DumpsFree provides high-quality dumps PDF & dumps VCE for candidates who are willing to pass exams and get certifications soon. We provide dumps free download before purchasing dumps VCE. 100% pass exam!

[Jul 23, 2026] Genuine SC-401 Exam Dumps New 2026 Microsoft Pratice Exam [Q172-Q194]

Share

[Jul 23, 2026] Genuine SC-401 Exam Dumps New 2026 Microsoft Pratice Exam

New 2026 Realistic SC-401 Dumps Test Engine Exam Questions in here


Microsoft SC-401 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Implement Information Protection: This section measures the skills of Information Security Analysts in classifying and protecting data. It covers identifying and managing sensitive information, creating and applying sensitivity labels, and implementing protection for Windows, file shares, and Exchange. Candidates must also configure document fingerprinting, trainable classifiers, and encryption strategies using Microsoft Purview.
Topic 2
  • Protect Data Used by AI Services: This section evaluates AI Governance Specialists on securing data in AI-driven environments. It includes implementing controls for Microsoft Purview, configuring Data Security Posture Management (DSPM) for AI, and monitoring AI-related security risks to ensure compliance and protection.
Topic 3
  • Implement Data Loss Prevention and Retention: This section evaluates Data Protection Officers on designing and managing data loss prevention (DLP) policies and retention strategies. It includes setting policies for data security, configuring Endpoint DLP, and managing retention labels and policies. Candidates must understand adaptive scopes, policy precedence, and data recovery within Microsoft 365.
Topic 4
  • Manage Risks, Alerts, and Activities: This section assesses Security Operations Analysts on insider risk management, monitoring alerts, and investigating security activities. It covers configuring risk policies, handling forensic evidence, and responding to alerts using Microsoft Purview and Defender tools. Candidates must also analyze audit logs and manage security workflows.

 

NEW QUESTION # 172
You have a Microsoft 365 E5 tenant.
You create a data loss prevention (DLP) policy.
You need to ensure that the policy protects documents in Microsoft Teams chat sessions.
Which location should you enable in the policy?

  • A. SharePoint sites
  • B. OneDrive accounts
  • C. Teams chat and channel messages
  • D. Exchange email

Answer: B


NEW QUESTION # 173
You have two Microsoft 365 subscriptions named Contoso and Fabrikam. The subscriptions contain the users shown in the following table.

You have a sensitivity label named Sensitivity! as shown in the exhibit. (Click the Exhibit tab) you have the files shown in the following table.

For each of the following statements, select yes if the statement is true. Otherwise select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 174
You have a Microsoft 365 E5 subscription that contains four users named User1. User2, User3, and User4 and a file named File1.docx. File1 has a sensitivity label applied. The label is configured as shown in the following table.

Which users can summarize File1 by using Microsoft 365 Copilot?

  • A. User1, User2, User3. and User4
  • B. User1 and User2 only
  • C. User1, User2. and User3 only
  • D. User1 only

Answer: B

Explanation:
Step 1 - Understand the scenario
* We have a Microsoft 365 E5 subscription with Copilot available.
* File1.docx has a sensitivity label applied.
* The sensitivity label controls usage rights (Owner, Editor, Restricted Editor, Viewer).
* The question: Which users can summarize File1 with Microsoft 365 Copilot?
Step 2 - Sensitivity labels and usage rights
When a sensitivity label is configured to apply encryption with usage rights, each role has different levels of access:
* Owner: Full control (read, edit, reshare, extract, etc.).
* Editor: Can read, edit, and copy content.
* Restricted Editor: Can read and edit in place, but cannot copy, print, or extract content.
* Viewer: Can only read (view) the content.
# Reference: Rights included in usage rights for sensitivity labels
Step 3 - Copilot's requirements for summarization
Microsoft 365 Copilot requires that the user has the ability to read and extract text from the document in order to generate a summary.
* Owners and Editors: # Can both read and extract # Copilot works.
* Restricted Editors: # Cannot copy/extract text # Copilot cannot summarize.
* Viewers: # Can only view # Copilot cannot process content for summarization.
# Reference: Microsoft 365 Copilot and sensitivity labels
"Users must have extract and copy rights in order for Microsoft 365 Copilot to process and summarize labeled documents." Step 4 - Apply to the case
* User1 (Owner) # Can summarize.
* User2 (Editor) # Can summarize.
* User3 (Restricted Editor) # Cannot summarize.
* User4 (Viewer) # Cannot summarize.


NEW QUESTION # 175
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You recently discovered that the developers at your company emailed Azure Storage Account keys in plain text to third parties.
You need to ensure that when Azure Storage Account keys are emailed, the emails are encrypted.
Solution: You configure a mail flow rule that matches a sensitive info type.
Does this meet the goal?

  • A. Yes
  • B. No

Answer: B

Explanation:
To ensure Azure Storage Account keys are encrypted when sent via email, you need a Data Loss Prevention (DLP) policy that detects Azure Storage Account keys using a sensitive information type and automatically encrypts emails containing these keys.
Mail flow rules (transport rules) can detect sensitive info, but they are limited in encryption capabilities.
DLP policies provide more advanced protection and integration with Microsoft Purview for sensitive info detection.


NEW QUESTION # 176
You have a Microsoft 365 E5 tenant and the Windows Client devices shown in the following table.

To which devices can you apply Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings?

  • A. Device1 and Device2 only
  • B. Device1 and Device3 only
  • C. Device1, Device2, Device3, and Device4
  • D. Device1, Device3, and Device4 only
  • E. Device1 only

Answer: A

Explanation:
https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-getting-started


NEW QUESTION # 177
HOTSPOT
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

You plan to create a Microsoft Purview insider risk management case named Case1.
Which insider risk management object should you select first, and which users will be added as contributors for Case1 by default?
To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

Box 1: When creating a Microsoft Purview Insider Risk Management case, you must first select a risky user to investigate. The case will be built around this specific user's activities, linking alerts and risk signals to the investigation.
Box 2: The Insider Risk Management role groups determine who can access and contribute to cases:
# Admin1 (Insider Risk Management Admins) # Full admin access.
# Admin2 (Insider Risk Management Analysts) # Analysts who review cases.
# Admin3 (Risk Management Investigators) # Investigators who work on cases.
# Admin4 (Insider Risk Management Auditors) # Auditors who oversee cases.
All these roles have default access to insider risk cases in Microsoft Purview, so all four admins are added as contributors.


NEW QUESTION # 178
You have a Microsoft 365 E5 subscription that contains a user named User1.
You deploy Microsoft Purview insider risk management.
You need ensure that insider risk management events related to User1 are visible only to specific users.
What should you create?

  • A. a detection group
  • B. a global exclusion
  • C. a priority user group
  • D. an indicator variant

Answer: A


NEW QUESTION # 179
You have a Microsoft 365 ES subscription that uses Microsoft Teams and contains the users shown in the following table.

You have the retention policies shown in the following table.

The users perform the actions shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point

Answer:

Explanation:

Explanation:

Let's analyze each scenario based on the given retention policies and Microsoft 365 documentation.
# Policies Recap
Policy1
Teams channel messages # All Teams # Retain 7 years # Delete automatically.
Teams chats # User1 # Retain 7 years # Delete automatically.
Policy2
Teams channel messages # Team1 # Retain 5 years # Delete automatically.
Teams chats # User2 # Retain 5 years # Delete automatically.
# Reference: Retention policies in Microsoft Teams
# Statement 1: The message edited by User1 will be deleted after five years.
Location = Team1 channel.
Policy1 applies (7 years for all Teams).
Policy2 applies (5 years for Team1).
Conflict rule: For retention, the longest duration wins.
Therefore, the message stays 7 years, not 5.
# Answer: NO
# Statement 2: User1 can see the message sent by User2 for up to seven years.
Location = Private 1:1 chat (User2 # User1).
For User1's mailbox: Policy1 applies (7 years).
For User2's mailbox: Policy2 applies (5 years).
Retention in Teams chats is per-user, so each participant may have different durations.
For User1, the retention is 7 years.
# Answer: YES
# Statement 3: The message deleted by User1 will be moved to the SubstrateHolds folder.
Location = Team2 channel.
User1 deletes the message, but retention policy (Policy1) applies (7 years).
Retention overrides user deletion: message is moved to the SubstrateHolds folder in the hidden mailbox for preservation.
# Reference: How retention works with SubstrateHolds
# Answer: YES


NEW QUESTION # 180
Your company has offices in multiple countries.
The company has a Microsoft 365 E5 subscription that uses Microsoft Purview insider risk management.
You plan to perform the following actions:
*In a new country, open an office named Office1.
*Create a new user named User1.
*Deploy insider risk management to Office1.
*Add User1 to the Insider Risk Management Admins role group.
You need to ensure that User1 can perform insider risk management tasks for only the users and the devices in Office1.
What should you create first?

  • A. a dynamic device group
  • B. a management group
  • C. an administrative unit
  • D. a dynamic user group

Answer: C

Explanation:
To ensure User1 can perform insider risk management tasks only for the users and devices in Office1, the first step is to create an administrative unit in Microsoft Entra ID (formerly Azure AD).
Administrative units allow you to scope permissions to specific users, devices, and locations. By creating an administrative unit for Office1 and assigning User1 to the Insider Risk Management Admins role group within that unit, User1 will only have access to users and devices in Office1.


NEW QUESTION # 181
You are creating a DLP policy named Policy1 that will be applied to the locations as shown in the following exhibit.

Policy1 contains an advanced data loss prevention (DLP) rule named Rule1.
Which two conditions can you use in Rule1? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.

  • A. Attachment's file extension is
  • B. Content contains
  • C. Document size equals or is greater than
  • D. Content is shared from Microsoft 365
  • E. Document property is

Answer: B,D

Explanation:
You are creating a Data Loss Prevention (DLP) policy in Microsoft 365 with advanced rules. Advanced DLP rules provide more granular conditions and actions than standard DLP rules.
Conditions available in advanced DLP
According to Microsoft Docs on Conditions in DLP policies:
* # Content contains # Used to detect sensitive information types, keywords, or exact data matches.
This is one of the most common and fundamental DLP conditions.
* # Content is shared from Microsoft 365 # Used to detect whether content has been shared externally or with specific domains/users. This is a modern advanced DLP condition.
Why the others are not correct:
* A. Document property is # This condition applies to information governance retention policies
/labels (not DLP). Not available in DLP rules.
* B. Attachment's file extension is # This is supported in Exchange mail flow rules (transport rules) but not in advanced DLP rules.
* C. Document size equals or is greater than # Also applies in Exchange transport rules and certain SharePoint restrictions, but not available as a DLP rule condition.


NEW QUESTION # 182
You have a Microsoft 365 E5 subscription that uses Microsoft Purview.
You are creating an exact data match (EDM) classifier named EDM1.
For EDM1, you upload a schema file that contains the fields shown in the following table.

What is the maximum number of primary elements that EDM1 can have?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B

Explanation:
In Microsoft Purview Exact Data Match (EDM) classifiers, a primary element is a unique, identifying field used for data matching. EDM allows up to two primary elements per schema.
From the provided table, the Match mode indicates how data is analyzed:
# PP (EU Passport Number) # Likely a primary element because it's unique.
# Name (All Full Names) # Typically not a primary element as names are common.
# DateOfBirth (Single-token) # Usually a secondary element, not unique.
# AccountNumber (Multi-token) # Can be a primary element, as it's a unique identifier.
# Since EDM supports a maximum of two primary elements, the correct answer is 2.


NEW QUESTION # 183
You have a Microsoft 365 E5 subscription.
You plan to implement insider risk management for users that manage sensitive data associated with a project.
You need to create a protection policy for the users. The solution must meet the following requirements:
# Minimize the impact on users who are NOT part of the project.
# Minimize administrative effort.
What should you do first?

  • A. From the Microsoft Entra admin center create a User risk policy
  • B. From the Microsoft Entra admin center, create a security group.
  • C. From the Microsoft Purview portal create a priority user group
  • D. From the Microsoft Purview portal, create an insider risk management policy.

Answer: A


NEW QUESTION # 184
Hotspot Question
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1 and a sensitivity label named Label1.
The external sharing settings for Site1 are configured as shown in the Site1 exhibit. (Click the Site1 tab.)

The external sharing settings for Label1 are configured as shown in the Label1 exhibit. (Click the Label1 tab.)

Label1 is applied to Site1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:


NEW QUESTION # 185
HOTSPOT
You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.
You create the audit retention policies shown in the following table.

The users perform the following actions:
# User1 renames a Microsoft SharePoint Online site.
# User2 sends an email message.
How long will the audit log records be retained for each action? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

The action "SiteRenamed" for SharePoint is covered under the AuditRetention4 policy, which applies to User1 and retains logs for 9 months.
The action "Send" for ExchangeItem is covered under the AuditRetention2 policy, but this policy applies only to User1. Since User2 is not covered under a specific policy, the default retention period for audit logs in Microsoft Purview is 90 days.


NEW QUESTION # 186
You have a Microsoft 365 E5 subscription that contains three DOCX files named File1, File2, and File3.
You create the sensitivity labels shown in the following table.

You apply the labels to the files as shown in the following table.

You ask Microsoft 365 Copilot to summarize the files, and you receive the results shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:


NEW QUESTION # 187
HOTSPOT
You have a Microsoft 365 E5 subscription.
You need to implement a compliance solution that meets the following requirements:
# Captures clips of key security-related user activities, such as the exfiltration of sensitive company data.
# Integrates data loss prevention (DLP) capabilities with insider risk management.
What should you use for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:

Captures clips of key security-related user activities
This requirement refers to recording and surfacing evidence of risky user behavior (e.g., copying sensitive files to USB, uploading to cloud storage, or exfiltrating data).
In Microsoft Purview Insider Risk Management, this is achieved through Forensic evidence, which allows capturing screenshots/clips of user activities on endpoints when a policy is triggered.
Ref: Microsoft Learn - Insider risk forensic evidence
Integrates DLP capabilities with insider risk management
Microsoft introduced Adaptive Protection as part of Purview Insider Risk.
Adaptive Protection uses insider risk signals and DLP together, dynamically adjusting DLP controls (block, restrict, monitor) based on the user's risk level.
This integration reduces false positives and ensures risky users are monitored more strictly while low-risk users are less impacted.
Ref: Microsoft Learn - Adaptive Protection in Microsoft Purview
Other options ruled out:
Adaptive scopes: Used for defining policy targeting groups dynamically, not capturing activities.
Classifiers/Trainable classifiers: Used for content classification, not exfiltration capture or DLP integration.
eDiscovery (Premium): For legal investigations, not insider risk + DLP integration.
Records management: Lifecycle retention, not related to insider risk.


NEW QUESTION # 188
You have a Microsoft 365 subscription that contains the devices shown in the following table.

From which devices can Microsoft Purview Insider Risk Management capture forensic evidence?

  • A. Device1 and Device2 only
  • B. Device2 only
  • C. Device1, Device2 and Device3
  • D. Device only
  • E. Device2 and Device3 only

Answer: B

Explanation:
Forensic evidence in Microsoft Purview Insider Risk Management allows capturing screenshots/clips of user activity on endpoints.
Requirements for forensic evidence capture:
The device must be onboarded to Microsoft Purview (via Defender for Endpoint).
The Microsoft Purview client must be installed.
Supported platforms: Windows 10 and Windows 11 (macOS is not supported for forensic evidence).
Now check each device:
Device1 (Windows 11) # Client installed, but not onboarded # # Not eligible.
Device2 (Windows 10) # Onboarded and client installed # # Eligible.
Device3 (macOS) # Onboarded, but client not installed and macOS is not supported # # Not eligible.
Therefore, only Device2 qualifies.
Reference:
Microsoft Learn: Forensic evidence in insider risk management
Microsoft Learn: Onboard devices for insider risk management forensic evidence


NEW QUESTION # 189
You need to test Microsoft Purview Advanced Message Encryption capabilities for your company. The test must verify the following information:
* The acquired default template names
* The encryption and decryption verification status
Which PowerShell cmdlet should you run?

  • A. Test-Mailflow
  • B. Test-IRMConfiguration
  • C. Test-ClientAccessRule
  • D. Test-OAuthConnectivity

Answer: B

Explanation:
To test Microsoft Purview Advanced Message Encryption (which relies on Azure Information Rights Management), you use the Test-IRMConfiguration cmdlet. It verifies configuration, template availability, and encryption/decryption status.
Test-OAuthConnectivity # tests OAuth authentication.
Test-ClientAccessRule # tests client access rules.
Test-Mailflow # tests mail routing.
Reference: Test-IRMConfiguration cmdlet


NEW QUESTION # 190
Hotspot Question
You create a retention policy as shown in the following exhibit.

A user named User1 deletes a file named File1.docx from a Microsoft SharePoint Online site named Site1.
A user named User2 deletes an email and empties the Deleted Items folder in Microsoft Outlook.
Where is the content retained one year after deletion? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/retention?view=o365-worldwide


NEW QUESTION # 191
Drag and Drop Question
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.
You plan to deploy a Defender for Cloud Apps file policy that will be triggered when the following conditions are met:
- A file is shared externally.
- A file is labeled as internal only.
Which filter should you use for each condition? To answer, drag the appropriate filters to the correct conditions. Each filter may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
The "Access level" filter in Microsoft Defender for Cloud Apps helps identify how a file is shared, including whether it is shared externally outside the organization.
The "Sensitivity label" filter is used to track files that have been classified with specific Microsoft Purview sensitivity labels, such as Internal only, ensuring that files with internal classifications are properly monitored and protected.
The "Collaborators" filter tracks users who have access but does not indicate external sharing.
The "Matched policy" filter identifies files based on predefined policies but does not directly filter for external sharing or sensitivity labels.


NEW QUESTION # 192
You have a Microsoft OneDrive folder that contains the files shown in the following table.

In Microsoft Defender for Cloud Apps, you create a file policy to automatically apply a classification.
What is the effect of applying the policy?

  • A. The policy will apply to only the .docx and .txt files. The policy will classify the files within 24 hours.
  • B. The policy will apply to only the .docx and .txt files. The policy will classify the files immediately.
  • C. The policy will apply to all the files. The policy will classify only 100 files daily.
  • D. The policy will apply to only the .docx files. The policy will classify only 100 files daily.

Answer: D

Explanation:
https://docs.microsoft.com/en-us/cloud-app-security/azip-integration


NEW QUESTION # 193
Hotspot Question
You plan to create a custom sensitive information type that will use Exact Data Match (EDM).
You need to identify what to upload to Microsoft 365, and which tool to use for the upload.
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Answer:

Explanation:

Explanation:
EDM Upload Agent creates hashes for your SITs and saves them in the .CSV format. However you can also upload .csv, .tsv or pipe (|) formatted files. It also saves schema in XML format.


NEW QUESTION # 194
......

Grab latest Amazon SC-401 Dumps as PDF Updated: https://dumpstorrent.dumpsfree.com/SC-401-valid-exam.html