Microsoft Administering Information Security in Microsoft 365 - SC-401 Exam Practice Test
SIMULATION
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
[email protected]
Microsoft 365 Password: XXXXXXXXX
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL "https://admin.microsoft.com", and press Enter.
The following information is for technical support purposes only:
Lab Instance: XXXXXXXXX
Task 1
You plan to implement Endpoint data loss prevention (Endpoint DLP). You plan to create a policy that will restrict OneDrive.exe from accessing files that have the Highly Confidential sensitivity label.
You need to configure the Endpoint DLP settings so that onedrive.exe actions can be restricted by a DLP policy.
You do NOT need to create a DLP policy at this time.
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
[email protected]
Microsoft 365 Password: XXXXXXXXX
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL "https://admin.microsoft.com", and press Enter.
The following information is for technical support purposes only:
Lab Instance: XXXXXXXXX
Task 1
You plan to implement Endpoint data loss prevention (Endpoint DLP). You plan to create a policy that will restrict OneDrive.exe from accessing files that have the Highly Confidential sensitivity label.
You need to configure the Endpoint DLP settings so that onedrive.exe actions can be restricted by a DLP policy.
You do NOT need to create a DLP policy at this time.
Correct Answer:
To restrict onedrive.exe actions in Microsoft Purview, you first configure it as a restricted app group in Endpoint DLP settings and then add that group to a DLP policy in the Microsoft Purview portal. In the Endpoint DLP settings, navigate to Data loss prevention > Settings > Data loss prevention > Endpoint settings > Restricted apps and app groups. Create a new group called
"Cloud Sync apps," select the Auto-quarantine option, and add onedrive.exe as the executable name for Windows.
Configure the restricted app group
Step 1: Sign in to the Microsoft Purview portal.
Step 2: Go to Data loss prevention > Settings (gear icon) > Data loss prevention > Endpoint settings.
Step 3: Expand Restricted apps and app groups.
Step 4: Under "Restricted app groups," select Add restricted app group.
Step 5: Enter a group name, such as Cloud Sync apps.
Step 6: Check the box for Auto-quarantine.
Step 7: In the "App name" field, add the executable name:
For Windows, enter onedrive.exe and click the + button.
Reference:
https://learn.microsoft.com/en-us/purview/endpoint-dlp-using
"Cloud Sync apps," select the Auto-quarantine option, and add onedrive.exe as the executable name for Windows.
Configure the restricted app group
Step 1: Sign in to the Microsoft Purview portal.
Step 2: Go to Data loss prevention > Settings (gear icon) > Data loss prevention > Endpoint settings.
Step 3: Expand Restricted apps and app groups.
Step 4: Under "Restricted app groups," select Add restricted app group.
Step 5: Enter a group name, such as Cloud Sync apps.
Step 6: Check the box for Auto-quarantine.
Step 7: In the "App name" field, add the executable name:
For Windows, enter onedrive.exe and click the + button.
Reference:
https://learn.microsoft.com/en-us/purview/endpoint-dlp-using
Hotspot Question
You have a Microsoft 365 E5 subscription.
You need to implement a compliance solution that meets the following requirements:
- Captures clips of key security-related user activities, such as the
exfiltration of sensitive company data.
- Integrates data loss prevention (DLP) capabilities with insider risk
management.
What should you use for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription.
You need to implement a compliance solution that meets the following requirements:
- Captures clips of key security-related user activities, such as the
exfiltration of sensitive company data.
- Integrates data loss prevention (DLP) capabilities with insider risk
management.
What should you use for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Box 1: Forensic evidence in Microsoft Purview Insider Risk Management allows organizations to capture screen recordings of security-related user activities, such as attempted exfiltration of sensitive data. This feature provides context around risky behavior, helping investigators analyze incidents more effectively.
Box 2: Adaptive Protection uses Microsoft Purview Insider Risk Management and DLP together to apply protection dynamically based on detected user risks. It enhances DLP policies by automatically adjusting enforcement based on insider risk signals, ensuring that high-risk users receive stricter data controls while minimizing friction for low-risk users.
Hotspot Question
You use project codes that have a format of three alphabetical characters that represent the project type, followed by three digits, for example Abc123.
You need to create a new sensitive info type for the project codes.
How should you configure the regular expression to detect the content? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You use project codes that have a format of three alphabetical characters that represent the project type, followed by three digits, for example Abc123.
You need to create a new sensitive info type for the project codes.
How should you configure the regular expression to detect the content? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

You have enabled OCR scanning in Microsoft Purview at the tenant level. OCR scanning has been configured to scan images for sensitive information, and the following locations are selected: Exchange, SharePoint, OneDrive, Teams, Windows, and macOS devices.
You need Microsoft Purview to scan for credit card numbers in both text and images at all chosen locations. What should you do?
You need Microsoft Purview to scan for credit card numbers in both text and images at all chosen locations. What should you do?
Correct Answer: C
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
You have a Microsoft 365 E5 subscription.
You need to ensure that encrypted email messages sent to an external recipient can be revoked or will expire within seven days.
What should you configure first?
You need to ensure that encrypted email messages sent to an external recipient can be revoked or will expire within seven days.
What should you configure first?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Hotspot Question
You have a Microsoft 365 E5 tenant that contains the users shown in the following table.

You have a retention policy that has the following configurations:
- Retain items for a specific period: 5 years
- Locations to apply the policy: Exchange email, SharePoint sites
You place a Preservation Lock on Policy1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 tenant that contains the users shown in the following table.

You have a retention policy that has the following configurations:
- Retain items for a specific period: 5 years
- Locations to apply the policy: Exchange email, SharePoint sites
You place a Preservation Lock on Policy1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
Box 1: No
When a retention policy is locked:
No one, including the global admin, can disable the policy or delete it Locations can be added but not removed You can extend the retention period but not decrease it Box 2: Yes You can extend the retention period but not decrease it Box 3: No You can extend the retention period but not decrease it Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/retention-preservation-lock
Hotspot Question
You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.

The subscription contains the resources shown in the following table.

You create a sensitivity label named Label1.
You need to publish Label1 and have the label apply automatically.
To what can you publish Label1, and to what can Label1 be auto-applied? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.

The subscription contains the resources shown in the following table.

You create a sensitivity label named Label1.
You need to publish Label1 and have the label apply automatically.
To what can you publish Label1, and to what can Label1 be auto-applied? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

Correct Answer:

Explanation:
There are two different methods for automatically applying a sensitivity label to content in Microsoft 365
1. Client-side labeling when users edit documents or compose (also reply or forward) emails
2.Service-side labeling when content is already saved (in SharePoint or OneDrive) or emailed (processed by Exchange Online).
You have a Microsoft 365 E5 subscription.
You plan to use Microsoft Purview insider risk management.
You need to create an insider risk management policy that will detect data theft from Microsoft SharePoint Online by users that submitted their resignation or are near their employment termination date.
What should you do first?
You plan to use Microsoft Purview insider risk management.
You need to create an insider risk management policy that will detect data theft from Microsoft SharePoint Online by users that submitted their resignation or are near their employment termination date.
What should you do first?
Correct Answer: C
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 tenant and 500 computers that run Windows 11. The computers are onboarded to Microsoft Purview.
You discover that a third-party application named Tailspin_scanner.exe accessed protected sensitive information on multiple computers.
Tailspin_scanner.exe is installed locally on the computers.
You need to block Tailspin_scanner.exe from accessing sensitive documents without preventing the application from accessing other documents.
Solution: From the Microsoft Defender for Cloud Apps, you mark the application as Unsanctioned.
Does this meet the goal?
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 tenant and 500 computers that run Windows 11. The computers are onboarded to Microsoft Purview.
You discover that a third-party application named Tailspin_scanner.exe accessed protected sensitive information on multiple computers.
Tailspin_scanner.exe is installed locally on the computers.
You need to block Tailspin_scanner.exe from accessing sensitive documents without preventing the application from accessing other documents.
Solution: From the Microsoft Defender for Cloud Apps, you mark the application as Unsanctioned.
Does this meet the goal?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
You plan to implement Microsoft Purview Advanced Message Encryption.
You need to ensure that encrypted email sent to external recipients expires after seven days.
What should you create first?
You need to ensure that encrypted email sent to external recipients expires after seven days.
What should you create first?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
You plan to create a new data loss prevention (DLP) policy named DLP1.
DLP1 will be applied to the Exchange email location.
You need to exclude two users named User1 and User2 from DLP1.
What should you do first?
DLP1 will be applied to the Exchange email location.
You need to exclude two users named User1 and User2 from DLP1.
What should you do first?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).