Practice Free SC-400 Exam Online Questions
HOTSPOT
You use project codes that have a format of three alphabetical characters that represent the project
type, followed by three digits, for example Abc123.
You need to create a new sensitive info type for the project codes.
How should you configure the regular expression to detect the content? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.
You need to ensure that you receive an alert when a user uploads a document to a third-party cloud storage service.
What should you use?
- A . an insider risk policy
- B . a file policy
- C . a sensitivity label
- D . an activity policy
Your company manufactures parts that are each assigned a unique 12-character alphanumeric serial number. Emails between the company and its customers refer in the serial number.
You need to ensure that ail Microsoft Exchange Online emails containing the serial numbers are retained for five years.
Which three objects should you create? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
- A . a trainable classifier
- B . a sensitive info type
- C . a retention polity
- D . a data loss prevention (DLP) policy
- E . an auto-labeling policy
- F . a retention label
- G . a sensitivity label
You need to recommend a solution to configuration the Microsoft 365 Records management settings by using the CSV file must meet the compliance requirements.
What should you recommend?
- A . From the Microsoft 365 compliance center, import the CSV file to a file plan.
- B . Use EdmUploadAgent.exe to upload a hash of the CSV to a datastore.
- C . Use a PowerShell command that pipes the import csv cmdlet to the New-RetentionPolicy cmdlet.
- D . Use a PowerShell command that pipes the import-csv cmdlet to the New-Label cmdlet.
You have a Microsoft 365 E5 subscription that contains a retention policy named RP1 as shown in the following table.

You place a preservation lock on RP1. You need to modify RP1.
Which two actions can you perform? Each correct answer NOTE: Each correct selection is worth one point.
- A . Decrease the retention period of the policy.
- B . Delete the policy.
- C . Increase the retention period of the policy.
- D . Disable the policy.
- E . Remove locations from the policy.
- F . Add locations to the policy.
You have a Microsoft 365 E5 subscription that uses Privacy Risk Management in Microsoft Priva.
You need to review the personal data type instances that were detected in the subscription.
What should you use in the Microsoft Purview compliance portal?
- A . Content explorer
- B . User data search
- C . Content search
- D . an eDiscovery case
HOTSPOT
You plan to create a custom trainable classifier based on an organizational form template.
You need to identity which role based access control (RBAC) role is required to create the trainable classifier and where to classifier. The solution must use the principle of least privilege.
What should you identify? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

HOTSPOT
You need to recommend an information governance solution that meets the HR requirements for handling employment applications and resumes.
What is the minimum number of information governance solution components that you should create? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

You need to create a retention policy to delete content after seven years from the following locations:
✑ Exchange email
✑ SharePoint sites
✑ OneDrive accounts
✑ Office 365 groups
✑ Teams channel messages
✑ Teams chats
What is the minimum number of retention policies that you should create?
- A . 1
- B . 2
- C . 3
- D . 4
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 tenant and 500 computers that run Windows 10. The computers are onboarded to the Microsoft 365 compliance center.
You discover that a third-party application named Tailspin_scanner.exe accessed protected sensitive
information on multiple computers. Tailspin_scanner.exe is installed locally on the computers.
You need to block Tailspin_scanner.exe from accessing sensitive documents without preventing the application from accessing other documents.
Solution: From the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings, you add a folder path to the file path exclusions.
Does this meet the goal?
- A . Yes
- B . No
