Get Started: SC-400 Exam [2022] Dumps Microsoft PDF Questions
SC-400 Premium Exam Engine pdf Download
Exam SC-400: Microsoft Information Protection Administrator
The Information Protection Administrator plans and implements controls that meet organizational compliance needs. This person is responsible for translating requirements and compliance controls into technical implementation. They assist organizational control owners to become and stay compliant.
They work with information technology (IT) personnel, business application owners, human resources, and legal stakeholders to implement technology that supports policies and controls necessary to sufficiently address regulatory requirements for their organization. They also work with the compliance and security leadership such as a Chief Compliance Officer and Security Officer to evaluate the full breadth of associated enterprise risk and partner to develop those policies.
This person defines applicable requirements and tests IT processes and operations against those policies and controls. They are responsible for creating policies and rules for content classification, data loss prevention, governance, and protection.
Part of the requirements for: Microsoft Certified: Information Protection Administrator Associate
Schedule exam
Languages: English, Chinese (Simplified), Japanese, Korean
Retirement date: none
This exam measures your ability to accomplish the following technical tasks: implement information protection; implement data loss prevention; and implement information governance.
NEW QUESTION 10
You have a Microsoft 365 E5 tenant and the Windows 10 devices shown in the following table.
To which devices can you apply Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings?
- A. Device1, Device2, Device3, and Device4
- B. Device1, Device3, and Device4 only
- C. Device1 only
- D. Device1 and Device3 only
- E. Device1 and Device2 only
Answer: E
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-getting-started?view=o365-worldwide
NEW QUESTION 11
You have a Microsoft SharePoint Online site named Site1 and a sensitivity label named Sensitivity1. Sensitivity1 adds a watermark and a header to content.
You create a policy to automatically apply Sensitivity1 to emails in Microsoft Exchange Online and Site1.
How will Sensitivity1 mark matching emails and Site1 documents? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/sensitivity-labels?view=o365-worldwide
NEW QUESTION 12
You need to recommend a solution that meets the compliance requirements for Dropbox.
What should you recommend?
- A. Create a DLP policy that applies to devices.
- B. Edit an existing retention label that enforces the item deletion settings.
- C. Create a retention label that enforces the item deletion settings.
- D. Create a DLP policy that applies to Cloud App Security.
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/dlp-use-policies-non-microsoft-cloud-apps?
view=o365-worldwide
Overview
Contoso, Ltd. is a consulting company that has a main office in Montreal and three branch offices in Seattle, Boston, and Johannesburg.
Microsoft 365 Environment
Contoso has a Microsoft 365 FS tenant I he tenant contains the administrative user accounts shown in the following table.
Users store data In the following locations:
* SharePoint sites
* OneDrive accounts
* Exchange email
* Exchange public folders
* Teams chats
* Teams channel messages
When users in the research department create documents, they must add a 10-dig>t project code to each document. Project codes that start with the digits 999 are confidential.
SharePoint Online Environment
Contoso has four Microsoft SharePoint Online sites named Site1. Site2. Site3. and Site4.
Site2 contains the files shown in the following table.
Two users named User1 and User2 are assigned roles for Site2 as shown in the following table.
Sile3 stores documents related to the company's projects. The documents are organized In a folder hierarchy based on the project.
Slte4 has the following two retention policies applied:
* Name: SitetKetentionPolicy1
* Locations to apply the policy: Site4
* Delete items older than:2 years
* Delete content based on: When items were created
* Name: Site4RetentionPolicy2
* Locations to apply the policy. Sile4
* Retain items for a specific period: 4 years
* Start the retention period based on: When items were created
* At the end of the retention period: Do nothing
NEW QUESTION 13
You are creating a custom trainable classifier to identify organizational product codes referenced in Microsoft
365 content.
You identify 300 files to use as seed content.
Where should you store the seed content?
- A. an Azure file share
- B. Microsoft Exchange Online shared mailbox
- C. a Microsoft OneDrive for Business folder
- D. a Microsoft SharePoint Online folder
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/classifier-get-started-with?view=o365-worldwide
NEW QUESTION 14
You have a Microsoft 365 tenant that uses data loss prevention (DLP) to protect sensitive information.
You create a new custom sensitive info type that has the matching element shown in the following exhibit.
The supporting elements are configured as shown in the following exhibit.
The confidence level and character proximity are configured as shown in the following exhibit.
For each of the following statements, select Yes if statement is true. Otherwise, select No NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/create-a-custom-sensitive-information-type?view=o365-worldwide
NEW QUESTION 15
You have a Microsoft 365 tenant that uses records management.
You use a retention label to mark legal files stored in a Microsoft SharePoint Online document library as regulatory records.
What can you do to the legal files?
- A. Remove the retention label of the files.
- B. Move the files to a different folder within the document library.
- C. Edit the properties of the files.
- D. Delete the content from the files.
Answer: B
Explanation:
Explanation/Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/records-management?view=o365- worldwide#records
NEW QUESTION 16
You have a data loss prevention (DLP) policy configured for endpoints as shown in the following exhibit.
From a computer named Computer1, 3 user can sometimes upload files to cloud services and sometimes cannot. Other users experience the same issue. What are two possible causes of the issue? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
- A. The Copy to clipboard action is set to Audit only.
- B. The computers are NOT onboarded to the Microsoft 365 compliance center.
- C. There are file path exclusions in the Microsoft 365 Endpoint data loss prevention (Endpoint DIP) settings.
- D. The Access by unallowed apps action is set to Audit only.
- E. The unallowed browsers in the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings are NOT configured.
Answer: C,D
NEW QUESTION 17
You need to recommend a solution that meets the sales requirements.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
Explanation
Graphical user interface, text, application, chat or text message Description automatically generated
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/classifier-get-started-with?view=o365-worldwide
NEW QUESTION 18
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 tenant and 500 computers that run Windows 10. The computers are onboarded to the Microsoft 365 compliance center.
You discover that a third-party application named Tailspin_scanner.exe accessed protected sensitive information on multiple computers. Tailspin_scanner.exe is installed locally on the computers.
You need to block Tailspin_scanner.exe from accessing sensitive documents without preventing the application from accessing other documents.
Solution: From the Cloud App Security portal, you mark the application as Unsanctioned.
Does this meet the goal?
- A. No
- B. Yes
Answer: A
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-using?view=o365-worldwide
NEW QUESTION 19
You have a data loss prevention (DLP) policy configured for endpoints as shown in the following exhibit.
From a computer named Computer1, 3 user can sometimes upload files to cloud services and sometimes cannot. Other users experience the same issue. What are two possible causes of the issue? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.
- A. The Copy to clipboard action is set to Audit only.
- B. The computers are NOT onboarded to the Microsoft 365 compliance center.
- C. There are file path exclusions in the Microsoft 365 Endpoint data loss prevention (Endpoint DIP) settings.
- D. The Access by unallowed apps action is set to Audit only.
- E. The unallowed browsers in the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings are NOT configured.
Answer: C,D
NEW QUESTION 20
You create a data loss prevention (DLP) policy that meets the following requirements:
* Prevents guest users from accessing a sensitive document shared during a Microsoft Teams chat
* Prevents guest users from accessing a sensitive document stored in a Microsoft Teams channel Which location should you select for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/dlp-microsoft-teams?view=o365-worldwide
https://docs.microsoft.com/en-us/microsoftteams/sharepoint-onedrive-interact
NEW QUESTION 21
You need to implement a solution to encrypt email. The solution must meet the compliance requirements.
What should you create in the Exchange admin center and the Microsoft 36.S compliance center? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
NEW QUESTION 22
Each product group at your company must show a distinct product logo in encrypted emails instead of the standard Microsoft Office 365 logo.
What should you do to create the branding templates?
- A. Create an RMS template.
- B. Create a Transport rule.
- C. Run the Set-IRMConfiguration cmdlet.
- D. Run the New-OMEConfiguration cmdlet.
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/add-your-organization-brand-to-encryptedmessages?view=o365-worldwide
NEW QUESTION 23
Your company manufactures parts that are each assigned a unique 12-character alphanumeric serial number.
Emails between the company and its customers refer in the serial number.
You need to ensure that ail Microsoft Exchange Online emails containing the serial numbers are retained for five years.
Which three objects should you create? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
- A. a retention polity
- B. a data loss prevention (DLP) policy
- C. a retention label
- D. a sensitivity label
- E. an auto-labeling policy
- F. a trainable classifier
- G. a sensitive info type
Answer: B,E,G
NEW QUESTION 24
You have a Microsoft 365 tenant that uses Microsoft Office 365 Message Encryption (OME).
You need to ensure that any emails containing attachments and sent to [email protected] are encrypted automatically by using OME.
What should you do?
- A. From the Exchange admin center, create a mail flow rule.
- B. From the Microsoft 365 security center, create a Safe Attachments policy.
- C. From the Microsoft 365 compliance center, configure an auto-apply retention label policy.
- D. From the Exchange admin center, create a new sharing policy.
Answer: A
Explanation:
Explanation
You can create mail flow rules to help protect email messages you send and receive. You can set up rules to encrypt any outgoing email messages and remove encryption from encrypted messages coming from inside your organization or from replies to encrypted messages sent from your organization.
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/define-mail-flow-rules-to-encrypt-email?view=o365
NEW QUESTION 25
You plan to implement Microsoft 365 Endpoint data loss prevention (Endpoint DLP).
You need to identify which end user activities can be audited on the endpoints, and which activities can be restricted on the endpoints.
What should you identify for each activity? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-learn-about?view=o365-worldwide
NEW QUESTION 26
Your company has a Microsoft 365 tenant.
The company performs annual employee assessments. The assessment results are recorded in a document named Assessment I cmplatc.docx that is created by using Microsoft Word template. Copies of the employee assessments are sent to employees and their managers. The assessment copies are stored in mailboxes, Microsoft SharePoint Online sites, and OneDrive for Business folders. A copy of each assessment is also stored in a SharePoint Online folder named Assessments.
You need to create a data loss prevention (DLP) policy that prevents the employee assessments from being emailed to external users. You will use a document fingerprint to identify the assessment documents.
What should you include in the solution?
- A. Create a fingerprint of TOO sample documents in the Assessments folder.
- B. Create a sensitive info type that uses Exact Data Match (EDM).
- C. Import TOO sample documents from the Assessments folder to a seed folder.
- D. Create a fingerprint of AssessmentTemplate.docx.
Answer: C
NEW QUESTION 27
You are planning a data loss prevention (DLP) solution that will apply to computers that run Windows 10.
You need to ensure that when users attempt to copy a file that contains sensitive information to a USB storage device, the following requirements are met:
* If the users are members of a group named Group1, the users must be allowed to copy the file, and an event must be recorded in the audit log.
* All other users must be blocked from copying the file.
What should you create?
- A. one DLP policy that contains one DLP rule
- B. two DLP policies that each contains on DLP rule
- C. one DLP policy that contains two DLP rules
Answer: B
NEW QUESTION 28
You have a Microsoft 365 E5 tenant.
You create sensitivity labels as shown in the Sensitivity Labels exhibit.
The Confidential/External sensitivity label is configured to encrypt files and emails when applied to content.
The sensitivity labels are published as shown in the Published exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/sensitivity-labels?view=o365-worldwide
NEW QUESTION 29
You plan to implement sensitivity labels for Microsoft Teams.
You need to ensure that you can view and apply sensitivity labels to new Microsoft Teams sites.
What should you do first?
- A. Create a new sensitivity label scoped to Groups & sites.
- B. Configure the EnableMTPLabels Azure Active Directory (Azure AD) setting.
- C. Run the Set-sposite cmdlet.
- D. Run the Execute-AzureAdLabelSync cmdtet.
Answer: A
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/sensitivity-labels-teams-groups-sites?view=o365-wo
NEW QUESTION 30
You need to recommend a solution that meets the compliance requirements for protecting the documents in the Data shared folder.
What should you recommend?
- A. From the Microsoft 365 compliance center, configure an auto-labeling policy.
- B. From the Microsoft 365 compliance center, configure a Content Search query.
- C. From the Microsoft 365 compliance center, configure a DLP policy.
- D. From Azure Information Protection, configure a content scan job.
Answer: D
Explanation:
Explanation/Reference:
https://docs.microsoft.com/en-us/azure/information-protection/deploy-aip-scanner Implement Data Loss Prevention Question Set 1
NEW QUESTION 31
You have a Microsoft 365 tenant that contains a Microsoft SharePoint Online site named Site1.
You have the users shown in the following table.
You create a data loss prevention (DLP) policy for Site1 that detects credit card number information. You configure the policy to use the following protection action:
* When content matches the policy conditions, show policy tips to users and send them an email notification.
You use the default notification settings.
To Site1, User1 uploads a file that contains a credit card number.
Which users receive an email notification?
- A. Used and User4 only
- B. Used and User3 only
- C. Used and User2 only
- D. Used only
- E. Used, User2, User3, and User4
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/get-started-with-the-default-dlp-policy?view=o365-w
NEW QUESTION 32
You have a Microsoft 365 tenant that uses data loss prevention (DLP).
You have a custom employee information form named Template 1.docx.
You need to create a classification rule package based on the document fingerprint of Templatel.docx.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Answer:
Explanation:
NEW QUESTION 33
You need to be alerted when users share sensitive documents from Microsoft OneDrive to any users outside your company.
What should you do?
- A. From the Microsoft 36h compliance? center, create an insider risk policy.
- B. From the Azure portal, create an Azure Active Directory (Azure Al)) Identity Protection policy.
- C. From the Microsoft 365 compliance center, start a data investigation.
- D. From the Microsoft 365 compliance center, create a data loss prevention (DLP) policy.
Answer: D
Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp?view=o365-worldwide
NEW QUESTION 34
You have a data loss prevention (DLP) policy that applies to the Devices location. The policy protects documents that contain States passport numbers.
Users reports that they cannot upload documents to a travel management website because of the policy.
You need to ensure that the users can upload the documents to the travel management website. The solution must prevent the protected content from being uploaded to other locations.
Which Microsoft 365 Endpoint data loss prevention (Endpoint DLP) setting should you configure?
- A. Service domains
- B. Unallowed browsers
- C. File path exclusions
- D. Unallowed apps
Answer: A
Explanation:
Explanation
You can control whether sensitive files protected by your policies can be uploaded to specific service domains from Microsoft Edge.
* If the list mode is set to Block, then user will not be able to upload sensitive items to those domains.
When an upload action is blocked because an item matches a DLP policy, DLP will either generate a
* warning or block the upload of the sensitive item.
* If the list mode is set to Allow, then users will be able to upload sensitive items only to those domains, and upload access to all other domains is not allowed.
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-using?view=o365-worldwide
NEW QUESTION 35
......
Skills measured
- Implement information governance (25-30%)
- The content of this exam was updated on July 23, 2021. Please download the exam skills outline below to see what changed.
- Implement data loss prevention (30-35%)
- Implement information protection (35-40%)
Pass Your Microsoft Exam with SC-400 Exam Dumps: https://www.examcost.com/SC-400-practice-exam.html
Verified SC-400 Bundle Real Exam Dumps PDF: https://drive.google.com/open?id=1j38j4k1j8fTsjn4170x7X0qZW5CxJqwx

