g., investigators, analysts) can view data related to those high-risk users.
How to use:
Create a PUG in the Insider Risk Management settings.
When creating the PUG, you'll designate which users (or Insider Risk Management role groups) can view data related to the users within that PUG.
This ensures that only authorized personnel can access and manage alerts and cases associated with those high-risk users.
Reference:
https://learn.microsoft.com/en-us/purview/insider-risk-management-users


NEW QUESTION # 31
You have a Microsoft 365 E5 subscription that uses Microsoft Purview insider risk management and contains three users named User1, User2, and User3.
All insider risk management policies have adaptive protection enabled and the default conditions for insider risk levels configured.
The users perform the following activities, which trigger insider risk policy alerts:
* User1 performs at least one data exfiltration activity that results in a high severity risk score.
* User2 performs at least three risky user activities within seven days, that each results in a high severity risk score.
* User3 performs at least bwo data exfiltration activities within seven days, that each results in a high severity risk score.
Which insider risk level is assigned to each user? To answer, drag the appropriate levels to the correct users.
Each level may be used once, more than once, or not at all. You may need to drag the split bar between panes or seroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 32
You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.
On January 1, you create the sensitivity label shown in the following table.

On January 2, you publish Label1 to User.
On January 3, User1 creates a Microsoft Word document named Doc1 and applies Label1 to the document.
On January 4, User2 edits Doc1.
On January 15, you increase the content expiry period for Label1 to 28 days.
When will access to Doc1 expire for User2?

  • A. January 24
  • B. January 23
  • C. January 25
  • D. January 31

Answer: A


NEW QUESTION # 33
You are reviewing policies for the SharePoint Online environment.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 34
DRAG DROP
You have a Microsoft 365 subscription that contains 20 data loss prevention (DLP) policies.
You need to identify the following:
# Rules that are applied without triggering a policy alert
# The top 10 files that have matched DLP policies
# Alerts that are miscategorized
Which report should you use for each requirement? To answer, drag the appropriate reports to the correct requirements. Each report may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

The False positive and override report helps identify rules that were applied but did not generate an actual policy alert, which means they were overridden or deemed false positives.
The DLP policy matches report provides details on files that matched DLP policies, including the top 10 files.
The Incident reports report helps analyze and review alerts, including those that may have been miscategorized.


NEW QUESTION # 35
You receive an email that contains a list of words that will be used for a sensitive information type.
You need to create a file that can be used as the source of a keyword dictionary.
In which format should you save the list?

  • A. an XLSX file that contains one word in each cell of the first row
  • B. an XML file that contains a keyword tag for each word
  • C. a text file that has one word on each line
  • D. an ACCDB database file that contains a table named Dictionary

Answer: C

Explanation:
To create a keyword dictionary for a sensitive information type in Microsoft Purview Data Loss Prevention (DLP), you must use a plain text (.txt) file where each keyword is on a separate line.
Format Example (TXT file):
confidential
sensitive
classified
top secret
This format is simple, efficient, and directly compatible with Microsoft 365 DLP policies for keyword dictionaries.
How to use the keyword dictionary?
*Create a text file with one keyword per line.
*Upload it to Microsoft Purview under Data Classification > Sensitive Info Types.
*Use the dictionary in a DLP policy to identify and protect sensitive information.


NEW QUESTION # 36
You have a Microsoft 365 E5 tenant.
You need to add a new keyword dictionary.
What should you create?

  • A. a sensitivity label
  • B. a retention policy
  • C. a trainable classifier
  • D. a sensitive info type

Answer: D

Explanation:
To add a new keyword dictionary in Microsoft Purview Data Loss Prevention (DLP), you must create a Sensitive Information Type (SIT).
Sensitive Info Types (SITs) allow you to define custom detection rules, including keyword dictionaries, regular expressions, and functions for identifying sensitive content in emails, documents, and other Microsoft 365 locations. A keyword dictionary is a list of predefined words/phrases that Microsoft Purview can use to identify and classify content for DLP policies.
Steps to add a keyword dictionary:
1. Go to Microsoft Purview compliance portal
2. Navigate to Data classification > Sensitive info types
3. Create a new sensitive info type
4. Add a keyword dictionary
5. Save and use it in a DLP policy


NEW QUESTION # 37
You have a Microsoft 365 E5 subscription that contains four users named User1. User2, User3, and User4 and a file named File1.docx. File1 has a sensitivity label applied. The label is configured as shown in the following table.

Which users can summarize File1 by using Microsoft 365 Copilot?

  • A. User1 and User2 only
  • B. User1 only
  • C. User1, User2, User3. and User4
  • D. User1, User2. and User3 only

Answer: A

Explanation:
Step 1 - Understand the scenario
* We have a Microsoft 365 E5 subscription with Copilot available.
* File1.docx has a sensitivity label applied.
* The sensitivity label controls usage rights (Owner, Editor, Restricted Editor, Viewer).
* The question: Which users can summarize File1 with Microsoft 365 Copilot?
Step 2 - Sensitivity labels and usage rights
When a sensitivity label is configured to apply encryption with usage rights, each role has different levels of access:
* Owner: Full control (read, edit, reshare, extract, etc.).
* Editor: Can read, edit, and copy content.
* Restricted Editor: Can read and edit in place, but cannot copy, print, or extract content.
* Viewer: Can only read (view) the content.
# Reference: Rights included in usage rights for sensitivity labels
Step 3 - Copilot's requirements for summarization
Microsoft 365 Copilot requires that the user has the ability to read and extract text from the document in order to generate a summary.
* Owners and Editors: # Can both read and extract # Copilot works.
* Restricted Editors: # Cannot copy/extract text # Copilot cannot summarize.
* Viewers: # Can only view # Copilot cannot process content for summarization.
# Reference: Microsoft 365 Copilot and sensitivity labels
"Users must have extract and copy rights in order for Microsoft 365 Copilot to process and summarize labeled documents." Step 4 - Apply to the case
* User1 (Owner) # Can summarize.
* User2 (Editor) # Can summarize.
* User3 (Restricted Editor) # Cannot summarize.
* User4 (Viewer) # Cannot summarize.


NEW QUESTION # 38
You have a Microsoft 365 tenant
You need to create a new sensitive into type for items that contain the following:
* An employee ID number that consists of the hire date of the employee followed by a three digit number
* The words "Employee", "ID", or "Identification" within 300 characters of the employee ID number What should you use for the primary and secondary elements? To answer, select the appropriate options m the answer area NOTE: Each correct selection is worth one point

Answer:

Explanation:

Explanation:

Step 1 - Requirement
We need a custom sensitive information type (SIT) that detects:
An employee ID number in a specific format # hire date + three digits.
This is a pattern-based requirement.
Specific keywords within 300 characters of that ID # "Employee", "ID", or "Identification".
This is a keyword proximity requirement.
Step 2 - Sensitive info type elements in Microsoft 365
When creating custom SITs, you define primary and secondary elements:
Primary element # The main pattern or data to detect (the most defining factor).
Secondary element # Supporting evidence that must be found near the primary element to increase confidence.
Available elements:
Regular expression # Used to define patterns such as date + digits (for employee ID).
Keyword list # Used for lists of words/phrases like "Employee", "ID", "Identification".
Functions # Used for built-in validators like credit card checksum, not relevant here.
# Reference: Create a custom sensitive information type in Microsoft 365 Step 3 - Apply to scenario Employee ID pattern (hire date + 3 digits) # Needs a regular expression # This must be the Primary element.
Keywords ("Employee", "ID", "Identification") within 300 characters # A keyword list # This must be the Secondary element.


NEW QUESTION # 39
Hotspot Question
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1 and a sensitivity label named Label1.
The external sharing settings for Site1 are configured as shown in the Site1 exhibit. (Click the Site1 tab.)

The external sharing settings for Label1 are configured as shown in the Label1 exhibit. (Click the Label1 tab.)

Label1 is applied to Site1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 40
You have two Microsoft 365 subscriptions named Contoso and Fabrikam. The subscriptions contain the users shown in the following table.

You have a sensitivity label named Sensitivity! as shown in the exhibit. (Click the Exhibit tab) you have the files shown in the following table.

For each of the following statements, select yes if the statement is true. Otherwise select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 41
You have a Microsoft 365 E5 subscription that contains a data loss prevention (DLP) policy named DLP1.
DLP1 contains the DLP rules shown in the table.

You need to ensure that when a document matches all the rules, users will see Tip 2.
What should you change?

  • A. the priority setting of Rule2 to 0
  • B. the If there's a match for this rule, stop processing additional DLP policies and rules setting for Rule3 to Enabled
  • C. the priority setting of Rule2 to 2
  • D. the priority setting of Rule3 and Rule4 to 0

Answer: A


NEW QUESTION # 42
HOTSPOT
You plan to create a custom sensitive information type that will use Exact Data Match (EDM).
You need to identify what to upload to Microsoft 365, and which tool to use for the upload.
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

EDM does not store raw data; instead, it requires hashed versions of sensitive data for privacy and security.
To upload the hashed data, Microsoft provides the EDM upload agent. This ensures that the data is securely processed and recognized by the EDM service in Microsoft 365.


NEW QUESTION # 43
You have a Microsoft 365 subscription.
You have a Microsoft SharePoint Online site named Site1. Site1 has a document library that contains the files shown in the following table.

From the Microsoft Purview compliance portal, for Site1 you create a content search named Search1 that has the date in the YYYY-MM-DD format as shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 44
You are creating a custom trainable classifier to Identify organizational product codes referenced in Microsoft
36S content. You identify 300 files to use as seed content When? should you store the seed content?

  • A. an Azure file share
  • B. a Microsoft Exchange Online shared mailbox
  • C. a Microsoft SharePoint Online folder
  • D. a Microsoft OneDrive folder

Answer: C


NEW QUESTION # 45
You have a Microsoft 365 E5 subscription that uses Microsoft Purview.
You need ensure that an incident will be generated when a user visits a phishing website.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 46
You receive an email that contains a list of words that will be used for a sensitive information type.
You need to create a file that can be used as the source of a keyword dictionary.
In which format should you save the list?

  • A. a DOCX file that has one word on each line
  • B. an ACCDB database file that contains a table named Dictionary
  • C. a JSON file that has an element for each word
  • D. a CSV file that contains words separated by commas

Answer: D

Explanation:
Correct:
* a CSV file that contains words separated by commas
* a text file that has one word on each line
Incorrect:
* an ACCDB database file that contains a table named Dictionary
* a DOCX file that has one word on each line
* a JSON file that has an element for each word
* a TSV file that contains words separated by tabs
* an XML file that contains a keyword tag for each word
* an XLSX file that contains one word in each cell of the first row
Note:
To create a keyword dictionary for a sensitive information type in Microsoft Purview Data Loss Prevention (DLP), you must use a plain text (.txt) file (or a .CSV file) where each keyword is on a separate line.
Format Example (TXT file):
confidential
sensitive
classified
top secret
This format is simple, efficient, and directly compatible with Microsoft 365 DLP policies for keyword dictionaries.
How to use the keyword dictionary?
Create a text file with one keyword per line.
Upload it to Microsoft Purview under Data Classification > Sensitive Info Types.
Use the dictionary in a DLP policy to identify and protect sensitive information.
In steps:
Create a keyword dictionary using the Microsoft Purview portal
Use these steps to create or import keywords for a custom dictionary:
1. Sign in to the Microsoft Purview portal Information Protection > Classifiers > Sensitive info types.
2. Select + Create sensitive info type and then enter a Name and Description for your sensitive info type. Choose Next.
3. On the Define patterns for this sensitive info type page, choose + Create pattern.
4. In the New pattern window, select a Confidence level.
5. Choose Add a Primary element and select Keyword dictionary.
*-> 6. On the Add a keyword dictionary flyout, you can:
6a. Upload a dictionary file in TXT or CSV format.
6b. Choose from existing dictionaries.
or create a new dictionary by entering keywords manually and giving it a name.
Reference:
https://learn.microsoft.com/en-us/purview/sit-create-a-keyword-dictionary


NEW QUESTION # 47
Hotspot Question
You have a Microsoft 365 E5 tenant that contains the objects shown in the following table.

You need to restore a Microsoft Word document that was deleted from the Sales channel by User1.
From where can the document be restored, and how long will the document be retained if it is NOT restored? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Box 1: Microsoft Teams
Restore items in the recycle bin that were deleted from SharePoint or Teams When you delete items from a document library or list in Microsoft Teams or SharePoint, they aren't immediately removed. Deleted items go into the SharePoint site recycle bin for a period of time or until they are emptied from the recycle bin. The SharePoint site recycle bin isn't the same as the Windows recycle bin that you see on your desktop.
Box 2: 30 days
Restore a shared library
SharePoint in Microsoft 365 Microsoft Teams
If lots of your SharePoint or Microsoft Teams files get deleted, overwritten, corrupted, or infected by malware, you can restore an entire shared document library to a previous time. The restore will undo all the actions that occurred on both files and folders in the last 30 days.
If your entire library was deleted, see Restore items in the Recycle Bin of a SharePoint site. If you want to correct issues with individual files one at a time, you can restore deleted items or restore a previous version of an item.
Reference:
https://support.microsoft.com/en-us/office/restore-items-in-the-recycle-bin-that-were-deleted-from- sharepoint-or-teams-6df466b6-55f2-4898-8d6e-c0dff851a0be
https://support.microsoft.com/en-us/office/restore-a-shared-library-317791c3-8bd0-4dfd-8254-
3ca90883d39a


NEW QUESTION # 48
......

Guaranteed Success with SC-401 Dumps: https://www.latestcram.com/SC-401-exam-cram-questions.html

Pass Microsoft SC-401 Exam – Experts Are Here To Help You: https://drive.google.com/open?id=1vXKpwqyURyHx-M6KxCHP4yyCYcAzha9M