Practice Free SC-400 Exam Online Questions
HOTSPOT
You plan to create a custom sensitive information type that will use Exact Data Match (EDM).
You need to identify what to upload to Microsoft 365, and which tool to use for the upload.
What should you identify? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 subscription.
You have a user named User1. Several users have full access to the mailbox of User1.
Some email messages sent to User1 appear to have been read and deleted before the user viewed them.
When you search the audit log in the Microsoft Purview compliance portal to identify who signed in to the mailbox of User1, the results are blank.
You need to ensure that you can view future sign-ins to the mailbox of User1.
Solution: You run the Set-AuditConfig -Workload Exchange command.
Does that meet the goal?
- A . Yes
- B . No
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Project1.
You need to recommend a record management solution that meets the following requirements:
• Retains files in Project1 for a minimum of 10 years
• Once Project1 is complete, retains files for an additional five years before the files are deleted
Which two components should you include in the recommendation? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
- A . a sensitivity label
- B . an event type
- C . an adaptive scope
- D . a data loss prevention (DLP) policy
- E . a file plan
HOTSPOT
You have a Microsoft 365 subscription.
You are creating a retention policy named Retention1 as shown in the exhibit. (Click the Exhibit tab.)

You apply Retention1 to SharePoint sites and OneDrive accounts.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription.
You need to export the details of a retention label.
The export must include the following information;
• Is record
• Is regulatory
• Disposition type
What should you do?
- A . From the Microsoft Purview compliance portal, export Compliance Manager assessment actions.
- B . From the Microsoft Purview compliance portal export a file plan.
- C . From the Microsoft Purview compliance portal export a disposition review.
- D . From PowerShell, run the Export-ActivityExplorerData cmdlet.
- E . From PowerShell, run the Get-RetentionEvent cmdlet.
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.

You need to prevent users in the finance department from sharing files with users in the research department.
Which type of policy should you configure?
- A . communication compliance
- B . information barrier
- C . Conditional Access
- D . insider risk management
DRAG DROP
You have a Microsoft 365 subscription that contains 20 data loss prevention (DLP) policies.
You need to identify the following:
• Rules that are applied without triggering a policy alert
• The top 10 files that have matched DLP policies
• Alerts that are miscategorized
Which report should you use for each requirement? To answer, drag the appropriate reports to the correct requirements. Each report may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.

You have a Microsoft SharePoint Online site named Site! that contains the files shown in the following table.

You have a data loss prevention (DLP) policy named DLP1 that has the advanced DLP rules shown in the following table.

You apply DLP1 toSite1.
Which policy tips will appear for File2?
- A . Tip1 only
- B . Tip2only
- C . Tip3 only
- D . Tip1 and Tip2 only
You have a Microsoft 365 subscription.
You have a user named User1. Several users have full access to the mailbox of User1.
Some email messages sent to User1 appear to have been read and deleted before the user viewed them.
When you search the audit log in the Microsoft Purview compliance portal to identify who signed in to the mailbox of User1, the results are blank.
You need to ensure that you can view future sign-ins to the mailbox of User1.
YOU run the Set-MailboxFolderPernission -Identity "User1" -User Userlfcontoso.com -AccessRights Owner command.
Does that meet the goal?
- A . Yes
- B . No
You have a Microsoft 365 E5 subscription.
You plan to implement insider risk management for users that manage sensitive data associated with a project.
You need to create a protection policy for the users.
The solution must meet the following requirements:
• Minimize the impact on users who are NOT part of the project.
• Minimize administrative effort.
What should you do first?
- A . From the Microsoft Entra admin center, create a security group.
- B . From the Microsoft Purview compliance portal, create a priority user group.
- C . From the Microsoft Entra admin center, create a User risk policy.
- D . From the Microsoft Purview compliance portal, create an insider risk management policy.



