[Full-Version] 2026 New SC-401 Actual Exam Dumps, Microsoft Practice Test
Study HIGH Quality SC-401 Free Study Guides and Exams Tutorials
NEW QUESTION # 93
You have a Microsoft 365 E5 subscription.
You have a file named Customer.csv that contains a list of 1,000 customer names.
You plan to use Customer.csv to classify documents stored in a Microsoft SharePoint Online library.
What should you create in the Microsoft Purview portal, and which type of element should you select? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 94
Hotspot Question
You have a Microsoft 365 E5 subscription.
You receive the data loss prevention (DLP) alert shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Box 1: The DLP policy matched and an alert was generated, but the user (Megan Bowen) overrode the policy. Since the override justification was "Manager approved," the system allowed the email to be sent. This means the email was delivered immediately instead of being quarantined or sent for further approval.
Box 2: The "Override justification text" states "Manager approved," indicating that a manager explicitly approved the email through a workflow-based override process. If the manager was uninvolved, the justification would either be missing or state "User justified." The manager did not override Rule1 directly, but rather approved the email via workflow.
NEW QUESTION # 95
You have two Microsoft 365 subscriptions named Contoso and Fabrikam. The subscriptions contain the users shown in the following table.
You have a sensitivity label named Sensitivity! as shown in the exhibit. (Click the Exhibit tab) you have the files shown in the following table.
For each of the following statements, select yes if the statement is true. Otherwise select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Yes , Yes, No
To determine whether each statement is true or false, let's analyze the provided information step by step based on the sensitivity label settings and the user permissions associated with the files.
Given Information:
Users and Subscriptions:
User1: Contoso subscription, email: [email protected]
User2: Contoso subscription, email: [email protected]
User3: Fabrikam subscription, email: [email protected]
User4: Fabrikam subscription, email: [email protected]
Files and Sensitivity Label Application:
File1: Automatically applied Sensitivity1 using an auto-labeling policy File2: Applied by User2 File3: Applied by User1 Sensitivity Label (Sensitivity1) Assumptions: Since the exhibit for the sensitivity label is not fully detailed, we need to make reasonable assumptions based on typical Microsoft 365 sensitivity label behavior.
Sensitivity labels can restrict access based on user permissions, subscription boundaries, or specific configurations (e.g., allowing only users within the same organization to edit or view). Given the context of two separate subscriptions (Contoso and Fabrikam), it's likely that Sensitivity1 restricts access to users within the same subscription unless explicitly configured otherwise. A common default for such labels is to allow editing and other rights only to users within the applying user's organization, with possible restrictions for cross-subscription access.
Key Assumptions:
Sensitivity1 likely encrypts the files and restricts editing rights to users within the same subscription as the user who applied the label or where the auto-labeling policy is configured.
File1 (auto-applied) would inherit permissions based on the policy, likely restricting access to Contoso users if the policy is set up within the Contoso subscription.
File2 (applied by User2 from Contoso) would restrict access to Contoso users.
File3 (applied by User1 from Contoso) would also restrict access to Contoso users.
Users from Fabrikam (User3, User4) would not have edit rights unless explicitly granted, which is unlikely given the separation of subscriptions.
Statement Analysis:
User1 can edit rights for File1.
File1 was automatically applied with Sensitivity1 using an auto-labeling policy. Since the policy is likely configured within the Contoso subscription (where User1 resides), User1, as a Contoso user, should have edit rights unless the policy explicitly restricts this. Given User1's affiliation with Contoso, this is typically allowed.
The answer: Yes
User2 can edit rights for File3.
File3 was applied by User1, who is from the Contoso subscription. Since User2 is also from the Contoso subscription, they should have edit rights unless the label configuration explicitly denies this for other users within the same subscription. Typically, users within the same organization can edit files labeled by another user from the same organization.
The answer: Yes
User3 can print File2.
File2 was applied by User2, who is from the Contoso subscription. Sensitivity1 likely restricts access to Contoso users only. User3 is from the Fabrikam subscription, which is a separate entity. Unless cross-sub Answer : No
NEW QUESTION # 96
You have a Microsoft 365 E5 subscription.
You are implementing insider risk management.
You need to maximize the amount of historical data that is collected when an event is triggered.
What is the maximum number of days that historical data can be collected?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
NEW QUESTION # 97
Hotspot Question
You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.
You create the audit retention policies shown in the following table.
The users perform the following actions:
- User1 renames a Microsoft SharePoint Online site.
- User2 sends an email message.
How long will the audit log records be retained for each action? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
The action "SiteRenamed" for SharePoint is covered under the AuditRetention4 policy, which applies to User1 and retains logs for 9 months.
The action "Send" for ExchangeItem is covered under the AuditRetention2 policy, but this policy applies only to User1. Since User2 is not covered under a specific policy, the default retention period for audit logs in Microsoft Purview is 90 days.
NEW QUESTION # 98
DRAG DROP
You have a Microsoft 365 subscription that contains 20 data loss prevention (DLP) policies.
You need to identify the following:
# Rules that are applied without triggering a policy alert
# The top 10 files that have matched DLP policies
# Alerts that are miscategorized
Which report should you use for each requirement? To answer, drag the appropriate reports to the correct requirements. Each report may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
The False positive and override report helps identify rules that were applied but did not generate an actual policy alert, which means they were overridden or deemed false positives.
The DLP policy matches report provides details on files that matched DLP policies, including the top 10 files.
The Incident reports report helps analyze and review alerts, including those that may have been miscategorized.
NEW QUESTION # 99
You have a Microsoft 36S subscription.
In Microsoft Exchange Online, you configure the mail flow rule shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 100
SIMULATION
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
[email protected]
Microsoft 365 Password: XXXXXXXXX
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL "https://admin.microsoft.com", and press Enter.
The following information is for technical support purposes only:
Lab Instance: XXXXXXXXX
Task 2
You need to ensure that email sent to external recipients with the word Falcon in the subject line will be encrypted by using an RMS template named Highly Confidential \ All Employees.
Answer:
Explanation:
To encrypt emails with "Falcon" in the subject to external recipients, you must first create an Information Protection sensitivity label with RMS encryption, then create a mail flow rule in the Purview compliance portal that applies this label to emails that are sent externally and have
"Falcon" in the subject line.
Task 1: Set up the Information Protection sensitivity label
Step 1: Go to the Microsoft Purview compliance portal and navigate to Information protection.
Step 2: Open the Labels tab and click Create a label.
Step 3: Follow the wizard to configure the new label. On the label settings page, enable Encrypt and then select the RMS template that you want to apply.
Task 2: Create the mail flow rule
Step 4: Go to the Purview compliance portal and navigate to Mail flow rules.
Step 5: Click New rule.
Step 6: Set the conditions:
Condition 1: Select "The subject contains..." and enter "Falcon".
Condition 2: Select "The recipient is located..." and choose "External".
Step 7: Set the action:
Select "Apply the sensitivity label..." and choose the label you created in the previous step.
Step 8: Review and save the rule.
Reference:
https://learn.microsoft.com/en-us/purview/ome
NEW QUESTION # 101
You have a Microsoft 365 E5 subscription that contains a user named User1.
You deploy Microsoft Purview insider risk management.
You need ensure that insider risk management events related to User1 are visible only to specific users.
What should you create?
- A. an indicator variant
- B. a global exclusion
- C. a detection group
- D. a priority user group
Answer: D
Explanation:
To restrict management of Microsoft Purview Insider Risk Management events to specific users, you can utilize Priority User Groups and Administrative Units. Priority User Groups allow you to designate which users can view data related to specific users in Insider Risk Management, while Administrative Units enable you to scope user permissions to geographical areas or departments.
Priority User Groups (PUGs):
Purpose:
PUGs allow you to create groups of users who are deemed high-risk and designate which users (e.g., investigators, analysts) can view data related to those high-risk users.
How to use:
Create a PUG in the Insider Risk Management settings.
When creating the PUG, you'll designate which users (or Insider Risk Management role groups) can view data related to the users within that PUG.
This ensures that only authorized personnel can access and manage alerts and cases associated with those high-risk users.
Reference:
https://learn.microsoft.com/en-us/purview/insider-risk-management-users
NEW QUESTION # 102
SIMULATION
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
[email protected]
Microsoft 365 Password: XXXXXXXXX
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL "https://admin microsoft.com", and press Enter.
The following information is for technical support purposes only:
Lab Instance: XXXXXXXX.
Task 7
You need to create a retention policy that meets the following requirements:
- Applies to Microsoft Teams chats and Teams channel messages.
- Retains items for five years from the date they are created, and then deletes them.
Answer:
Explanation:
Stage 1: Create an adaptive scope
Step 1: Sign into Microsoft Purview compliance portal using credentials for an admin account in your Microsoft 365 organization.
Step 2: In the compliance portal, select Roles and Scopes.
Step 3: Select Adaptive scopes, and then + Create scope.
Step 4: Follow the prompts in the configuration where you'll first be asked to assign an administrative unit. If your account has been assigned administrative units, you must select one administrative unit that will restrict the scope membership. (Does not apply here) If you don't want to restrict the adaptive scope by using administrative units, or your organization hasn't configured administrative units, keep the default of Full directory. (Applies here) Step 5: Select the type of scope, and then select the attributes or properties you want to use to build the dynamic membership, and type in the attribute or property values. Select Add attribute (for users and groups).
For example, to configure an adaptive scope that will be used to identify users in Europe, first select Users as the scope type, and then select the Country or region attribute, and type in Europe:
Step 6: For User Attributes select: Department, is equal to, Sales
Stage 2: Create and configure retention policies
Step 1: From the Microsoft Purview compliance portal, select Data lifecycle management > Microsoft 365 > Retention Policies.
Step 2: Select New retention policy to start the Create retention policy configuration, and name your new retention policy.
Step 3: For the Assign admin units page (skip)
Step 4: For the Choose the type of retention policy to create page, select Adaptive or Static.
Select Adaptive.
We need Adaptive scopes.
Step 5: On the Choose adaptive policy scopes and locations page, select Add scopes and select the one you created in Stage 1.
Step 6: Then, select one or more locations. The locations that you can select depend on the scope types added. For example, if you only added a scope type of User, you'll be able to select Teams chats but not Teams channel messages.
Select: Teams chat and Teams channel
Step 7: For Decide if you want to retain content, delete it:
Select: On the Decide if you want to retain content, delete it, or both page, select Retain items for a specific period, specify the retention period [specify 5 years], and then for At end of the retention period select Delete items automatically.
Note: We need to retains item for five years from the date they are created, and then deletes them.
Reference:
https://learn.microsoft.com/en-us/purview/purview-adaptive-scopes
https://learn.microsoft.com/en-us/purview/create-retention-policies
https://learn.microsoft.com/en-us/purview/retention-settings#settings-for-retaining-and-deleting- content
NEW QUESTION # 103
HOTSPOT
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
You plan to create a Microsoft Purview insider risk management case named Case1.
Which insider risk management object should you select first, and which users will be added as contributors for Case1 by default?
To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Box 1: When creating a Microsoft Purview Insider Risk Management case, you must first select a risky user to investigate. The case will be built around this specific user's activities, linking alerts and risk signals to the investigation.
Box 2: The Insider Risk Management role groups determine who can access and contribute to cases:
# Admin1 (Insider Risk Management Admins) # Full admin access.
# Admin2 (Insider Risk Management Analysts) # Analysts who review cases.
# Admin3 (Risk Management Investigators) # Investigators who work on cases.
# Admin4 (Insider Risk Management Auditors) # Auditors who oversee cases.
All these roles have default access to insider risk cases in Microsoft Purview, so all four admins are added as contributors.
NEW QUESTION # 104
You have a Microsoft J65 ES subscription.
You need to create a Microsoft Defender for Cloud Apps policy that will detect data loss prevention (DIP) violations. What should you create?
- A. an activity policy
- B. a session policy
- C. a file policy
- D. an access policy
Answer: C
Explanation:
The question asks about creating a Microsoft Defender for Cloud Apps (MCAS / MDA) policy that will detect Data Loss Prevention (DLP) violations.
Understanding the policy types in Defender for Cloud Apps:
File Policy
Used for monitoring and controlling files stored in cloud apps (e.g., SharePoint, OneDrive, Box, Google Drive).
Can detect sensitive information types (like credit cards, SSNs, SWIFT codes) and flag DLP violations.
Can apply governance actions (e.g., quarantine, remove sharing, notify user).
Correct for DLP violation detection.
Activity Policy
Monitors user activities (e.g., login attempts, mass downloads, suspicious behavior).
Not for file content DLP.
Session Policy
Applied through Conditional Access App Control for real-time monitoring/control during a user session.
Used for controlling actions (download, cut/paste) but not for broad DLP scanning of stored files.
Access Policy
Controls access to apps based on conditions (e.g., unmanaged device access).
Not designed for DLP content inspection.
Why File Policy is correct
Since the requirement is:
"detect DLP violations"
That means scanning file content for sensitive information. This is only possible with a File Policy in Microsoft Defender for Cloud Apps.
Reference: File policies in Microsoft Defender for Cloud Apps
NEW QUESTION # 105
You create a retention label that has a retention period of seven years.
You need to ensure that documents containing a credit card number are retained for seven years. Other documents must not be retained.
What should you create?
- A. a retention policy that deletes files automatically
- B. a retention label policy of type auto-apply
- C. a retention label policy of type publish
- D. a retention policy that retains files automatically
Answer: B
NEW QUESTION # 106
You have a Microsoft SharePoint Online site named Site! that contains the files shown in the following table.
You have a data loss prevention (DLP) policy named DLP1 that has the advanced DLP rules shown in the following table.
You apply DLP1 toSite1.
Which policy tips will appear for File2?
- A. Tip1 and Tip2 only
- B. Tip3 only
- C. Tip2 only
- D. Tip1 only
Answer: C
NEW QUESTION # 107
You need to be alerted when users share sensitive documents from Microsoft OneDrive to any users outside your company.
What should you do?
- A. From the Microsoft Purview portal start an Advanced eDiscovery search.
- B. From the Exchange admin center, create a data loss prevention (DLP) policy.
- C. From the Microsoft Defender portal, create a file policy.
- D. From the Microsoft Defender portal create an activity policy.
Answer: C
Explanation:
After you connect an app to Defender for Cloud Apps, integrate with Microsoft Purview Information Protection. Then, in the Files page, filter for files labeled Confidential and exclude your domain in the Collaborators filter. If you see that there are confidential files shared outside your organization, you can create a file policy to detect them.
Reference:
https://learn.microsoft.com/en-us/defender-cloud-apps/file-filters
https://learn.microsoft.com/en-us/microsoft-365/compliance/how-dlp-works-between-admin- centers
NEW QUESTION # 108
HOTSPOT
You have a Microsoft 365 E5 subscription.
You need to implement a compliance solution that meets the following requirements:
# Captures clips of key security-related user activities, such as the exfiltration of sensitive company data.
# Integrates data loss prevention (DLP) capabilities with insider risk management.
What should you use for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 109
You have a Microsoft 365 E5 subscription that contains a data loss prevention (DLP) policy named DLP1.
DLP1 contains the DLP rules shown in the table.
You need to ensure that when a document matches all the rules, users will see Tip 2.
What should you change?
- A. the priority setting of Rule2 to 0
- B. the If there's a match for this rule, stop processing additional DLP policies and rules setting for Rule3 to Enabled
- C. the priority setting of Rule3 and Rule4 to 0
- D. the priority setting of Rule2 to 2
Answer: A
NEW QUESTION # 110
You are configuring a data loss prevention (DLP) policy to report when credit card data is found on a Microsoft Entra joined Windows device.
You plan to use information from the policy to restrict the ability to copy the sensitive data to the clipboard.
What should you configure in the policy advanced DLP rule?
- A. user overrides
- B. an action
- C. the incident report
- D. user notifications
Answer: B
NEW QUESTION # 111
Your company has offices in multiple countries.
The company has a Microsoft 365 E5 subscription that uses Microsoft Purview insider risk management.
You plan to perform the following actions:
*In a new country, open an office named Office1.
*Create a new user named User1.
*Deploy insider risk management to Office1.
*Add User1 to the Insider Risk Management Admins role group.
You need to ensure that User1 can perform insider risk management tasks for only the users and the devices in Office1.
What should you create first?
- A. a management group
- B. a dynamic user group
- C. a dynamic device group
- D. an administrative unit
Answer: D
Explanation:
To ensure User1 can perform insider risk management tasks only for the users and devices in Office1, the first step is to create an administrative unit in Microsoft Entra ID (formerly Azure AD).
Administrative units allow you to scope permissions to specific users, devices, and locations. By creating an administrative unit for Office1 and assigning User1 to the Insider Risk Management Admins role group within that unit, User1 will only have access to users and devices in Office1.
NEW QUESTION # 112
You have a Microsoft 365 £5 subscription that contains the groups shown in the following table.
The subscription contains the users shown in the following table.
You create the mail flow rules shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 113
You have a Microsoft 365 E5 subscription.
You plan to implement insider risk management for users that manage sensitive data associated with a project.
You need to create a protection policy for the users. The solution must meet the following requirements:
- Minimize the impact on users who are NOT part of the project.
- Minimize administrative effort.
What should you do first?
- A. From the Microsoft Entra admin center, create a User risk policy.
- B. From the Microsoft Purview portal, create an insider risk management policy.
- C. From the Microsoft Purview portal, create a priority user group.
- D. From the Microsoft Entra admin center, create a security group.
Answer: D
Explanation:
To implement insider risk management for users managing sensitive project data while minimizing the impact on other users and reducing administrative effort, you should first create a security group in Microsoft Entra ID (formerly Azure AD).
Security groups allow you to scope insider risk management policies to specific users instead of applying policies to all users, which helps in minimizing unnecessary alerts and reducing administrative overhead. After creating the security group, you can assign this group to a Microsoft Purview Insider Risk Management policy, ensuring that only project-related users are affected.
NEW QUESTION # 114
SIMULATION
Username and password
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
[email protected]
Microsoft 365 Password: XXXXXXXXX
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL "https://admin.microsoft.com", and press Enter.
The following information is for technical support purposes only:
Lab Instance: XXXXXXXXX
Task 3
You need to create a retention label that retains items for 10 years starting from June 1, 2025.
The items must be deleted after the retention period.
You do NOT need to publish or auto-apply the label at this time.
Answer:
Explanation:
To create a retention label, sign in to the Microsoft Purview portal and navigate to Solutions > Records management > Policies. Select Publish labels and follow the prompts to configure the label's settings, retention period, and what happens after the period ends.
Step 1: Sign in to the Microsoft Purview portal. You can access it by going to the Microsoft 365 app launcher and selecting "Compliance".
Step 2: In the Microsoft Purview portal, go to Solutions > Records management > Policies and click on Publish labels.
Step 3: Create and configure the retention label
Make the following choices:
Retain items for a specific period: Select 10 years
Start the retention period based: Select June 1, 2025 as start date
At the end of the retention period: Delete items automatically.
Reference:
https://learn.microsoft.com/en-us/purview/retention-settings
NEW QUESTION # 115
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 tenant and 500 computers that run Windows 11. The computers are onboarded to Microsoft Purview.
You discover that a third-party application named Tailspin_scanner.exe accessed protected sensitive information on multiple computers.
Tailspin_scanner.exe is installed locally on the computers.
You need to block Tailspin_scanner.exe from accessing sensitive documents without preventing the application from accessing other documents.
Solution: From the Microsoft Defender for Cloud Apps, you mark the application as Unsanctioned.
Does this meet the goal?
- A. No
- B. Yes
Answer: A
Explanation:
You can unsanction a specific risky app by clicking the three dots at the end of the row. Then select Unsanction. Unsanctioning an app doesn't block use, but enables you to more easily monitor its use with the Cloud Discovery filters. You can then notify users of the unsanctioned app and suggest an alternative safe app for their use.
https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-using?view=o365- worldwide
NEW QUESTION # 116
Hotspot Question
You have a Microsoft 365 E5 subscription that contains four Microsoft SharePoint Online sites named Site1, Site2, Site3, and Site4.
You have the retention policies shown in the following table.
You have the documents shown in the following table.
User1 moves Doc3 to Site4.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
Box 1: Yes
Doc1 will be successfully retained for six years because Policy3 provides the longest retention period among all policies applied to Site1.
This retention duration is determined by evaluating which policies apply to Site1 and applying Microsoft 365's standard principles of retention.
1. Identify Applicable PoliciesTo determine how long Doc1 is retained, we first identify every policy targeting Site1:
Policy1: Targets Site1 and Site3. Retention period is 2 years.
Policy3: Targets Site1, Site2, and Site3. Retention period is 6 years.
2. Apply Retention Principles
When multiple retention policies apply to the same content, Microsoft 365 resolves conflicts using the Principles of Retention in a specific order:
Retention wins over deletion: Both Policy1 and Policy3 are retention policies, so this rule is satisfied.
Longest retention period wins: Policy3 specifies a 6-year retention period, which outlasts the 2- year period specified by Policy1.
Therefore, the 6-year retention rule from Policy3 takes precedence over Policy1.
Box 2: No
Doc2 will be retained for a total of six years, not four years.
Doc2 will be retained for six years because the longest retention period always wins when multiple Microsoft 365 retention policies conflict.
1. Identify Applicable Policies
Doc2 is stored in Site2.
We must isolate the policies that include Site2 in their location scope:
Policy2: Retains content for 4 years.
Policy3: Retains content for 6 years.
2. Apply Retention Principles
When a document is subject to multiple retention policies, Microsoft 365 evaluates them using the following hierarchical rules:
Retention wins over deletion: Both policies are retention policies, so this rule is a tie.
Longest retention period wins: Policy3 specifies a 6-year retention period, while Policy2 specifies a 4-year period.
Because 6 years is longer than 4 years, Policy3 takes precedence over Policy2.
Box 2: No
When document Doc3 is moved from Site3 to Site4, it is no longer covered by any of the retention policies because Site4 is not a location in Policy1, Policy2, or Policy3. The claim that Doc3 will be retained for four years is incorrect.
Reference:
https://joannecklein.com/2026/01/23/office-365-retention-policy-questions-from-the-field/
NEW QUESTION # 117
You have a Microsoft 365 E5 subscription that uses Microsoft Purview insider risk management and contains three users named User1, User2, and User3.
All insider risk management policies have adaptive protection enabled and the default conditions for insider risk levels configured.
The users perform the following activities, which trigger insider risk policy alerts:
* User1 performs at least one data exfiltration activity that results in a high severity risk score.
* User2 performs at least three risky user activities within seven days, that each results in a high severity risk score.
* User3 performs at least bwo data exfiltration activities within seven days, that each results in a high severity risk score.
Which insider risk level is assigned to each user? To answer, drag the appropriate levels to the correct users.
Each level may be used once, more than once, or not at all. You may need to drag the split bar between panes or seroll to view content.
NOTE: Each correct selection is worth one point.
Answer:
Explanation:
Explanation:
NEW QUESTION # 118
......
Get 100% Real Free Microsoft Certified: Information Security Administrator Associate SC-401 Sample Questions: https://pass4sure.troytecdumps.com/SC-401-troytec-exam-dumps.html