Free Microsoft SC-401 Exam Questions (page: 7)

View Related Case Study

HOTSPOT (Drag and Drop is not supported)

You need to implement an information compliance policy to meet the following requirements:

Documents that contain passport numbers from the United States, Germany, Australia, and Japan must be identified automatically.
When a user attempts to send an email or an attachment that contains a passport number, the user must receive a tooltip in Microsoft Outlook.
Users must be blocked from using Microsoft SharePoint Online or OneDrive for Business to share a document that contains a passport number.

What is the minimum number of sensitivity labels and auto-labeling policies you should create? To answer, select the appropriate options in the answer area.

Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Box 1: 1
We have four different kind of built-in sensitive information types for United States, Germany, Australia, and Japan in Data classification.

Box 2: 1
One Autolabeling policy can include all (4) passport sensitive information types in Rule-Conditions. In the same policy you choose one sensitivity label to add to files.


Reference:

https://docs.microsoft.com/en-us/microsoft-365/compliance/get-started-with-sensitivity-labels



View Related Case Study

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You recently discovered that the developers at your company emailed Azure Storage Account keys in plain text to third parties.

You need to ensure that when Azure Storage Account keys are emailed, the emails are encrypted.

Solution: You create a data loss prevention (DLP) policy that has Exchange email, SharePoint sites, OneDrive accounts, and Teams chat and channel messages selected.

Does this meet the goal?

  1. Yes
  2. No

Answer(s): A

Explanation:

Correct:
* You create a data loss prevention (DLP) policy that has only the Exchange email location selected.
To ensure Azure Storage Account keys are encrypted when sent via email, you need a Data Loss Prevention (DLP) policy that detects Azure Storage Account keys using a sensitive information type and automatically encrypts emails containing these keys.
A DLP policy with Exchange email as the only location meets this requirement because it identifies sensitive data in email messages and it applies protection actions, such as encryption, blocking, or alerts.
* You create a data loss prevention (DLP) policy that has Exchange email, SharePoint sites, OneDrive accounts, and Teams chat and channel messages selected.OneDrive accounts, and Teams chat and channel messages selected.
Creating a Data Loss Prevention (DLP) policy that includes Exchange email as a location can help detect and prevent the sharing of sensitive information, like Azure Storage keys, in plain text. By setting up a DLP policy with conditions to identify Azure Storage keys and enforce encryption or blocking actions for Exchange email, the policy will ensure that any emails containing such sensitive information are either encrypted or prevented from being sent.
Incorrect:
* You configure a mail flow rule that matches a sensitive info type.
* You configure a mail flow rule that matches the text patterns.
To ensure Azure Storage Account keys are encrypted when sent via email, you need a Data Loss Prevention (DLP) policy that detects Azure Storage Account keys using a sensitive information type and automatically encrypts emails containing these keys.
Text patterns in mail flow rules are not as reliable as sensitive information types in DLP.
Mail flow rules lack advanced content detection and machine learning-based classification, making them less effective than DLP.
* You create a data loss prevention (DLP) policy that has all locations selected.


Reference:

https://docs.microsoft.com/en-us/exchange/policy-and-compliance/mail-flow-rules/conditions-and-exceptions



View Related Case Study

DRAG DROP (Drag and Drop is not supported)

You have a Microsoft 365 E5 subscription.

You need to label Microsoft Exchange Online emails that match the following conditions:

Contain employment offers


Contain offensive language


Contain medical terms and conditions


The solution must minimize administrative effort.

Which type of data classification should you use for each condition? To answer, drag the appropriate data classification types to the correct conditions. Each data classification type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

Note: Each correct selection is worth one point.

Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Box 1: Sensitive info Type

Box 2: Trainable classifier
Contain offensive language

Trainable classifiers definitions

Microsoft Purview comes with multiple pretrained classifiers. They appear in the Microsoft Purview compliance portal > Data classification > Trainable classifiers view with the status of Ready to use.

For example:

* Profanity
Detects a specific category of offensive language text items that contain expressions that embarrass most people.

Box 3: Exact Data Match (EDM)
Contain medical terms and conditions

With Exact Data Match (EDM) based classification, you can create a custom sensitive information type that is designed to:

be dynamic and easily refreshed result in fewer false-positives work with structured sensitive data handle sensitive information more securely, not sharing it with anyone, including Microsoft be used with several Microsoft cloud services

EDM-based classification enables you to create custom sensitive information types that refer to exact values in a database of sensitive information. The database can be refreshed daily, and can contain up to 100 million rows of data. So as employees, patients, or clients come and go, and as records change, your custom sensitive information types remain current and applicable.


Reference:

https://learn.microsoft.com/en-us/purview/classifier-learn-about https://learn.microsoft.com/en-us/purview/classifier-tc-definitions https://learn.microsoft.com/en-us/purview/sit-learn-about-exact-data-match-based-sits



View Related Case Study

HOTSPOT (Drag and Drop is not supported)

You have a Microsoft 365 E5 subscription.

In Microsoft Exchange Online, you have the mail flow rule shown in the following exhibit.



Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.

Note: Each correct selection is worth one point.

Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Box 1: subject line
Outbound messages with the [Encrypt] string in the __________ of the message will be encrypted.

The mail flow rule Rule description states:
Apply this rule if

Is sent to 'Outside the organization
And includes these words in the message subject: [Encrypt]

Do the following

Rights protect message with RMS template: Do Not Forward

Box 2: restrict recipients from printing the message
The mail flow rule will ______.

Note: IRM is an encryption solution that also applies usage restrictions to email messages. It helps prevent sensitive information from being printed, forwarded, or copied by unauthorized people. IRM capabilities in Microsoft 365 use Azure Rights Management (Azure RMS).


Reference:

https://learn.microsoft.com/en-us/purview/email-encryption



View Related Case Study

HOTSPOT (Drag and Drop is not supported)

You have a Microsoft 365 5 subscription that contains the devices shown in the following table.



You publish Microsoft Purview Information Protection sensitivity labels.

You plan to deploy the information protection client to the devices. The solution must ensure that the labels can be applied to sensitive images and documents.

On which devices can you install the information protection client, and what should users use to apply labels? To answer, select the appropriate options in the answer area.

Note: Each correct selection is worth one point.

Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:




Box 1: Device1 and Device3 only.
Devices

Requirements for deploying the information protection client To use the Microsoft Purview Information Protection client, install this client on Windows computers where you want to use the client components.

You also must meet the following requirements:

The following operating systems support the Microsoft Purview Information Protection client:

Windows 11, including Windows 11 Enterprise multi-session
Windows 10 (x64) (Handwriting isn't supported in the Windows 10 RS4 build and later.) Windows Server 2019
Windows Server 2016

ARM64 isn't supported. [Not Device2]

Box 2: File Explorer
Use the Microsoft Purview Information Protection client can be installed and used with File Explorer in Windows. You can apply sensitivity labels and protection to files directly within File Explorer.


Reference:

https://learn.microsoft.com/en-us/purview/information-protection-client



Viewing page 7 of 42



Post your Comments and Discuss Microsoft SC-401 exam prep with other Community members:

SC-401 Exam Discussions & Posts