ExamGecko
Home Home / Microsoft / SC-400

Microsoft SC-400 Practice Test - Questions Answers, Page 4

Question list
Search
Search

List of questions

Search

Related questions











Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have a Microsoft 365 tenant and 500 computers that run Windows 10. The computers are onboarded to the Microsoft 365 compliance center.

You discover that a third-party application named Tailspin_scanner.exe accessed protected sensitive information on multiple computers. Tailspin_scanner.exe is installed locally on the computers.

You need to block Tailspin_scanner.exe from accessing sensitive documents without preventing the application from accessing other documents.

Solution: From the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings, you add the application to the unallowed apps list.

Does this meet the goal?

A.

Yes

A.

Yes

Answers
B.

No

B.

No

Answers
Suggested answer: A

Explanation:

Unallowed apps is a list of applications that you create which will not be allowed to access a DLP protected file.

Reference:

https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-using?view=o365-worldwide

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You are configuring a file policy in Microsoft Cloud App Security.

You need to configure the policy to apply to all files. Alerts must be sent to every file owner who is affected by the policy. The policy must scan for credit card numbers, and alerts must be sent to the Microsoft Teams site of the affected department.

Solution: You use the Data Classification service inspection method and send alerts as email.

Does this meet the goal?

A.

Yes

A.

Yes

Answers
B.

No

B.

No

Answers
Suggested answer: B

Explanation:

Alerts must be sent to the Microsoft Teams site of the affected department. A Microsoft Power Automate playbook should be used.

Reference:

https://docs.microsoft.com/en-us/cloud-app-security/dcs-inspection

https://docs.microsoft.com/en-us/cloud-app-security/flow-integration

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You are configuring a file policy in Microsoft Cloud App Security.

You need to configure the policy to apply to all files. Alerts must be sent to every file owner who is affected by the policy. The policy must scan for credit card numbers, and alerts must be sent to the Microsoft Teams site of the affected department.

Solution: You use the Built-in DLP inspection method and send alerts to Microsoft Power Automate.

Does this meet the goal?

A.

Yes

A.

Yes

Answers
B.

No

B.

No

Answers
Suggested answer: A

Explanation:

Reference:

https://docs.microsoft.com/en-us/cloud-app-security/content-inspection-built-in

https://docs.microsoft.com/en-us/cloud-app-security/flow-integration

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You are configuring a file policy in Microsoft Cloud App Security.

You need to configure the policy to apply to all files. Alerts must be sent to every file owner who is affected by the policy. The policy must scan for credit card numbers, and alerts must be sent to the Microsoft Teams site of the affected department.

Solution: You use the Built-in DLP inspection method and send alerts as email.

Does this meet the goal?

A.

Yes

A.

Yes

Answers
B.

No

B.

No

Answers
Suggested answer: B

Explanation:

Alerts must be sent to the Microsoft Teams site of the affected department. A Microsoft Power Automate playbook should be used.

Reference:

https://docs.microsoft.com/en-us/cloud-app-security/content-inspection-built-in

https://docs.microsoft.com/en-us/cloud-app-security/flow-integration

You have a Microsoft 365 tenant that uses 100 data loss prevention (DLP) policies.

A Microsoft Exchange administrator frequently investigates emails that were blocked due to DLP policy violations.

You need recommend which DLP report the Exchange administrator can use to identify how many messages were blocked based on each DLP policy.

Which report should you recommend?

A.

Third-party DLP policy matches

A.

Third-party DLP policy matches

Answers
B.

DLP policy matches

B.

DLP policy matches

Answers
C.

DLP incidents

C.

DLP incidents

Answers
D.

False positive and override

D.

False positive and override

Answers
Suggested answer: B

Explanation:

Reference:

https://docs.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp?view=o365-worldwide

You have a data loss prevention (DLP) policy configured for endpoints as shown in the following exhibit.

From a computer named Computer1, a user can sometimes upload files to cloud services and sometimes cannot. Other users experience the same issue.

What are two possible causes of the issue? Each correct answer presents a complete solution.

NOTE: Each correct selection is worth one point.

A.

The computers are NOT onboarded to the Microsoft 365 compliance center.

A.

The computers are NOT onboarded to the Microsoft 365 compliance center.

Answers
B.

The Copy to clipboard action is set to Audit only.

B.

The Copy to clipboard action is set to Audit only.

Answers
C.

There are file path exclusions in the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings.

C.

There are file path exclusions in the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings.

Answers
D.

The Access by unallowed apps action is set to Audit only.

D.

The Access by unallowed apps action is set to Audit only.

Answers
E.

The unallowed browsers in the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings are NOT configured.

E.

The unallowed browsers in the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings are NOT configured.

Answers
Suggested answer: D, E

You are planning a data loss prevention (DLP) solution that will apply to computers that run Windows 10.

You need to ensure that when users attempt to copy a file that contains sensitive information to a USB storage device, the following requirements are met:

If the users are members of a group named Group1, the users must be allowed to copy the file, and an event must be recorded in the audit log.

All other users must be blocked from copying the file.

What should you create?

A.

two DLP policies that each contains one DLP rule

A.

two DLP policies that each contains one DLP rule

Answers
B.

one DLP policy that contains one DLP rule

B.

one DLP policy that contains one DLP rule

Answers
C.

one DLP policy that contains two DLP rules

C.

one DLP policy that contains two DLP rules

Answers
Suggested answer: A

You need to be alerted when users share sensitive documents from Microsoft One Drive to any users outside your company.

What should you do?

A.

From the Exchange admin center, create a data loss prevention (DLP) policy.

A.

From the Exchange admin center, create a data loss prevention (DLP) policy.

Answers
B.

From the Azure portal, create an Azure Active Directory (Azure AD) Identity Protection policy.

B.

From the Azure portal, create an Azure Active Directory (Azure AD) Identity Protection policy.

Answers
C.

From the Microsoft 365 compliance center, create an insider risk policy.

C.

From the Microsoft 365 compliance center, create an insider risk policy.

Answers
D.

From the Cloud App Security portal, create a file policy.

D.

From the Cloud App Security portal, create a file policy.

Answers
Suggested answer: D

Explanation:

File Policies allow you to enforce a wide range of automated processes using the cloud provider's APIs. Policies can be set to provide continuous compliance scans, legal eDiscovery tasks, DLP for sensitive content shared publicly, and many more use cases.

Note:

There are several versions of this question in the exam. The question has two possible correct answers:

1. From the Microsoft 365 compliance center, create a data loss prevention (DLP) policy.

2. From the Cloud App Security portal, create a file policy.

Other incorrect answer options you may see on the exam include the following:

From the Microsoft 365 compliance center, start a data investigation.

From the Azure portal, create an Azure Information Protection policy.

Reference:

https://docs.microsoft.com/en-us/defender-cloud-apps/data-protection-policies

Your company has a Microsoft 365 tenant.

The company performs annual employee assessments. The assessment results are recorded in a document named AssessmentTemplate.docx that is created by using a Microsoft Word template. Copies of the employee assessments are sent to employees and their managers. The assessment copies are stored in mailboxes, Microsoft SharePoint Online sites, and OneDrive for Business folders. A copy of each assessment is also stored in a SharePoint Online folder named

Assessments.

You need to create a data loss prevention (DLP) policy that prevents the employee assessments from being emailed to external users. You will use a document fingerprint to identify the assessment documents. The solution must minimize effort.

What should you include in the solution?

A.

Create a fingerprint of 100 sample documents in the Assessments folder.

A.

Create a fingerprint of 100 sample documents in the Assessments folder.

Answers
B.

Create a sensitive info type that uses Exact Data Match (EDM).

B.

Create a sensitive info type that uses Exact Data Match (EDM).

Answers
C.

Import 100 sample documents from the Assessments folder to a seed folder.

C.

Import 100 sample documents from the Assessments folder to a seed folder.

Answers
D.

Create a fingerprint of AssessmentTemplate.docx.

D.

Create a fingerprint of AssessmentTemplate.docx.

Answers
Suggested answer: D

Explanation:

Reference:

https://docs.microsoft.com/en-us/microsoft-365/compliance/document-fingerprinting?view=o365-worldwide

You have a Microsoft 365 subscription that uses Microsoft Exchange Online.

You need to receive an alert if a user emails sensitive documents to specific external domains.

What should you create?

A.

a data loss prevention (DLP) policy that uses the Privacy category

A.

a data loss prevention (DLP) policy that uses the Privacy category

Answers
B.

a Microsoft Cloud App Security activity policy

B.

a Microsoft Cloud App Security activity policy

Answers
C.

a Microsoft Cloud App Security file policy

C.

a Microsoft Cloud App Security file policy

Answers
D.

a data loss prevention (DLP) alert filter

D.

a data loss prevention (DLP) alert filter

Answers
Suggested answer: A

Explanation:

Reference:

https://docs.microsoft.com/en-us/microsoft-365/compliance/dlp-policy-reference?view=o365-worldwide

Total 293 questions
Go to page: of 30